<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://portal.spidynamics.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>HP ASC Portal</title><link>http://portal.spidynamics.com/blogs/default.aspx</link><description /><dc:language>en-US</dc:language><generator>CommunityServer 2.1 (Build: 60809.935)</generator><item><title>News Flash: phpBB Massive Hack</title><link>http://portal.spidynamics.com/blogs/rafal/archive/2008/05/13/News-Flash_3A00_-phpBB-Massive-Hack.aspx</link><pubDate>Tue, 13 May 2008 19:42:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:77204</guid><dc:creator>Rafal Los</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;ComputerWorld is running &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9084991&amp;amp;source=NLT_PM&amp;amp;nlid=8" title="ComputerWorld Article (phpBB Hacks)"&gt;an article&lt;/a&gt; from Paul Ferguson of TrendMicro claiming that there is a massive hack going on as you read this - via the phpBB bulletin-board software.&amp;nbsp; Truth be told, phpBB has been known to be bug-ridden over the years (simply Google &amp;quot;phpBB vulnerability&amp;quot; and you&amp;#39;ll get more than you wanted) but I believe that these have come to a boiling point now.&amp;nbsp; If it&amp;#39;s actually true, the number of site that was hacked stands at ~500,000, it would point to a massive problem within phpBB&amp;#39;s code which likley hasn&amp;#39;t been disclosed yet.&lt;/p&gt;&lt;p&gt;What worries me is not that these sites are being hacked (because this is a &amp;quot;normal&amp;quot; occurrence these days) but that they&amp;#39;re increasingly effective.&amp;nbsp; While a half-million web sites being broken into isn&amp;#39;t something to sound the alarm over - and this is truly a sad commentary on the state of web security today - the precision and effectiveness of these types of attacks is scary.&amp;nbsp; Furthermore, the &amp;quot;drive-by&amp;quot; installations of malware, trojans and other unwanted stuff on your computer is the stuff that security managers worry about at night.&amp;nbsp; Just think of the amount of data that a half-million key loggers can pull?&amp;nbsp; Think of the potential fallout of having to re-load (because cleaning isn&amp;#39;t possible most of the time) every machine at your office... the possibility boggles the mind.&lt;/p&gt;&lt;p&gt;What comes out in incidents like this, and sadly people still do not understand, is that an insecure web application/site does more than just possibly damage the host.&amp;nbsp; A vulnerable site leaves its visitors vulnerable, which sets off a chain of reactions that resonates back into the CISO&amp;#39;s office at any company that allows its users to browse the Internet.&amp;nbsp; More on this in a future post.&lt;/p&gt;&lt;p&gt;While I know it&amp;#39;s rather un-common to have a php-facing application like this in an entierprise - it&amp;#39;s definitely not impossible so I felt like I needed to notify and warn you readers.&amp;nbsp; More as information comes in... if it comes in.&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=77204" width="1" height="1"&gt;</description><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/phpBB/default.aspx">phpBB</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/hack/default.aspx">hack</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/php/default.aspx">php</category></item><item><title>Top Five Web Application Vulnerabilities 4/28/08 - 5/11/08</title><link>http://portal.spidynamics.com/blogs/top5/archive/2008/05/12/Top-Five-Web-Application-Vulnerabilities-4_2F00_28_2F00_08-_2D00_-5_2F00_11_2F00_08.aspx</link><pubDate>Mon, 12 May 2008 18:28:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:77188</guid><dc:creator>mep</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;1) SAP Internet Transaction Server Multiple Cross-Site Scripting Vulnerabilities&lt;/p&gt;&lt;p&gt;SAP Internet Transaction Server is susceptible to multiple instances of Cross-Site Scripting.&amp;nbsp; If exploited, these vulnerabilities could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. A solution is reported to be available in SAP note 1052053. Contact the vendor for further details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29103"&gt;http://www.securityfocus.com/bid/29103&lt;/a&gt;&lt;/p&gt;&lt;p&gt;2) Sun Java System Web Server Search Module Cross-Site Scripting Vulnerability&lt;/p&gt;&lt;p&gt;Sun Java System Web Server Search Module is susceptible to a Cross-Site Scripting vulnerability. If successfully exploited, this vulnerability could allow an attacker to steal confidential information and cookie-based authentication credentials, and possibly lead to execution of arbitrary code in the browser of an unsuspecting user.&amp;nbsp; A fix has been released. Contact the vendor for additional information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29087"&gt;http://www.securityfocus.com/bid/29087&lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) Sun Java System Directory Proxy Server Remote Unauthorized Access Vulnerability&lt;/p&gt;&lt;p&gt;Sun Java System Directory Proxy Server is susceptible to a remote unauthorized access vulnerability. An attacker can leverage this vulnerability to gain administrative access to the affected server. An advisory and fixes for this issue have been released. Contact the vendor for more details.&amp;nbsp; &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28941/discuss"&gt;http://www.securityfocus.com/bid/28941/discuss&lt;/a&gt;&lt;/p&gt;&lt;p&gt;4) Sun Java System Application Server and Web Server JSP Information Disclosure Vulnerability&lt;/p&gt;&lt;p&gt;Sun Java System Application Server and Web Server are prone to an information-disclosure vulnerability. An attacker could leverage this issue to obtain sensitive information which could possibly be used to orchestrate more dangerous attacks. An advisory and updates which address this issue have been released. Contact the vendor for additional information. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29088"&gt;http://www.securityfocus.com/bid/29088&lt;/a&gt;&lt;/p&gt;&lt;p&gt;5) Zen Cart &amp;#39;keyword&amp;#39; parameter SQL Injection and Cross-Site Scripting Vulnerabilities&lt;/p&gt;&lt;p&gt;Zen Cart is susceptible to SQL Injection and Cross-Site Scripting vulnerabilities. If exploited, these vulnerabilities could lead to compromise of the application, the theft of confidential information and authentication credentials, or be utilized in conducting additional database attacks. A fix has not yet been released. Contact the vendor for more information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/29020"&gt;http://www.securityfocus.com/bid/29020&lt;/a&gt;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=77188" width="1" height="1"&gt;</description></item><item><title>Static Code Analysis Failures</title><link>http://portal.spidynamics.com/blogs/rafal/archive/2008/05/06/Static-Code-Analysis-Failures.aspx</link><pubDate>Tue, 06 May 2008 21:32:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:77056</guid><dc:creator>Rafal Los</dc:creator><slash:comments>6</slash:comments><description>&lt;p&gt;Static code analysis failures are costing enterprises money and reputation.&lt;/p&gt;&lt;p&gt;White-box security testing is inherently a flawed proposition for many reasons -but it all comes down to a very simple concept:&lt;/p&gt;&lt;p&gt;&amp;nbsp; &lt;strong&gt;Machines do not execute source code, they execute machine code (compiled code). --Paul Anderson (&lt;a href="http://www.grammatech.com" title="GrammaTech website"&gt;GrammaTech&lt;/a&gt;)&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp; If you think this through for a minute you realize that there are a few specific reasons why the above statement fundamentally changes the way that people look at white-box testing, and why this is a losing proposition.&amp;nbsp; Let&amp;#39;s analyze this in the context of a web application project for a mythical online bank.&amp;nbsp; Consider that the use-case here is that we are dealing with a bank that has an online presence (currently being analyzed) which will be integrated with a series of existing legacy applications, partners, and external 3rd party components.&amp;nbsp; Given this information let&amp;#39;s analyze why white-box analysis (or static source-code analysis) is doomed to fail this project with respect to security.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;div&gt;&lt;strong&gt;Compiler Optimizers Break Things&lt;/strong&gt; - Think of it this way, compilers are designed to make machine code from your source code.&amp;nbsp; That compiler&amp;#39;s sole purpose (in most cases) is to create machine code that will be optimized, extremely fast-executing, but not necessarily secure.&amp;nbsp; Often times security functions that people build into source code can be removed by compiler optimizers and most often without our knowledge.&amp;nbsp; These actions often undo many of the advanced security features that developers may consciously insert into their code.&amp;nbsp; Consider the following example:&lt;/div&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;&lt;div&gt;Developer is paranoid about data-persistence in memory space, and wants to be doubly-sure that variables are expired and destroyed&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div&gt;Developer writes a routine whereby the variable will have a null value written to it&amp;nbsp;before the memory is freed&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div&gt;Compiler optimizer sees this as a double-work scenario, and removes the null-value portion and simply opts to free memory&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div&gt;A potential security vulnerability is created with variable persistence in freed memory space&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;blockquote&gt;&lt;p&gt;This example ideally demonstrates how a security vulnerability can be inserted in spite of the developer&amp;#39;s best efforts to write secure code.&amp;nbsp; Standard static-code analysis tools which are used to &amp;quot;scan code&amp;quot; at the static-file level will fail to catch this vulnerability.&amp;nbsp; Quite simply - static code analysis fails if it is not supplemented with dynamic analysis.&lt;/p&gt;&lt;/blockquote&gt;&lt;ul&gt;&lt;li&gt;&lt;div&gt;&lt;strong&gt;3rd Party Library Integrations&lt;/strong&gt; - There is another threat to developing and scanning static code in a white-box format.&amp;nbsp; Inevitably, 3rd party libraries are used to complement features or functionality that are not natively provided by the local development effort.&amp;nbsp; After all, no one re-invents the whole wheel everytime - we simply build what we cannot reuse from someone else&amp;#39;s work, then use the publicly available libraries from 3rd parties to fill in the functionality and features that have already been written and (hopefully) tested before.&amp;nbsp; White-box testing (or static code analysis) will absolutely fail in finding flaws when it comes to pulling in 3rd party libraries.&amp;nbsp; By the definition of this type of issue, 3rd party libraries rarely provide you the source to be scanned and checked for weaknesses that will affect your application.&amp;nbsp; What you&amp;#39;re left with is someone else&amp;#39;s code (in machine-compiled format!) which will be interacting with your application.&amp;nbsp; Would you trust that model?&lt;/div&gt;&lt;/li&gt;&lt;li&gt;&lt;div&gt;&lt;strong&gt;Static Code Analysis Rarely Understands&amp;nbsp;Data-Flow&amp;nbsp;Modeling&amp;nbsp;(Data Tracing)&lt;/strong&gt; - If you&amp;#39;re scanning your application with a source-code-only analysis tool, you&amp;#39;re going to not only miss things that will almost certainly come back to haunt you - but you may also be over-working yourself without a real purpose.&amp;nbsp; Consider the following example to illustrate my point.&amp;nbsp; Before I get into that example though, allow me to explain this idea of &amp;quot;data-flow modeling&amp;quot; for those that are not familiar with this idea.Data-flow modeling seeks to understand how data moves through your application, not just how the application code is written.&amp;nbsp; After all, that&amp;#39;s the whole pointn of the application, to work with data.&amp;nbsp; Vulnerabilities lie in manipulating data either to or from the end users or the server(s).&amp;nbsp; Data-flow modeling maps out the data in your appliaction from it&amp;#39;s instantiation (maybe when the user types it in) to its resting state (maybe when it&amp;#39;s finally written to a database, or handed off to another application or service for additional work).&amp;nbsp; That being said let&amp;#39;s consider a web application that has 1,000 forms across 100 pages written in the language of your choice, built to be AJAX.&amp;nbsp; While each page does nothing individually to validate user input (the data source) all variables (data) are filtered through a central validation module deep within the application logic.&amp;nbsp; A standard source-code analysis tool (I have evaluated this and can honestly say this is a real use-case but will not mention the tool) will flag on each and every input that is not validated (within the page) as vulnerable to hudreds of vulnerabilities ranging from XSS (Cross-Site Scripting) to SQL Injection and other attack types.&amp;nbsp; What you are left with is a very lengthy report with hundreds of critical and high vulnerabilities that you now obviously must address... unless you do some dynamic analysis on the code and realize that *none* of those theoretical vulnerabilities are exploitable due to the fact that the application filters all data through the central validator/scrubber.&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;So, there you have it.&amp;nbsp; Static code analysis is inherently doomed to fail.&amp;nbsp; White-box testing of source-only is flawed.&amp;nbsp; The sky is falling, global warming will kill us all.&amp;nbsp; In my next installment of this column, I&amp;#39;ll&amp;nbsp;give you what you need to know to avoid&amp;nbsp;failing in your security initiatives at the development step of the SDLC&amp;nbsp;- remember, knowing is half the battle.&lt;/p&gt;&lt;p&gt;&lt;em&gt;&amp;nbsp;Stay tuned!&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;font size="1"&gt;If this information disturbs you, and you would like to talk about it directly please don&amp;#39;t hesitate to email me directly.&amp;nbsp; I am not a sensationalist, and pride myself on presenting practical solutions to real-world problems which are realistically attainable.&amp;nbsp; Thanks for reading.&lt;/font&gt;&lt;/em&gt;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=77056" width="1" height="1"&gt;</description><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/security/default.aspx">security</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/testing/default.aspx">testing</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/static+code+analysis/default.aspx">static code analysis</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/whitebox/default.aspx">whitebox</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/data-flow+analysis/default.aspx">data-flow analysis</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/hybrid+analysis/default.aspx">hybrid analysis</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/dynamic+analysis/default.aspx">dynamic analysis</category></item><item><title>Security and Compliance - Strange Bedfellows Indeed</title><link>http://portal.spidynamics.com/blogs/rafal/archive/2008/05/01/Security-and-Compliance-_2D00_-Strange-Bedfellows-Indeed.aspx</link><pubDate>Thu, 01 May 2008 18:24:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:76973</guid><dc:creator>Rafal Los</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;&amp;nbsp; It&amp;#39;s a classic problem of which came first... the chicken or the egg?&amp;nbsp; politics or corruption?&amp;nbsp; security or compliance?&amp;nbsp; While I admit, it&amp;#39;s not such a strange thing to see the two groups working together these days... I would like to point of some of the issues that I&amp;#39;ve come across between these two very important groups in today&amp;#39;s enterprises.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;The issue of compliance is much like the issue of legal counsel.&amp;nbsp; All large enterprises, and even most small business have someone that&amp;#39;s responsible for compliance - occasionally you&amp;#39;ll see an entire department dedicated to the daunting task of keeping up with regulations, compliance policies, and the ever-changing landscape of procedural accountability.&amp;nbsp; Oddly enough, there is not a one-to-one relationship between the&amp;nbsp;compliance department and a security department.&amp;nbsp; I&amp;#39;ve spent a large portion of my IT career in situations just like this and I would like to share some of my understanding with you.&lt;/p&gt;&lt;p&gt;&amp;nbsp; Compliance, while not always a necessity in private businesses, is almost always present in larger, pubilc enterprises.&amp;nbsp; The compliance department is responsible for making sure the business is in-line with self-imposed corporate regulations and policies, industry-consortium regulatory guidance, government oversight and policy even international laws too!&amp;nbsp; It&amp;#39;s amazing these groups can even keep this stuff straight, right?&amp;nbsp; What&amp;#39;s equally amazing is how often compliance relies on IT Security for guidance and implementation of compliance components. This of course begs the question - would IT Security exist in some organizations if there was no compliance stipulation for such groups?&amp;nbsp; On the flipside of that... in a perfectly secure world where no one is ever malicious - what would be the need for the compliance group?&amp;nbsp; So while it may be a stretch to say that one group cannot function properly without the other (I will concede that they can, albeit poorly) each is heavily dependant on the other for its very existence within a business.&amp;nbsp; This is where I find some strange... interactions.&lt;/p&gt;&lt;p&gt;&amp;nbsp; As I&amp;#39;ve stated, the security team often carries out part of compliance policy or regulations; or performs audits to ensure that the same regulations are being followed - but I feel like even in these cases the synergies between these groups are under-utilized.&amp;nbsp; I can&amp;#39;t count the number of times I&amp;#39;ve been turned down for an IT Security initiative (which made perfect business sense, by the way - but was simply under-funded) only to push that same initiative through under the guise of a compliance regulation - through the compliance team.&amp;nbsp; In return... the compliance teams I&amp;#39;ve had the pleasure to work with have repeatedly called upon my security resources to be the &amp;quot;muscle&amp;quot; behind their policies.&lt;/p&gt;&lt;p&gt;&amp;nbsp; As I travel and talk to different groups about Application Security, I am agaff at the number of times that I get an entirely blank stare when I try to explain how leveraging compliance is a sure-fire way to get security initiatives done.&amp;nbsp; Here&amp;#39;s my reasoning... see if you disagree...&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Compliance is a &amp;quot;necessary evil&amp;quot; which exists to keep the business in good legal and regulatory standing&lt;/li&gt;&lt;li&gt;IT Security exists to keep the balance of risk/reward within the business IT as balanced as possible&lt;/li&gt;&lt;li&gt;IT Security should be looking to enact initiatives which work to support the business&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp; If you take all 3 points above as truth (and I firmly believe they are) then it&amp;#39;s a logical next-step to say that IT Security initiatives and Compliance initiatives will greatly overlap.&amp;nbsp; An overlap within two very necessary units of the enterprise will always, without fail, lend more credibility to their efforts and causes.&amp;nbsp; If both the security and compliance teams are pushing the same agenda, it becomes very difficult for a business owner to simply dismiss that agenda as unnecessary or frivolous.&lt;/p&gt;&lt;p&gt;&amp;nbsp; So a lesson-learned here - if you&amp;#39;re not already doing this... here are some very simple yet extremely effective (based on personal experience and first-hand accounts) techniques for getting things &amp;quot;done&amp;quot;.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Open a regular dialogue with your complaince team.&amp;nbsp; Meet once a quarter, once a month, or once a week as permissable to discuss what you&amp;#39;re independently working on&lt;/li&gt;&lt;li&gt;Find overlaps in your goals from a non-technical perspective&lt;/li&gt;&lt;li&gt;Create a joint strategy for compliance and technical implementation of initiatives previously agreed upon&lt;/li&gt;&lt;li&gt;Review business requirements jointly - ensure that both groups understand each other&amp;#39;s point-of-view&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Given these very simple, and probably obvious, steps - I can virtually guarantee a more successful IT Security goal achievement.&amp;nbsp; You&amp;#39;ll work less uphill, you&amp;#39;ll &amp;quot;win&amp;quot; more often, and you&amp;#39;ll do a much better job not only understanding but supporting your business - that makes everyone happy.&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=76973" width="1" height="1"&gt;</description><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/security/default.aspx">security</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/politics/default.aspx">politics</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/compliance/default.aspx">compliance</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/technology+strategy/default.aspx">technology strategy</category></item><item><title>Top Five Web Application Vulnerabilities 4/14/08 - 4/27/08</title><link>http://portal.spidynamics.com/blogs/top5/archive/2008/04/28/Top-Five-Web-Application-Vulnerabilities-4_2F00_14_2F00_08-_2D00_-4_2F00_27_2F00_08.aspx</link><pubDate>Mon, 28 Apr 2008 20:08:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:76862</guid><dc:creator>mep</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;1) IBM Lotus Expeditor URI Handler Command Execution Vulnerability&lt;/p&gt;&lt;p&gt;IBM Lotus Expeditor is susceptible to a remote command-execution vulnerability because user-supplied input is not properly sanitized. Attackers who successfully exploit this issue can execute arbitrary commands in the context of victims who follow malicious URI&amp;#39;s.&amp;nbsp; A fix has not yet been released. Contact IBM for more information. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28926"&gt;http://www.securityfocus.com/bid/28926&lt;/a&gt;&lt;/p&gt;&lt;p&gt;2) F5 Networks FirePass 4100 SSL VPN &amp;#39;installControl.php3&amp;#39; Cross-Site Scripting Vulnerability&lt;/p&gt;&lt;p&gt;F5 Networks FirePass 4100 SSL VPN is susceptible to a Cross-Site Scripting vulnerability. If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. An update which resolves this vulnerability has been released. Contact the vendor for additional details. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28902"&gt;http://www.securityfocus.com/bid/28902&lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) HP OpenView Network Node Manager Running Apache Multiple Vulnerabilities&lt;/p&gt;&lt;p&gt;HP OpenView Network Node Manager when running Apache is vulnerable to multiple vulnerabilities including Cross-Site Scripting and Denial-of Service attacks. If successfully exploited, these vulnerabilities could allow an attacker to steal confidential information and cookie-based authentication credentials,&amp;nbsp; possibly lead to execution of arbitrary code in the browser of an unsuspecting users, and be used to deny access to legitimate users. Patches which resolve these issues have been released. Contact the vendor for more details. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/archive/1/491026"&gt;http://www.securityfocus.com/archive/1/491026&lt;/a&gt;&lt;/p&gt;&lt;p&gt;4) Novell GroupWise HTML Injection and Denial-of-Service Vulnerabilities&lt;/p&gt;&lt;p&gt;Novell GroupWise is susceptible to HTML Injection and Denial-of-Service vulnerabilities. HTML Injection can be leveraged to add content into a web server&amp;rsquo;s response, which can then be used to steal cookie-based authentication credentials, execute arbitrary code in context of the site, or simply alter how the site appears. Denial-of-Service attacks can be exploited to crash the application and deny access to legitimate users. A fix has not yet been released. Contact the vendor for additional information. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28944"&gt;http://www.securityfocus.com/bid/28944&lt;/a&gt;&lt;/p&gt;&lt;p&gt;5) RSA Authentication Agent for Web URI Redirection Vulnerability&lt;/p&gt;&lt;p&gt;RSA Authentication Agent for Web is susceptible to a remote URI-redirection vulnerability because inadequate data sanitization is performed on user-supplied input. Exploitation of this vulnerability could aid in phishing-style attacks. RSA Authentication Agent for Web 5.3.3.378 resolves this issue. Contact the vendor for specific upgrade information. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28907"&gt;http://www.securityfocus.com/bid/28907&lt;/a&gt;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=76862" width="1" height="1"&gt;</description></item><item><title>Navigating the PCI DSS Standards...</title><link>http://portal.spidynamics.com/blogs/rafal/archive/2008/04/22/Navigating-the-PCI-DSS-Standards_2E002E002E00_.aspx</link><pubDate>Tue, 22 Apr 2008 16:18:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:76702</guid><dc:creator>Rafal Los</dc:creator><slash:comments>1</slash:comments><description>&lt;p&gt;For those of you who keep up with the PCI DSS standard, the coucil today has issued an update titled: &lt;strong&gt;&lt;a href="https://www.pcisecuritystandards.org/pdfs/infosupp_6_6_applicationfirewalls_codereviews.pdf" title="PCI DSS Section 6.6 Update" target="_blank"&gt;Information Supplement: Requirement 6.6 Code Reviews and Application Firewalls Clarified&lt;/a&gt;.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&amp;nbsp; &lt;/strong&gt;The standard item 6.6 has been further clarified in one of two options, as before, being either Application Code Reviews or an Application Firewall.&amp;nbsp; I&amp;#39;ll address the first option, since that is the more logical one, but will briefly talk about the Application Firewall as well - just to clear the air a bit.&amp;nbsp; While the Standards Council continues to add clarification, which makes the standard more usable, more opportunities for compliance surface with less cost and effort.&amp;nbsp; No doubt the IT manager feels like this is a good thing because now the cost of compliance won&amp;#39;t necessarily be astronomical - and thereby make it viable.&amp;nbsp; As we all know, the issue of compliance to a non-government regulation is always a balancing act.&amp;nbsp; Compliance, as with most security components, is an equation balancing risk against spending and business value.&amp;nbsp; We all know the results... if the equation balances just right, the business benefits from the added security and sees value while not spending more money than the risk is worth - and security feels worthwhile because risk has been decreased by some factor which affects the business in a positive manner.&amp;nbsp; Granted, it doesn&amp;#39;t always work out quite so rosy - but the PCI DSS standard is going a long way to make sure that these equations that happen every day, in many businesses throughout the world&amp;nbsp;- balance.&lt;/p&gt;&lt;p&gt;&amp;nbsp; Now - on to the meat of the standards update.&amp;nbsp; First off, let me address the Web Application Firewall issue.&amp;nbsp; While this is a topic that deserves a whole article onto itself, the short version is this - web app firewalls are very expensive, complex band-aids.&amp;nbsp; That&amp;#39;s the reality.&amp;nbsp; While many of them work phenomenally well, and in fact I can name a few that do, they are difficult to implement into an existing production environment, they are primarily signature-based (remember how well we stop &amp;quot;unknown&amp;quot; viruses?), or have some other architectural quirk that makes them an impossibility in your enterprise.&amp;nbsp; Personally, at my previous company I started to implement a particular WAF ... but it took over a year and a half of research, testing, approvals, and more testing to get them into a newly built environment... not even into a legacy production environment where they would have provided the most value.&amp;nbsp; Anyway... the point is - a WAF is a tool you use when you don&amp;#39;t have the resources to &amp;quot;do it right&amp;quot;... fix the code itself.&lt;/p&gt;&lt;p&gt;&amp;nbsp; Section 6.6 of the PCI DSS standards, option 1 (the Application Code Reviews) now has 4 basic alternatives.&amp;nbsp; Candidates are urged to implement at least one of the following...&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Manual review of application source code&lt;/li&gt;&lt;li&gt;Propse use of automated application source code analyzer tools (static code scanners)&lt;/li&gt;&lt;li&gt;Manual web application security vulnerability assessment&lt;/li&gt;&lt;li&gt;Propse use of automated web application security vulnerability assessment tools&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp; First, a few things of note.&amp;nbsp; The above does not necessarily call for a &amp;quot;penetration test&amp;quot; which exploits vulnerabilities by an ethical hacker... only an &amp;quot;assessment&amp;quot; (which identifies but does not exploit) vulnerabilities is required.&amp;nbsp; The distincion is important because it means that you can now do this on production code, or a production environment without the risk of damaging your applications by necessity to prove their vulnerability.&lt;/p&gt;&lt;p&gt;&amp;nbsp; I find it interesting that the update goes and directly says &lt;em&gt;&amp;quot;In all cases, the individual(s) must have the proper skills and experience to understand the source code and/or web application, know how to evaluate each for vulnerabilities, and understand the findings&amp;quot;&lt;/em&gt;.&amp;nbsp; The fact that the DSS requirement 6.6 now specifically addresses competence in the assessor should mean that there was some ... question... over the competence of assessors or possibly a need to specifically stamp out that only qualified people should be doing assessments.&amp;nbsp; Interesting, at either angle.&amp;nbsp; The same statement goes for assessors using automated tools - but now we have an interesting proposition.&amp;nbsp; Do you (a) hire an extremely qualified application vulnerability tester, or (b) hire a knowledgeable user, and give him a software testing/scanning tool and some training... and are those even the same?&amp;nbsp; Obviously the dollar amounts for the two are different... or are they?&amp;nbsp; There is also the point about the testers having to be (the authors use the word &amp;quot;should be&amp;quot;) organizationally separate from those writing the code... well that makes sense.&amp;nbsp; No one wants the fox guarding the hen-house, right?&amp;nbsp; You don&amp;#39;t want the same developers that are potentially churning out insecure code to then review it and give themselves gold stars.&amp;nbsp; So far so good.&lt;/p&gt;&lt;p&gt;&amp;nbsp; So now we have 2 options for doing this internally - which will help our bottom line (external 3rd parties are typically very, very expensive)... &lt;/p&gt;&lt;ol&gt;&lt;li&gt;First option is to do an SDLC-integrated code review... actually reviewing the application code before it gets compiled and leaves the development group&amp;#39;s control.&amp;nbsp; We have the option to do it manually, or with some tools - using only highly trained and knowledgeable people.&lt;/li&gt;&lt;li&gt;Second option is to do a post-development analysis of the code.&amp;nbsp; Once the code is written, built, and tested for usability issues it&amp;#39;s time to security-test it with, again, either a human being, or&amp;nbsp;some black-box testing tool(s) - but again, you must use trained and knowledgeable people here as well.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&amp;nbsp; Well, if I&amp;#39;m a security manager...this is great!&amp;nbsp; Thinking logically - you always want the security expertise in-house, and why in the world wouldn&amp;#39;t you want to do application security throughout the application lifecycle?&amp;nbsp; The DSS update also goes on to remind us of requirement 6.3, and the need to have an effective change-control process such that the security reviews are not bypassed, at any level.&amp;nbsp; While the final sign-off must be done when the code is ready for production - it&amp;#39;s imperative that the effectiveness of the application security policy be enacted to push as far back into the development (pre-development planning?&amp;nbsp; requirements gathering?) lifecycle as possible (more on that in a separate article).&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;As a final note - the update talks about the need to stay current and abreast of new developments in application security testing.&amp;nbsp; It&amp;#39;s essential that whatever tools are purchased (whether they be the full SDLC suite from &lt;a href="http://www.hp.com/go/securitysoftware" title="HP Application Security Center Suite" target="_blank"&gt;HP/ASC&lt;/a&gt;, or some other vendor) - that these tools and their users be continually updated from the brightest minds in the field.&amp;nbsp; This is unfortunately a one-up battle against the &amp;quot;bad guys&amp;quot;... if you&amp;#39;re behind you&amp;#39;re sunk.&lt;/p&gt;&lt;p&gt;So what have we learned from the new Section 6.6 update?&lt;/p&gt;&lt;ul&gt;&lt;li&gt;There are at least 4 ways to interpret the &amp;quot;Application Code Review&amp;quot; guideline&lt;/li&gt;&lt;li&gt;You can have your code &amp;quot;reviewed&amp;quot; internally, as long as your assessor is trained and competent (but to who&amp;#39;s qualifications?)&lt;/li&gt;&lt;li&gt;You can use automated tools, either static code analysis or black-box testing software, if you have your people trained in those tools, and application security&lt;/li&gt;&lt;li&gt;Your testers/assessors have to be organizationally separate from the development organization (but at what level?)&lt;/li&gt;&lt;li&gt;Your organization should absolutely integrate application security as early into the SDLC as possible, using &amp;quot;tools and rules&amp;quot; in combination&lt;/li&gt;&lt;li&gt;Your testers should always be up-to-date on the latest developments, techniques, and methods... otherwise you&amp;#39;re bringing a knife to a gunbattle&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Thanks for your attention!&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=76702" width="1" height="1"&gt;</description><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/testing/default.aspx">testing</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/tools/default.aspx">tools</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/web+application/default.aspx">web application</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/PCI+DSS/default.aspx">PCI DSS</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/assessments/default.aspx">assessments</category></item><item><title>Top Five Web Application Vulnerabilities  3/31/08 - 4/13/08</title><link>http://portal.spidynamics.com/blogs/top5/archive/2008/04/14/Top-Five-Web-Application-Vulnerabilities--3_2F00_31_2F00_08-_2D00_-4_2F00_13_2F00_08.aspx</link><pubDate>Mon, 14 Apr 2008 21:16:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:76514</guid><dc:creator>mep</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;1) F5 BIG-IP Web Management Interface &amp;#39;NEW_VALUE&amp;#39; Parameter Remote Code Injection Vulnerability&lt;/p&gt;&lt;p&gt;F5 BIG-IP Web Management Interface is susceptible to a remote code injection vulnerability. Attackers who successfully exploit this vulnerability could execute arbitrary code with the privileges of the user of the affected application. A fix has not yet been released. Contact the vendor for additional information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28639/"&gt;http://www.securityfocus.com/bid/28639/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;2) Cisco Unified Communication Manager Multiple Vulnerabilities&lt;/p&gt;&lt;p&gt;Cisco Unified Communication Manager is susceptible to multiple remote vulnerabilities including instances of SQL Injection, information disclosure, and unauthorized access. If exploited, these vulnerabilities could lead to compromise of the application, leveraged to gain unauthorized application access, or utilized to obtain sensitive information. A fix has not yet been released. Contact Cisco for further details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28690"&gt;http://www.securityfocus.com/bid/28690&lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) Drupal Menu System Security Bypass Vulnerabilities&lt;/p&gt;&lt;p&gt;Drupal is susceptible to multiple security-bypass vulnerabilities via the menu system because the application fails to properly control access to certain pages. Successful exploitation would give an attacker access to sensitive information which could likely be utilized in orchestrating more damaging attacks. Updates which resolve these issues have been released. Contact the vendor for more information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28714"&gt;http://www.securityfocus.com/bid/28714&lt;/a&gt;&lt;/p&gt;&lt;p&gt;4) Microsoft SharePoint Server Picture Source HTML Injection Vulnerability&lt;/p&gt;&lt;p&gt;Microsoft SharePoint Server is susceptible to an HTML Injection vulnerability. HTML Injection is used to add content into a web server&amp;rsquo;s response, which can then be used to steal cookie-based authentication credentials, execute arbitrary code in context of the site, or simply alter how the site appears. An attacker needs to utilize a user account with page editing privileges to successfully exploit this vulnerability. A fix has not yet been released. Contact Microsoft for additional details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28706"&gt;http://www.securityfocus.com/bid/28706&lt;/a&gt;&lt;/p&gt;&lt;p&gt;5) SAP NetWeaver Filesystem Feedbacks Cross-Site Scripting Vulnerability&lt;/p&gt;&lt;p&gt;SAP NetWeaver is susceptible to a Cross-Site Scripting vulnerability. If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information.&amp;nbsp; Note that this issue can be resolved by activating &amp;#39;Secure Editing&amp;#39; in the Portal. Contact the vendor for more information.&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28699"&gt;http://www.securityfocus.com/bid/28699&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=76514" width="1" height="1"&gt;</description></item><item><title>In &quot;cyberspace&quot;... no one can hear your database scream</title><link>http://portal.spidynamics.com/blogs/rafal/archive/2008/04/09/In-_2200_cyberspace_22002E002E002E00_-no-one-can-hear-your-database-scream.aspx</link><pubDate>Wed, 09 Apr 2008 16:01:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:76158</guid><dc:creator>Rafal Los</dc:creator><slash:comments>2</slash:comments><description>&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; It&amp;#39;s 2:34am, local time.&amp;nbsp; You&amp;#39;re snoring up a storm after a hard day at the office.&amp;nbsp; You&amp;#39;ve patched all your servers, your lockdown scripts have been verified, and your IDS is humming along perfectly.&amp;nbsp; Oh, and by the way, someone named &amp;quot;R0kk1t&amp;quot; just stole your customer database.&amp;nbsp; A quick check of the &amp;quot;Security Dashboard&amp;quot; when you get in at 8:00am will show everything is green...&amp;nbsp; You have a serious problem.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sound like anyone you know?&amp;nbsp; This is a serious concern, and the problem is - it&amp;#39;s pervasive.&amp;nbsp; It&amp;#39;s scarry that 7 out of every 10 people I talk to about Web Application Security don&amp;#39;t have any defenses.&amp;nbsp; When I ask what their defenses are they mention things like firewalls, IDSes, and patch policies - all have absolutely nothing to do with (and will do little for) Web Application Security.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Houston - we have a problem.&amp;nbsp; Even if you&amp;#39;re trying to build a program geared towards protecting your web apps - how are you going to justify it?&amp;nbsp; Inevitably someone is going to ask you the daunting question - &amp;quot;So, have we been attacked?&amp;nbsp; How many times?&amp;quot;&amp;nbsp; Odds are you&amp;#39;re going to have no idea.&amp;nbsp; All hope is *not* lost though... I have some suggestions from years of this happening to me.&amp;nbsp; Here are some tips on building self-defense mechanisms into your web applications - and how to use them as rudimentary alerting triggers...&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Kick out the troublemakers&lt;/strong&gt;&amp;nbsp;- A well-built web application has to know when someone is just being stupid.&amp;nbsp; If your&amp;#39;re tracking logged-in users it&amp;#39;s even easier.&amp;nbsp; Track the per-user incidence of &amp;quot;bad data&amp;quot; and if it reaches a specific threshold - expire the session and send that user to a page warning them that they&amp;#39;ve been bad and must re-login.&amp;nbsp; It&amp;#39;s basic, and not hard to do - but rarely implemented.&amp;nbsp; Of course, you&amp;#39;ll have to figure out those thresholds and what &amp;quot;bad data&amp;quot; is - but at least you have a start here.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Whitelist &lt;/strong&gt;-&amp;nbsp;In&amp;nbsp;the point&amp;nbsp;above&amp;nbsp;I said you should track&amp;nbsp;&amp;quot;bad data&amp;quot; or bad user-supplied input but how do you know what is good versus bad?&amp;nbsp; Simple, you first have to define what you should expect from the user.&amp;nbsp; An application should, on a per-page and per-input basis, know exactly what input is allowed and what data sets are in play.&amp;nbsp; You can use regular expressions to validate these lists!&amp;nbsp; For example, if you&amp;#39;ve got a field that expects social security numbers (don&amp;#39;t we all) then you can have&amp;nbsp;this simple bit of JavaScript to validate (obviously you&amp;#39;ll want to do this on the server side!)&lt;/li&gt;&lt;/ul&gt;&lt;blockquote&gt;&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;&lt;span class="Keyword"&gt;function&lt;/span&gt; isValidSSN(value) { &lt;br /&gt;&amp;nbsp; &amp;nbsp; &lt;span class="Keyword"&gt;var&lt;/span&gt; re = &lt;span class="Constant"&gt;/^([0-6]\d{2}|7[0-6]\d|77[0-2])([ \-]?)(\d{2})\2(\d{4})$/&lt;/span&gt;; &lt;br /&gt;&amp;nbsp; &amp;nbsp; &lt;span class="Keyword"&gt;if&lt;/span&gt; (!re.test(value)) { &lt;span class="Keyword"&gt;return false&lt;/span&gt;; } &lt;br /&gt;&amp;nbsp; &amp;nbsp; &lt;span class="Keyword"&gt;var&lt;/span&gt; temp = value; &lt;br /&gt;&amp;nbsp; &amp;nbsp; &lt;span class="Keyword"&gt;if&lt;/span&gt; (value.indexOf(&lt;span class="Constant"&gt;&amp;quot;-&amp;quot;&lt;/span&gt;) != &lt;span class="Constant"&gt;-1&lt;/span&gt;) { temp = (value.split(&lt;span class="Constant"&gt;&amp;quot;-&amp;quot;&lt;/span&gt;)).join(&lt;span class="Constant"&gt;&amp;quot;&amp;quot;&lt;/span&gt;); } &lt;br /&gt;&amp;nbsp; &amp;nbsp; &lt;span class="Keyword"&gt;if&lt;/span&gt; (value.indexOf(&lt;span class="Constant"&gt;&amp;quot; &amp;quot;&lt;/span&gt;) != &lt;span class="Constant"&gt;-1&lt;/span&gt;) { temp = (value.split(&lt;span class="Constant"&gt;&amp;quot; &amp;quot;&lt;/span&gt;)).join(&lt;span class="Constant"&gt;&amp;quot;&amp;quot;&lt;/span&gt;); } &lt;br /&gt;&amp;nbsp; &amp;nbsp; &lt;span class="Keyword"&gt;if&lt;/span&gt; (temp.substring(&lt;span class="Constant"&gt;0&lt;/span&gt;, &lt;span class="Constant"&gt;3&lt;/span&gt;) == &lt;span class="Constant"&gt;&amp;quot;000&amp;quot;&lt;/span&gt;) { &lt;span class="Keyword"&gt;return false&lt;/span&gt;; } &lt;br /&gt;&amp;nbsp; &amp;nbsp; &lt;span class="Keyword"&gt;if&lt;/span&gt; (temp.substring(&lt;span class="Constant"&gt;3&lt;/span&gt;, &lt;span class="Constant"&gt;5&lt;/span&gt;) == &lt;span class="Constant"&gt;&amp;quot;00&amp;quot;&lt;/span&gt;) { &lt;span class="Keyword"&gt;return false&lt;/span&gt;; } &lt;br /&gt;&amp;nbsp; &amp;nbsp; &lt;span class="Keyword"&gt;if&lt;/span&gt; (temp.substring(&lt;span class="Constant"&gt;5&lt;/span&gt;, &lt;span class="Constant"&gt;9&lt;/span&gt;) == &lt;span class="Constant"&gt;&amp;quot;0000&amp;quot;&lt;/span&gt;) { &lt;span class="Keyword"&gt;return false&lt;/span&gt;; } &lt;br /&gt;&amp;nbsp; &amp;nbsp; &lt;span class="Keyword"&gt;return true&lt;/span&gt;; &lt;br /&gt;}&lt;/em&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/p&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Log, Log, Log&lt;/strong&gt; - Your web applications should always have a separate log file for &amp;quot;unexpected input&amp;quot;.&amp;nbsp; In fact, where I&amp;#39;ve had input into the development process I&amp;#39;ve required there to be at least 2 log files.&amp;nbsp; First log file logs all &amp;quot;unexpected actions&amp;quot; in a web application, the time/date, the logged-in user, the source, user-agent and all other pertinent details of the &amp;quot;unexpected action&amp;quot; whether it be an exception, a crash, or whatever.&amp;nbsp; The second log file is just a dump of all the weird input people submit - some malicious, some not, to better help write regular expressions to filter the garbage.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Fire Alerts&lt;/strong&gt; - All the things I&amp;#39;ve mentioned previously are great - but if no one looks at them, or gets an alert when they fire - they&amp;#39;re worthless.&amp;nbsp; Make sure you create actionable alerts from with your application framework.&amp;nbsp; Combine all the loggins, white-listing, and self-defense into something that you can understand.&amp;nbsp; Be careful of the information Monster though... if you&amp;#39;re not careful in the way you set this up you&amp;#39;ll end up with 10,000 emails/hour and won&amp;#39;t be any more effective than having nothing.&amp;nbsp; It&amp;#39;s a difficult balance but with practice you&amp;#39;ll be one step closer.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Well - I hope you find those useful.&amp;nbsp; If you&amp;#39;re willing to share, I would love to hear of some other methods that YOU are using in the real-world!&amp;nbsp; Leave them as a comment here, share with the community - remember we&amp;#39;re all smarter when we share information.&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=76158" width="1" height="1"&gt;</description><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/security/default.aspx">security</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/hacked/default.aspx">hacked</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/web+application/default.aspx">web application</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/defense/default.aspx">defense</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/alerting/default.aspx">alerting</category></item><item><title>The Politics of Getting Hacked</title><link>http://portal.spidynamics.com/blogs/rafal/archive/2008/04/06/The-Politics-of-Getting-Hacked.aspx</link><pubDate>Sun, 06 Apr 2008 07:07:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:75986</guid><dc:creator>Rafal Los</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; It&amp;#39;s the words that keep IT Security Managers up at night - &amp;quot;We have a problem, I think we&amp;#39;ve been hacked&amp;quot;.&amp;nbsp; Of course, there are few possible responses...&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Acknowledge Responsibly - You can acknowledge what has happened, open an investigation, and communicate with the public and your customers.&amp;nbsp; While this may be initially bad PR, in the end it shows responsibility and maturity of process and management &lt;br /&gt;&lt;/li&gt;&lt;li&gt;Acknowledge Irresponsibly - You can acknowledge the issue but attempt a campaign of mis-direction and cover-up.&amp;nbsp; Redirect blame to partners, vendors and even former employees, release mis-leading information about the magnitude of the issue and do not publicly investigate the breach.&lt;/li&gt;&lt;li&gt;Bury It - Re-direct blame, issue no statements or official information&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; The problem is this - you know which you &lt;em&gt;want to do&lt;/em&gt;, but which option will your &lt;em&gt;lawyers allow&lt;/em&gt; you to take?&amp;nbsp; There are many IT Security departments which are run more by the company legal counsel than the IT Security manager or CISO.&amp;nbsp; Why is this you may ask?&amp;nbsp; Lack of planning and initiative.&amp;nbsp; If a CISO has no strategic, pre-planned response plan for that dark day - the lawyers will more often than not take over and try and guide the company out of trouble (and in the process create a bigger problem).&amp;nbsp; Responsible breach disclosure isn&amp;#39;t easy to plan for, and if executed poorly will potentially cause a catastrophic end.&amp;nbsp; This game isn&amp;#39;t for the faint of heart.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; The purpose here isn&amp;#39;t to poke at the legal counsels, in fact, they&amp;#39;re entirely necessary and should be your allies.&amp;nbsp; They should not; however, run your crisis management process.&amp;nbsp; Crisis management should be left up to those who are trained for it, and not to the CEOs, the lawyers, or the PR department.&amp;nbsp; Litigation should be a component of your crisis-management process but if you lose control of the situation as the &amp;quot;security&amp;quot; function - you&amp;#39;re in for a rough ride.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; As the title of this entry suggests, there is a political component to every &amp;quot;incident&amp;quot; that must be carefully navigated.&amp;nbsp; Leave room in your response strategy (crisis management process) for all those previously mentioned folks to do their part - but make sure you understand that you have to control the situation.&amp;nbsp; You&amp;#39;re only going to accomplish any semblance of control by planning in advance, working your plan through the ranks, and making sure you have buy-in long before the call comes.&amp;nbsp; This is really a case of failing to plan means planning to fail.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Politics is a dirty business, but unfortunately you cannot escape it, even in IT Security management.&amp;nbsp; Remember, make allies, plan ahead, and get buy in and you&amp;#39;ll weather the storm.&amp;nbsp; Otherwise... I need to tell you a story about 3 envelopes...&amp;nbsp;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=75986" width="1" height="1"&gt;</description><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/incident/default.aspx">incident</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/hacked/default.aspx">hacked</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/crisis+management/default.aspx">crisis management</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/breach/default.aspx">breach</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/politics/default.aspx">politics</category></item><item><title>What's the point of &quot;penetration testing&quot;?</title><link>http://portal.spidynamics.com/blogs/rafal/archive/2008/04/04/What_2700_s-the-point-of-_2200_penetration-testing_22003F00_.aspx</link><pubDate>Fri, 04 Apr 2008 18:45:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:75890</guid><dc:creator>Rafal Los</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Over the last 8 years in IT Security, I&amp;#39;ve had at least a professional interest in the idea of penetration testing and the opinion of this service has evolved as the IT Security market niche matures and grows.&amp;nbsp; I wanted to take a minute to discuss it with the readers out there, and maybe solicit some opinions on the topic if you&amp;#39;re willing to offer yours.&amp;nbsp; I&amp;#39;ll reserve my personal opinion for the end, but wanted to present some thoughts, rebuttals and commentary on these here.&amp;nbsp; I&amp;#39;m going to address penetration testing in the context of web applications - but this can be allied virtually to any technology out there.&lt;/p&gt;&lt;p&gt;&lt;u&gt;Let&amp;#39;s first look at the arguments &lt;strong&gt;for&lt;/strong&gt; penetration testing:&lt;/u&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Penetration testing provies a &lt;em&gt;hackers-eye view of your web application attack surface&lt;/em&gt;&lt;/li&gt;&lt;li&gt;Penetration testing provides an outsider&amp;#39;s view of your web application attack surface&amp;nbsp;&lt;/li&gt;&lt;li&gt;Penetration testers will often find ways to manipulate your applications in ways your developers never thought possible&lt;/li&gt;&lt;li&gt;Penetration testing offers the client an opportunity to get a snapshot picture of your security posture&lt;/li&gt;&lt;li&gt;A penetration test goes more in-depth than a &amp;quot;security scan&amp;quot; by &lt;em&gt;identifying and exploiting real weaknesses&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Those are some compelling points, to be sure.&amp;nbsp; Security is a very strange f1sh, it changes so drastically so often it&amp;#39;s almost impossible to be entirely up-to-date all the time, unless that is your sole job.&amp;nbsp; This is precisely what penetration testers are great at - they focus their entire energy on researching, identifying, and exploiting security weaknesses in, in this example, web applications.&amp;nbsp; There really isn&amp;#39;t any amount of &amp;quot;scanning&amp;quot; that an automated tool can do which will match the power and adaptive capability of the human mind - I don&amp;#39;t think anyone will argue that - so the value of employing someone who is extremely versed in this sort of thing is akin to having your transmission looked at by a transmission-only specialist... you do it because you want to go to the expert.&amp;nbsp; There are varying degrees of expertise; of course, and let&amp;#39;s not even try and disagree that you get what you pay for.&amp;nbsp; If you want a top-notch security expert, you&amp;#39;re likely going to be hiring someone with a shady past, and it&amp;#39;s going to cost a lot - but at least you know you&amp;#39;re getting the top talent matching wits with your pro-active security measures.&amp;nbsp; But what about the other side of the coin?&lt;/p&gt;&lt;p&gt;&lt;u&gt;Let&amp;#39;s look at arguments&amp;nbsp;&lt;strong&gt;against&lt;/strong&gt; penetration testing:&lt;/u&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Penetration testing can be argued to be a&amp;nbsp;test of the &amp;#39;tester&amp;#39; not the target&lt;/li&gt;&lt;li&gt;Penetration testing isn&amp;#39;t an exact science, and rarely standardized&lt;/li&gt;&lt;li&gt;Penetration testing results are inconsistent&lt;/li&gt;&lt;li&gt;Penetration testing is too expensive&lt;/li&gt;&lt;li&gt;Penetration testing is only a snapshot in time&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; With those arguments against penetration testing - how can one reasonably conclude it&amp;#39;s a good idea?&amp;nbsp; Well, the fact of the matter is that penetration testing is expensive, inconsistent and rarely an exact, standardized process (unless you pick one of the top firms which have standardized).&amp;nbsp; Yes, sometimes the results are inconsistent and a mere snapshot in time, not an accurate assessment of your stategy as a whole.&amp;nbsp;&amp;nbsp;The argument has also been made that a penetration test result is often a test of the &amp;quot;tester&amp;#39;s&amp;quot; intelligence and hacking prowess, and not necessarily of the defenses...&amp;nbsp;however I would say think twice about that argument.&amp;nbsp; Isn&amp;#39;t that the point?&amp;nbsp; You hire the best, they put their mind to the test against your defenses?&amp;nbsp; So now the pros are weighed against the cons... and the money issue is always on the forefront of the decision to go one way or the other.&amp;nbsp; I will only offer you these&amp;nbsp;words...Strike a balance in your strategy - but do not fail to test yourself.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Remember, the right balance when it comes to penetration testing is in moderation.&amp;nbsp; You can&amp;#39;t reasonably have a penetration test done once a week,&amp;nbsp;as it would destroy your budget.&amp;nbsp; You also&amp;nbsp;shouldn&amp;#39;t do it once a year - as that&amp;#39;s probably too rare.&amp;nbsp; The right balance is a combination of&amp;nbsp;automated tools which you&amp;nbsp;and your security team can use to&amp;nbsp;self-assess plus a seasoned expert tester to check your sanity and environment.&amp;nbsp; &lt;u&gt;Heed my warning... find your vulnerabilities because if you&amp;#39;re not testing the security of your web applications - rest-assured someone else is.&lt;/u&gt;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=75890" width="1" height="1"&gt;</description><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/webinspect/default.aspx">webinspect</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/tools/default.aspx">tools</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/hacking/default.aspx">hacking</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/penetration+testing/default.aspx">penetration testing</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/services/default.aspx">services</category></item><item><title>Top Five Web Application Vulnerabilities 3/17/08 - 3/30/08</title><link>http://portal.spidynamics.com/blogs/top5/archive/2008/04/01/Top-Five-Web-Application-Vulnerabilities-3_2F00_17_2F00_08-_2D00_-3_2F00_30_2F00_08.aspx</link><pubDate>Tue, 01 Apr 2008 21:03:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:75810</guid><dc:creator>mep</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;1) Webutil &amp;#39;webutil.pl&amp;#39; Multiple Remote Command Execution Vulnerabilities&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Webutil is susceptible to multiple command execution vulnerabilities which remote attackers can leverage to execute arbitrary commands. Successful exploitation can lead to a complete compromise of the affected application and underlying system. A fix has not yet been released. Contact the vendor for additional details.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28393"&gt;http://www.securityfocus.com/bid/28393&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;2) IBM Rational ClearQuest Multiple Parameters Multiple Cross-Site Scripting Vulnerabilities&lt;br /&gt;&amp;nbsp;&lt;br /&gt;IBM Rational ClearQuest is susceptible to multiple instances of Cross-Site Scripting. If successfully exploited, these vulnerabilities could allow an attacker to steal confidential information and cookie-based authentication credentials, and possibly lead to execution of arbitrary code in the browser of an unsuspecting user. Patches which resolve these issues have been released. Contact IBM for further information.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28296"&gt;http://www.securityfocus.com/bid/28296&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;3) Imperva SecureSphere Cross-Site Scripting Vulnerability&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Imperva SecureSphere is susceptible to a Cross-Site Scripting vulnerability. If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. An update which addresses this issue has been released. Contact the vendor for additional details. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28279"&gt;http://www.securityfocus.com/bid/28279&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;4) Joomla! and Mambo Components Multiple SQL Injection Vulnerabilities&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Multiple Joomla! and Mambo components are susceptible to SQL Injection vulnerabilities. SQL Injection can give an attacker full access to a backend database, and in certain circumstances can be utilized to take complete control of a system. No fixes have yet been released. Contact the vendor for more information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28271"&gt;http://www.securityfocus.com/bid/28271&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28305"&gt;http://www.securityfocus.com/bid/28305&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28331"&gt;http://www.securityfocus.com/bid/28331&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28325"&gt;http://www.securityfocus.com/bid/28325&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28324"&gt;http://www.securityfocus.com/bid/28324&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28361"&gt;http://www.securityfocus.com/bid/28361&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28427"&gt;http://www.securityfocus.com/bid/28427&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28422"&gt;http://www.securityfocus.com/bid/28422&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28428"&gt;http://www.securityfocus.com/bid/28428&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28409"&gt;http://www.securityfocus.com/bid/28409&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28443"&gt;http://www.securityfocus.com/bid/28443&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28496"&gt;http://www.securityfocus.com/bid/28496&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;5) PHP-Nuke Platinum &amp;#39;dynamic_titles.php&amp;#39; SQL Injection Vulnerability&lt;br /&gt;&amp;nbsp;&lt;br /&gt;PHP-Nuke Platinum is susceptible to a SQL Injection vulnerability. Successful exploitation could give an attacker the means to access or modify backend database contents, or in some circumstances be utilized to take control of the server hosting the database. A fix has not yet been released. Contact the vendor for further details. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28410"&gt;http://www.securityfocus.com/bid/28410&lt;/a&gt;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=75810" width="1" height="1"&gt;</description></item><item><title>&quot;Security Vulnerability&quot; != &quot;Defect&quot;  ; why?</title><link>http://portal.spidynamics.com/blogs/rafal/archive/2008/04/01/Security-vulnerabilities-as-quality-defects_3F00_.aspx</link><pubDate>Tue, 01 Apr 2008 15:18:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:75801</guid><dc:creator>Rafal Los</dc:creator><slash:comments>2</slash:comments><description>&lt;p&gt;It&amp;#39;s one of those obvious things.&amp;nbsp; A defect is a defect, right?&amp;nbsp; Whether the airbag is faulty, or the gas cap doesn&amp;#39;t hold pressure... a defect is a defect.&amp;nbsp; The strange thing is - it hasn&amp;#39;t been that way, and still isn&amp;#39;t that way, in most of the IT shops I&amp;#39;ve been in.&amp;nbsp; Why?&lt;/p&gt;&lt;p&gt;The reason is simple.&amp;nbsp; Historically, &lt;em&gt;security vulnerabilities&lt;/em&gt;&lt;strong&gt; &lt;/strong&gt;have been in a class all their own.&amp;nbsp; In an attempt to put some urgency to the matter, security professionals have labeled defects in the security of their projects (in this case I&amp;#39;m talking about web applications) as an entirely different thing than a functional defect.&amp;nbsp; What we didn&amp;#39;t realize is that we were actually doing a dis-service to ourselves and the security cause.&amp;nbsp; You may not agree with me right now - but I&amp;#39;ll explain this more clearly, and I think you&amp;#39;ll be on board with my thought process.&lt;/p&gt;&lt;p&gt;Let&amp;#39;s talk about defects, in general and then apply it to the matter at hand.&amp;nbsp; First, let&amp;#39;s identify what a defect is...&amp;nbsp; A defect is, in the dictionary sense (cut from &lt;a href="http://dictionary.reference.com/browse/defect" target="_blank"&gt;dictionary.com)&lt;/a&gt;:&lt;/p&gt;&lt;p&gt;&lt;span class="me"&gt;&lt;strong&gt;de&amp;middot;fect&lt;/strong&gt;&lt;/span&gt; &lt;span class="pronset"&gt;&lt;font color="#116699"&gt;&amp;nbsp;&lt;img border="0" height="15" src="http://cache.lexico.com/g/d/premium.gif" width="16" /&gt;&amp;nbsp; &lt;img border="0" class="luna-Img" height="4" src="http://cache.lexico.com/dictionary/graphics/luna/thinsp.png" width="2" /&gt;&lt;/font&gt;&lt;a href="https://secure.reference.com/premium/login.html?rd=2&amp;amp;u=http%3A%2F%2Fdictionary.reference.com%2Fbrowse%2Fdefect"&gt;&lt;font color="#116699"&gt;&lt;img border="0" height="18" src="http://cache.lexico.com/g/d/speaker.gif" width="17" /&gt;&lt;/font&gt;&lt;/a&gt;&lt;font color="#116699"&gt;&amp;nbsp;&amp;nbsp;&lt;/font&gt;&lt;span class="show_ipapr" style="display:none;"&gt;&lt;span class="prondelim"&gt;&lt;font color="#880000" face="Arial Unicode MS"&gt;/&lt;/font&gt;&lt;/span&gt;&lt;span class="pg"&gt;&lt;em&gt;&lt;font color="#558811"&gt;n. &lt;/font&gt;&lt;/em&gt;&lt;/span&gt;&lt;font size="3"&gt;&lt;font color="#880000"&gt;&lt;span class="pron"&gt;ˈdi&lt;img border="0" class="luna-Img" height="4" src="http://cache.lexico.com/dictionary/graphics/luna/thinsp.png" width="2" /&gt;fɛkt, &lt;/span&gt;&lt;span class="pron"&gt;dɪˈfɛkt; &lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;span class="pg"&gt;&lt;em&gt;&lt;font color="#558811"&gt;v. &lt;/font&gt;&lt;/em&gt;&lt;/span&gt;&lt;font color="#880000"&gt;&lt;span class="pron"&gt;dɪˈfɛkt&lt;/span&gt;&lt;span class="prondelim"&gt;&lt;font face="Arial Unicode MS"&gt;/&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;font color="#116699"&gt; &lt;/font&gt;&lt;a class="pronlink" title="Click for pronunciation key"&gt;&lt;u&gt;&lt;font color="#116699"&gt;Pronunciation Key&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;span class="pron_toggle" style="display:inline;"&gt;&lt;span class="prondelim"&gt;&lt;font color="#880000" face="Arial Unicode MS"&gt; - &lt;/font&gt;&lt;/span&gt;&lt;a class="pronlink" title="Click to show spelled pronunciation"&gt;&lt;u&gt;&lt;font color="#116699"&gt;Show Spelled Pronunciation&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="show_spellpr" style="display:inline;"&gt;&lt;span class="prondelim"&gt;&lt;font color="#880000" face="Arial Unicode MS"&gt;[&lt;/font&gt;&lt;/span&gt;&lt;span class="pg"&gt;&lt;em&gt;&lt;font color="#558811"&gt;n. &lt;/font&gt;&lt;/em&gt;&lt;/span&gt;&lt;font color="#880000"&gt;&lt;font face="Verdana"&gt;&lt;span class="pron"&gt;&lt;strong&gt;dee&lt;/strong&gt;-fekt, &lt;/span&gt;&lt;span class="pron"&gt;di-&lt;strong&gt;fekt&lt;/strong&gt;; &lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;span class="pg"&gt;&lt;em&gt;&lt;font color="#558811"&gt;v. &lt;/font&gt;&lt;/em&gt;&lt;/span&gt;&lt;font color="#880000"&gt;&lt;span class="pron"&gt;&lt;font face="Verdana"&gt;di-&lt;strong&gt;fekt&lt;/strong&gt;&lt;/font&gt;&lt;/span&gt;&lt;span class="prondelim"&gt;&lt;font face="Arial Unicode MS"&gt;]&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;font color="#116699"&gt; &lt;/font&gt;&lt;a class="pronlink" title="Click for pronunciation key"&gt;&lt;u&gt;&lt;font color="#116699"&gt;Pronunciation Key&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;span class="pron_toggle" style="display:inline;"&gt;&lt;span class="prondelim"&gt;&lt;font color="#880000" face="Arial Unicode MS"&gt; - &lt;/font&gt;&lt;/span&gt;&lt;a class="pronlink" title="Click to show IPA pronunciation"&gt;&lt;u&gt;&lt;font color="#116699"&gt;Show IPA Pronunciation&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;font color="#116699"&gt; &lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="body"&gt;&lt;span class="pg"&gt;&lt;em&gt;&lt;font color="#558811"&gt;&amp;ndash;noun &lt;/font&gt;&lt;/em&gt;&lt;/span&gt;&lt;table class="luna-Ent"&gt;&lt;tr&gt;&lt;td class="dn"&gt;1.&lt;/td&gt;&lt;td&gt;a shortcoming, fault, or imperfection: &lt;span class="ital-inline"&gt;&lt;em&gt;a defect in an argument; a defect in a machine. &lt;/em&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;table class="luna-Ent"&gt;&lt;tr&gt;&lt;td class="dn"&gt;2.&lt;/td&gt;&lt;td&gt;lack or want, esp. of something essential to perfection or completeness; deficiency: &lt;span class="ital-inline"&gt;&lt;em&gt;a defect in hearing. &lt;/em&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;p&gt;OK, easy enough right?&amp;nbsp; So the first meaning is clear; a defect is a shortcoming, fault, or imperfection.&amp;nbsp; It is reasoned that a defect in a web-based application results when functionality X doesn&amp;#39;t work as required.&amp;nbsp; Say you have a button, and the &lt;em&gt;functional specification&lt;/em&gt; (we&amp;#39;ll get back to this gem in a minute) calls for the button to perform some action, A.&amp;nbsp; During the testing phase of the application, before release to production, a tester or tool is utilized to test the functionality of that button, but instead of action A happening, some other action B happens.&amp;nbsp; This is a defect.&amp;nbsp; There is no doubt in anyone&amp;#39;s mind that this immediately gets classified as a defect, put into the defect tracking system and sent back to the developer for remediation.&amp;nbsp; The defect is classified as a higher-priority defect if the function happens to be one that is showcased, or important to the overall functionality of the application.&amp;nbsp; Those of you that already use the HP Quality Center tools know exactly what I&amp;#39;m talking about, and know how this process works.&amp;nbsp; Here&amp;#39;s the strange twist though - why is quality testing only done with &lt;em&gt;good data&lt;/em&gt;?&amp;nbsp; I understand that you want to make sure that the test cases work properly - but why are the testing options limited?&amp;nbsp; The issue at hand here is a very narrow view of defects, and defect testing.&lt;/p&gt;&lt;p&gt;Back in college, I took very basic programming class and had to write a program that was a calculator.&amp;nbsp; It would ask for two inputs of numbers, and then give you an option to perform either an addition, subtraction, multiplication or division of the inputs.&amp;nbsp; Generally, it was assumed that these would be numbers, but what if they weren&amp;#39;t numbers?&amp;nbsp; Most of the students in the class, myself included, never thought about ... &amp;quot;What if someone enters a letter or some other unexpected input?&amp;quot;&amp;nbsp; Well, luckily, the professor chose my application, put it up on the screen for the whole class to see, and promptly entered a and b for the two inputs and tried to add them.&amp;nbsp; When my application core dumped, he explained to the class why I had gotten my first F on a project.&amp;nbsp; I learned a very valuable lesson that day - developers must brace their applications for unexpected input.&amp;nbsp; &amp;quot;Why would anyone want to enter something other than numbers?&amp;quot; wasn&amp;#39;t a good enough answer to explain why my application failed.&amp;nbsp; Let&amp;#39;s apply this lesson I learned back in college to today&amp;#39;s application programmers and functional testers.&lt;/p&gt;&lt;p&gt;Here are the reasons why I think security &lt;em&gt;vulnerabilities&lt;/em&gt; aren&amp;#39;t seen as &amp;quot;defects&amp;quot; in general...&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Security professionals have insisted that a vulnerability is its own separate category&lt;/strong&gt; - While it is true, some security vulnerabilities are a whole new level of &amp;quot;bad&amp;quot; they should be considered just like any other defect in the application for the sake of tracking and remediation.&amp;nbsp; Web platform managers are generally concerned with meeting the demands of their customers and producing code that is defect-free - and it&amp;#39;s our own fault that &amp;quot;vulnerabilities&amp;quot; of the security variety have become some ethereal, magical issue for security nerds to worry about.&amp;nbsp; This matter can only be fixed by changing the naming back... a vulnerability is a defect, period.&amp;nbsp; &lt;em&gt;Security vulnerabilities must be explained as &amp;quot;high-criticality defects&amp;quot; to developers, managers and customers otherwise this situation will never change.&lt;/em&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Functional specifications rarely, if ever - call for for security validation&lt;/strong&gt; - Functional specifications aren&amp;#39;t written by security professionals, generally.&amp;nbsp; At best, security professionals have a chance to review the functional specification way too late into the process, while the code is being written and readied for production.&amp;nbsp; This is, once again, our own fault most of the time.&amp;nbsp; The answer to this dilemma is a two-pronged attack.&amp;nbsp; &lt;em&gt;We as security professionals must educate those that write functional specifications, and enlighten them to the need for security features.&amp;nbsp; At the same time, we must work hard to have an active input in the writing and release of functional specification documents.&amp;nbsp;&lt;/em&gt; These two vectors are critical to getting secure code as an end-product.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Programmers don&amp;#39;t typically think about malicious users&lt;/strong&gt; - While it would be great to think that one day all developers will inherently write secure code because they will have &amp;quot;learned&amp;quot; what security is, and how important it is to the application - the fact is that it&amp;#39;s a pipe dream.&amp;nbsp; Developers care about one thing... meeting functional specifications in the least amount of time possible, and moving on to the next project.&amp;nbsp; Developers like to write optimized code that accomplishes the required tasks in as little time as possible.&amp;nbsp; Solving #2 above will also partly solve this problem.&amp;nbsp; In addition, &lt;em&gt;developers must be given the tools (such as static and dynamic code analysis tools as plug-ins to their IDEs) to make their jobs easier&lt;/em&gt;.&amp;nbsp; It is not reasonable to expect developers to be security experts in all aspects, so we must arm them with the tools to be experts, without having to do too much extra work or they won&amp;#39;t use those tools.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;So what have we learned today?&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Security vulnerabilities must be re-classified as easily-understandable &amp;quot;functional defects&amp;quot;&lt;/li&gt;&lt;li&gt;Funcitonal specifications must be written to include provisions for security validation&lt;/li&gt;&lt;li&gt;Quality professionals must be given the tools to test for &amp;quot;security defects&amp;quot; in web applications to close the loop in the lifecycle&lt;/li&gt;&lt;li&gt;Developers must be educated and also given the tools to write more secure code with minimal additional effort&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;-- I welcome your comments!&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=75801" width="1" height="1"&gt;</description><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/defects/default.aspx">defects</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/vulnerabilities/default.aspx">vulnerabilities</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/security/default.aspx">security</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/functional+specification/default.aspx">functional specification</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/quality/default.aspx">quality</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/testing/default.aspx">testing</category><category domain="http://portal.spidynamics.com/blogs/rafal/archive/tags/development/default.aspx">development</category></item><item><title>DevInspect 5.0 is now available.</title><link>http://portal.spidynamics.com/blogs/products/archive/2008/04/01/DevInspect-5.0-is-now-available_2E00_.aspx</link><pubDate>Tue, 01 Apr 2008 04:09:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:75792</guid><dc:creator>patrickwolf</dc:creator><slash:comments>0</slash:comments><description>&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Introducing HP DevInspect 5.0&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP DevInspect extends the reach of HP&amp;rsquo;s Application Lifecycle Optimization portfolio into product development.&amp;nbsp; Combining our award-winning dynamic application scanning technology with static code analysis, HP DevInspect is the only tool available that performs true Hybrid Analysis &amp;ndash; both white-box and black-box testing.&amp;nbsp; HP DevInspect is seamlessly integrated with the Integrated Development Environment (IDE) &amp;ndash; Visual Studio for .NET or Eclipse or RAD for Java &amp;ndash; minimizing the training required to learn a new tool and eliminating any disruption of the development timeline.&amp;nbsp; The release of HP DevInspect 5.0 further enhances Hybrid Analysis and increases development efficiencies with the following features:&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Visual Studio 2008 Support&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP DevInspect &amp;nbsp;for .Net now supports Microsoft Visual Studio 2008 and Visual Studio 2005.&amp;nbsp; Businesses can now test for vulnerabilities with Hybrid Analysis regardless of the Visual Studio IDE preferred by their developers even in mixed environments.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Struts 1.x MVC support&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Struts is one of the most popular java frameworks used for web application development. HP DevInspect for Java 5.0 fully supports integrated security testing within Eclipse or IBM RAD for applications using the Struts framework.&amp;nbsp; Corporations using industry standard design practices can now take full advantage of the Hybrid Analysis inherent in HP DevInspect.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Hybrid Analysis&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP DevInspect is the only product to combine static analysis of all byte-code (both Java and MSIL) with dynamic black-box vulnerability scanning in one.&amp;nbsp; The static &amp;nbsp;analysis and dynamic scan engines have both been upgraded in HP DevInspect 5.0 to increase the accuracy, performance, and repeatability of our Hybrid Analysis. The time and money spent finding and fixing security vulnerabilities can now be dramatically decreased by equipping developers with an IDE with built-in Hybrid Analysis.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Vista Support&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP DevInspect for Java and HP DevInspect for .Net are now fully supported on Microsoft Vista.&amp;nbsp; IT organizations looking to upgrade their existing desktop environments can transition their developers without risking their ability to perform Hybrid Analysis on their applications. &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200^9564_4000_100__" title="DevInspect Home Page"&gt;Ready for Download today!&lt;/a&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=75792" width="1" height="1"&gt;</description><category domain="http://portal.spidynamics.com/blogs/products/archive/tags/DevInspect/default.aspx">DevInspect</category></item><item><title>QAInspect 5.0 is now available.</title><link>http://portal.spidynamics.com/blogs/products/archive/2008/03/31/QAInspect-5.0-is-now-available_2E00_.aspx</link><pubDate>Mon, 31 Mar 2008 20:02:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:75778</guid><dc:creator>patrickwolf</dc:creator><slash:comments>1</slash:comments><description>&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Introducing HP QAInspect 5.0&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;HP QAInspect completes the third pillar of Application Lifecycle Optimization.&amp;nbsp; Does it work?&amp;nbsp; Does it perform?&amp;nbsp; Is it secure?&amp;nbsp; Built on the foundation of the award-winning application scanning technology in HP WebInspect, QAInspect enables quality professionals to fully manage the process of finding and fixing security defects early in the application lifecycle. This ability to manage security defect testing early in the application lifecycle mitigates risk in the application, saves money on revisions over the life of the application, and produces more holistic data &amp;nbsp;for a Go/No Go decision.&amp;nbsp; The upcoming release of HP QAInspect 5.0 extends the already robust integration with Quality Center with the following new features:&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Defect Staging&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;New in QAInspect 5,0 is a staging area to vet vulnerabilities before they are added to the defect table within QC.&amp;nbsp; Users can fully test and validate all vulnerabilities found by the scan to ensure that application developers are only spending development cycles fixing confirmed defects.&amp;nbsp; &lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Defect Consolidation&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Vulnerabilities found during a scan can now be viewed as a consolidated list, grouped by application page or defect type.&amp;nbsp; For example, a user may view all vulnerabilities found on the login page of an application.&amp;nbsp; Similarly, a user may view all Cross-Site Scripting vulnerabilities or all SQL Injection vulnerabilities grouped into a single pane.&amp;nbsp; The ability to group vulnerabilities allows users to more quickly log specific defects and assign defect tasks to developers with greater accuracy.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Folder Restrictions&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Restrict the crawl and audit of a scan to a particular folder. This allows much more granular control of the testing allowing for better targeted security testing. Once a particular application section has been audited and all security issues mitigated to an acceptible degree it can be moved to regression; focusing new security testing and fixes on new functional areas of the application.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;Parameter Highlighting&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;As the size and complexity of web application pages grow the ability to quickly find a specific parameter within a vulnerable page becomes a greater burden.&amp;nbsp; In order to eliminate the time wasted by developers searching a page for a particular vulnerability all defect reports now highlight the specific vulnerable parameter within the HTTP Request/Response pair.&amp;nbsp; Developers can easily find the vulnerable part of the application and apply a fix with limited downtime.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;strong&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;a href="https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&amp;amp;cp=1-11-201-200^9561_4000_100__" title="QAInspect Home Page"&gt;Trial License Now Available (Click Here)&lt;/a&gt;&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin:0in 0in 0pt;"&gt;&lt;span style="color:#1f497d;"&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;This release includes a trial license allowing Quality Center customers to download and evaluate QAInspect for 15 days; enabling them to make better purchase decisions.&amp;nbsp; Talk to your sales representative for more details.&lt;/font&gt;&lt;/font&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=75778" width="1" height="1"&gt;</description></item><item><title>Welcome!</title><link>http://portal.spidynamics.com/blogs/rafal/archive/2008/03/27/Welcome_2100_.aspx</link><pubDate>Thu, 27 Mar 2008 14:18:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:75633</guid><dc:creator>Rafal Los</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&amp;nbsp; First, let me say thanks for clicking and taking a minute to read my column.&amp;nbsp; I hope to keep your attention while teaching you something you hopefully already don&amp;#39;t know so come back often, bookmark me, or feed it into your RSS reader.&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Let me use this first article to explain the types of content you&amp;#39;ll find&amp;nbsp;in this column, and some of my thought process when choosing what to write.&amp;nbsp;&amp;nbsp;My&amp;nbsp;column typically includes the following:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;High-level discussions of &lt;strong&gt;security&lt;/strong&gt; topics relevant in today&amp;#39;s world - too many times the small stories are the big news and they don&amp;#39;t get enough coverage&lt;/li&gt;&lt;li&gt;Semi-technical pieces on important issues which you should care about - it&amp;#39;s a shame how the message of an article can get lost in the technical details.&amp;nbsp; Not everyone reads in binary and I understand that, and write my column accordingly.&lt;/li&gt;&lt;li&gt;In-depth analysis of specific headline-grabbing issues with a not-just-for-nerds spin - We&amp;#39;ll take deeper dives into topics which grab the headlines with technical talk, explanations, and as always the &amp;quot;Why you should care&amp;quot; section.&lt;/li&gt;&lt;li&gt;Articles relevant to the business manager, the executive, and the aspiring CISO - Have you noticed how few columns there are written in an intelligent, technical and business-relevant way that you the manager can read and understand?&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp; You, my readers, are always invited to reply with your opinions, thoughts, and debate.&amp;nbsp; I thik a one-sided conversation is boring so I welcome your replies.&amp;nbsp; My only request is that you keep your comments and replies professional and work-safe; this is, after all, a column you would share with your manager.&lt;/p&gt;&lt;p&gt;&amp;nbsp; As a final disclaimer, the thoughts, opinions, and views shared here are my own - not anyone else&amp;#39;s.&amp;nbsp; If you don&amp;#39;t agree - write a rebuttal.&amp;nbsp; If you don&amp;#39;t like it, don&amp;#39;t read it.&lt;/p&gt;&lt;p&gt;&amp;nbsp;Thanks, I look forward to having you as a regular!&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=75633" width="1" height="1"&gt;</description></item><item><title>Top Five Web Application Vulnerabilities 3/3/08 - 3/16/08</title><link>http://portal.spidynamics.com/blogs/top5/archive/2008/03/17/Top-Five-Web-Application-Vulnerabilities-3_2F00_3_2F00_08-_2D00_-3_2F00_16_2F00_08.aspx</link><pubDate>Mon, 17 Mar 2008 20:52:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:75328</guid><dc:creator>mep</dc:creator><slash:comments>0</slash:comments><description>&lt;span class="433285215-17032008"&gt;&lt;p&gt;1) Dokeos Multiple Remote Code Execution and Cross-Site Scripting Vulnerabilities&lt;/p&gt;&lt;p&gt;Dokeos is susceptible to multiple remote code execution and Cross-Site Scripting vulnerabilities. Exploitation of these vulnerabilities could lead to a complete compromise of the affected application and underlying system, and also be used to steal cookie based authentication credentials. Dokeos 1.8.4 SP3 has been released to address these issues. Contact the vendor for further information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28121"&gt;http://www.securityfocus.com/bid/28121&lt;/a&gt;&lt;/p&gt;&lt;p&gt;2) Adobe ColdFusion Multiple Cross-Site Scripting Vulnerabilities&lt;/p&gt;&lt;p&gt;Adobe ColdFusion is susceptible to multiple instances of Cross-Site Scripting. If successfully exploited, these vulnerabilities could allow an attacker to steal confidential information and cookie-based authentication credentials, and possibly lead to execution of arbitrary code in the browser of an unsuspecting user. Adobe has released advisory APSB08-06 and APSB08-07 to address these issues. Contact the vendor for additional details. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28205"&gt;http://www.securityfocus.com/bid/28205&lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) F5 BIG-IP Web Management Interface Console HTML Injection Vulnerability&lt;/p&gt;&lt;p&gt;F5 BIG-IP is susceptible to an HTML Injection vulnerability. When exploited, this vulnerability will allow an attacker to execute arbitrary script code in the browser of an unsuspecting victim in context of the affected device. This could possibly lead to theft of cookie-based authentication credentials or be utilized to launch other attacks. A fix has not yet been released. Contact the vendor for more information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28151"&gt;http://www.securityfocus.com/bid/28151&lt;/a&gt;&lt;/p&gt;&lt;p&gt;4) Adobe LiveCycle Workflow Management Login Page Cross-Site Scripting Vulnerability&lt;/p&gt;&lt;p&gt;Adobe LiveCycle Workflow is susceptible to a Cross-Site Scripting vulnerability. If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. Adobe has released advisory APSB0-10 to address this issue. Contact the vendor for further details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28209/"&gt;http://www.securityfocus.com/bid/28209/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;5) Ruby WEBrick Remote Directory Traversal and Information Disclosure Vulnerabilities&lt;/p&gt;&lt;p&gt;Ruby WEBrick is susceptible to directory traversal and information disclosure vulnerabilities. Remote attackers can leverage these vulnerabilities to access the contents of arbitrary files, gathering information which will likely be utilized in orchestrating more dangerous attacks. Fixes which resolve these issues have been released. Contact the vendor for additional details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28123/"&gt;http://www.securityfocus.com/bid/28123/&lt;/a&gt;&lt;/p&gt;&lt;/span&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=75328" width="1" height="1"&gt;</description></item><item><title>Top Five Web Application Vulnerabilities 2/18/2008 - 3/02/2008</title><link>http://portal.spidynamics.com/blogs/top5/archive/2008/03/03/Top-Five-Web-Application-Vulnerabilities-2_2F00_18_2F00_2008-_2D00_-3_2F00_02_2F00_2008.aspx</link><pubDate>Mon, 03 Mar 2008 22:21:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:74845</guid><dc:creator>mep</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;1) IBM Lotus QuickPlace &amp;#39;Main.nsf&amp;#39; Cross-Site Scripting Vulnerability&lt;br /&gt;&amp;nbsp;&lt;br /&gt;IBM Lotus QuickPlace is susceptible to a Cross-Site Scripting vulnerability.&amp;nbsp; If exploited, this vulnerability could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. A fix has not yet been released. Contact IBM for additional details. &lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27871"&gt;http://www.securityfocus.com/bid/27871&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;2) PHP Nuke Multiple Modules SQL Injection&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Multiple PHP Nuke modules contain SQL Injection vulnerabilities. Successful exploitation could give an attacker the means to access or modify backend database contents, or in some circumstances be utilized to take control of the server hosting the database. No fixes have yet to be released. Contact the vendor for further information.&lt;br /&gt;&amp;nbsp;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27863"&gt;http://www.securityfocus.com/bid/27863&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27879"&gt;http://www.securityfocus.com/bid/27879&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27894"&gt;http://www.securityfocus.com/bid/27894&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27897"&gt;http://www.securityfocus.com/bid/27897&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27909"&gt;http://www.securityfocus.com/bid/27909&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27912"&gt;http://www.securityfocus.com/bid/27912&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27886"&gt;http://www.securityfocus.com/bid/27886&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27932"&gt;http://www.securityfocus.com/bid/27932&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27930"&gt;http://www.securityfocus.com/bid/27930&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27930"&gt;http://www.securityfocus.com/bid/27930&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27930"&gt;http://www.securityfocus.com/bid/27930&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27952"&gt;http://www.securityfocus.com/bid/27952&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27958"&gt;http://www.securityfocus.com/bid/27958&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27955"&gt;http://www.securityfocus.com/bid/27955&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27957"&gt;http://www.securityfocus.com/bid/27957&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27980"&gt;http://www.securityfocus.com/bid/27980&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27991"&gt;http://www.securityfocus.com/bid/27991&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28030"&gt;http://www.securityfocus.com/bid/28030&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28063"&gt;http://www.securityfocus.com/bid/28063&lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) Joomla! and Mambo Components Multiple SQL Injection Vulnerabilities&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Multiple Joomla! and Mambo components are susceptible to SQL Injection vulnerabilities. SQL Injection can give an attacker full access to a backend database, and in certain circumstances can be utilized to take complete control of a system. No fixes have yet been released. Contact the vendor for more information.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27849"&gt;http://www.securityfocus.com/bid/27849&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27860"&gt;http://www.securityfocus.com/bid/27860&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27864"&gt;http://www.securityfocus.com/bid/27864&lt;/a&gt; &lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27883"&gt;http://www.securityfocus.com/bid/27883&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27884"&gt;http://www.securityfocus.com/bid/27884&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27887"&gt;http://www.securityfocus.com/bid/27887&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27888"&gt;http://www.securityfocus.com/bid/27888&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27898"&gt;http://www.securityfocus.com/bid/27898&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27921"&gt;http://www.securityfocus.com/bid/27921&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27922"&gt;http://www.securityfocus.com/bid/27922&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27923"&gt;http://www.securityfocus.com/bid/27923&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27926"&gt;http://www.securityfocus.com/bid/27926&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27956"&gt;http://www.securityfocus.com/bid/27956&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27970"&gt;http://www.securityfocus.com/bid/27970&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27975"&gt;http://www.securityfocus.com/bid/27975&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27971"&gt;http://www.securityfocus.com/bid/27971&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27994"&gt;http://www.securityfocus.com/bid/27994&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/28018"&gt;http://www.securityfocus.com/bid/28018&lt;/a&gt;&lt;/p&gt;&lt;p&gt;4) Spyce Sample Scripts Multiple Input Validation Vulnerabilities&lt;/p&gt;&lt;p&gt;Spyce Sample Scripts are susceptible to multiple input validation vulnerabilities including Cross-Site Scripting and Path Disclosure. An attacker could possibly execute arbitrary script code in the browser of an unsuspecting user in context of the affected site, and could also retrieve the server&amp;#39;s web root path. A fix has not yet been released. Contact the vendor for more details. &lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/27898"&gt;http://www.securityfocus.com/bid/27898&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&lt;br /&gt;5) Drupal Multiple HTML Injection Vulnerabilities&lt;br /&gt;&amp;nbsp;&lt;br /&gt;Drupal is susceptible to multiple HTML Injection vulnerabilities. HTML Injection can be leveraged to add content into a web server&amp;rsquo;s response, which can then be used to steal cookie-based authentication credentials, execute arbitrary code in context of the site, or simply alter how the site appears. An update that addresses these issues has been released. Contact the vendor further details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/28026"&gt;http://www.securityfocus.com/bid/28026&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=74845" width="1" height="1"&gt;</description></item><item><title>Top Five Web Application Vulnerabilities 2/4/2008 - 2/17/2008</title><link>http://portal.spidynamics.com/blogs/top5/archive/2008/02/19/Top-Five-Web-Application-Vulnerabilities-2_2F00_4_2F00_2008-_2D00_-2_2F00_17_2F00_2008.aspx</link><pubDate>Tue, 19 Feb 2008 21:43:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:74312</guid><dc:creator>mep</dc:creator><slash:comments>0</slash:comments><description>&lt;font size="2"&gt;&lt;p&gt;1) Microsoft Internet Information Services ASP Remote Code-Execution Vulnerability&lt;/p&gt;&lt;p&gt;IIS is susceptible to a remote code-execution vulnerability that can be exploited via malicious input to vulnerable ASP pages. Attackers who successfully exploit this vulnerability could execute arbitrary code in context of the Worker Process Identity, which has Network Services privileges by default. Security bulletins which resolve this issue have been released for both IIS 5.1 and 6.0. Contact Microsoft for additional details.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/27676/"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27676/&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/font&gt;&lt;font size="2"&gt;&lt;p&gt;2) WordPress &amp;#39;wp-admin/options.php&amp;#39; Remote Code-Execution Vulnerability&lt;/p&gt;&lt;p&gt;WordPress is susceptible to a remote code-execution vulnerability due to a failure of the application to properly sanitize data. A remote attacker can leverage this vulnerability to execute arbitrary PHP code in context of the application, possibly leading to a complete compromise of the affected system. WordPress MU 1.3.2 has been released to correct this issue. Contact WordPress for further information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/27633/"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27633/&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/font&gt;&lt;font size="2"&gt;&lt;p&gt;3) Cisco Unified Communications Manager &amp;#39;key&amp;#39; Parameter SQL Injection Vulnerability&lt;/p&gt;&lt;p&gt;Cisco Unified Communications Manager is susceptible to a SQL Injection vulnerability. Successful exploitation could give an attacker the means to access or modify backend database contents, or in some circumstances be utilized to take control of the server hosting the database. An advisory which addresses this issue has been released. Contact Cisco for more information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/27775"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27775&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/font&gt;&lt;font size="2"&gt;&lt;p&gt;4) IBM Lotus Quickr Unspecified Cross-Site Scripting Vulnerability&lt;/p&gt;&lt;p&gt;IBM Lotus Quickr is susceptible to a Cross-Site Scripting vulnerability. Successful exploitation of Cross-Site Scripting could give an attacker the means to perform account hijacking, execute malicious scripts, or steal proprietary information. Fixes which address this issue have been released. Contact IBM for additional details.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27840"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27840&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;font size="2"&gt;5) Joomla! and Mambo Components Multiple SQL Injection Vulnerabilities &lt;/font&gt;&lt;/p&gt;&lt;p&gt;Multiple Joomla! and Mambo components are susceptible to SQL Injection vulnerabilities. SQL Injection can give an attacker full access to a backend database, and in certain circumstances can be utilized to take complete control of a system. No fixes have yet been released. Contact the vendor for more information.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/27609"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27609&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27617"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27617&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27648"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27648&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27649"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27649&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27673"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27673&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27679"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27679&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27691"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27691&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27692"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27692&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27695"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27695&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27731"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27731&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27748"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27748&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27783"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27783&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27780"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27780&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;font size="2"&gt; (Joomla! only)&lt;br /&gt;&lt;/font&gt;&lt;a href="http://www.securityfocus.com/bid/27781"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27781&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27784"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27784&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27842"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27842&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27808"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27808&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27805"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27805&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;font size="2"&gt; (Joomla! only)&lt;br /&gt;&lt;/font&gt;&lt;a href="http://www.securityfocus.com/bid/27818"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27818&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27820"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27820&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27822"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27822&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27821"&gt;&lt;u&gt;&lt;font color="#0000ff" size="2"&gt;http://www.securityfocus.com/bid/27821&lt;/font&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/font&gt;&lt;img src="http://portal.spidynamics.com/aggbug.aspx?PostID=74312" width="1" height="1"&gt;</description></item><item><title>Top Five Web Application Vulnerabilities 1/19/08 - 2/03/08</title><link>http://portal.spidynamics.com/blogs/top5/archive/2008/02/04/Top-Five-Web-Application-Vulnerabilities-1_2F00_19_2F00_08-_2D00_-2_2F00_03_2F00_0.aspx</link><pubDate>Mon, 04 Feb 2008 22:18:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:73908</guid><dc:creator>mep</dc:creator><slash:comments>0</slash:comments><description>&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;1) Coppermine Photo Gallery Multiple Remote Command Execution Vulnerabilities&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;Coppermine Photo Gallery&amp;nbsp;is susceptible to multiple remote command execution vulnerabilties. &lt;font size="2"&gt;Remote attackers can exploit this vulnerability to execute arbitrary commands with the privileges of the affected application, possibly leading to compromise of the application and the underlying web server.&amp;nbsp; Coppermine Photo Gallery 1.4.15 has been released to resolve these and other issues. Contact the vendor for additonal information.&amp;nbsp;&lt;br /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27512" title="http://www.securityfocus.com/bid/27512"&gt;http://www.securityfocus.com/bid/27512&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;2) PHP-Nuke Search Module &amp;#39;sid&amp;#39; Parameter SQL Injection Vulnerability&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;PHP-Nuke is susceptible to a SQL Injection vulnerability. S&lt;font size="2"&gt;QL Injection can allow an attacker full access to a backend database, and in certain circumstances can be utilized to take complete control of a system. A fix has not yet been released. Contact the vendor for further details.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27408" title="http://www.securityfocus.com/bid/27408"&gt;http://www.securityfocus.com/bid/27408&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;3)&amp;nbsp;Novell GroupWise WebAccess Multiple Cross-Site Scripting Vulnerabilities&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;Novell GroupWise WebAccess is susceptible to multiple instances of Cross-Site Scripting. I&lt;font size="2"&gt;f successful, Cross-Site Scripting vulnerabilities can be exploited to manipulate or steal cookies, create requests that can be mistaken for those of a valid user, compromise confidential information, or execute malicious code on end user systems. Fixes which address these issues have been released. Contact the vendor for more details.&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;font size="2"&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27582" title="http://www.securityfocus.com/bid/27582"&gt;http://www.securityfocus.com/bid/27582&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;4) WordPress Plug-ins Multiple Vulnerabilities&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;Several WordPress plug-ins are susceptible to vulnerabilities including SQL Injection and Cross-Site Scripting. &lt;font size="2"&gt;If successfully exploited, these vulnerabilities could allow an attacker to steal confidential information and cookie-based authentication credentials, and possibly lead to execution of arbitrary code in the browser of an unsuspecting user. &lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;font size="2"&gt;No upgrade or patch has yet been released to resolve these issues. &lt;/font&gt;Contact the vendor for additional information. &lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;p&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27525" title="http://www.securityfocus.com/bid/27525"&gt;http://www.securityfocus.com/bid/27525&lt;br /&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/a&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27504" title="http://www.securityfocus.com/bid/27504"&gt;http://www.securityfocus.com/bid/27504&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27464" title="http://www.securityfocus.com/bid/27464"&gt;http://www.securityfocus.com/bid/27464&lt;br /&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/a&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27362" title="http://www.securityfocus.com/bid/27362"&gt;http://www.securityfocus.com/bid/27362&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;5) Drupal Modules Multiple Vulnerabilities&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;Several Drupal&amp;nbsp;modules are&amp;nbsp;susceptible to&amp;nbsp;vulnerabilities including Authentication Bypass, Cross-Site Scripting, and HTML Injection. Successful exploitation can lead to escalation of&amp;nbsp;privileges, alter how the site appears, steal authentication credentials, or execute malicious scripts in the browsers of unsuspecting users.&amp;nbsp;Upgrades which resolve these issues have been released. Contact the vendor for further information.&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27545" title="http://www.securityfocus.com/bid/27545"&gt;http://www.securityfocus.com/bid/27545&lt;/a&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27544" title="http://www.securityfocus.com/bid/27544"&gt;http://www.securityfocus.com/bid/27544&lt;/a&gt; &lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27543" title="http://www.securityfocus.com/bid/27543"&gt;http://www.securityfocus.com/bid/27543&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="630533319-04022008"&gt;&lt;a href="http://www.securityfocus.com/bid/27444" title="http://www.securityfocus.com/bid/27444"&gt;http://www.securityfocus.com/bid/27444&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/div&gt;&lt;div&gt;&lt;font face