Mon, 2 Oct 2006 8:30:00 PDT
SANTA CLARA, CA -- (MARKET WIRE) -- 10/02/2006 -- Cenzic, Inc., a leading provider of automated application security assessment and compliance solutions, today announced that researchers in the company's CIA (Cenzic Intelligent Analysis) Lab have discovered a cross-site scripting vulnerability in Blojsom, a Java-based multi-blog software package that is the underlying technology for such blogs as Apple Computer's OS X Server Weblog Server. This vulnerability has the potential to compromise a user's account.
According to Cenzic analysts, users who register and publish on a blog site based on Blojsom can be unknowingly left susceptible to malicious activities. Other leading blog servers have also recently been cited as vulnerable. [Editor's Note: Please see Cenzic press release, "Cenzic Intelligent Analysis Lab Identifies Potentially Threatening Application Vulnerabilities in Blog Technology" at http://easypr.marketwire.com/easyir/prssrel.do?easyirid=308DDC21CFAD2E72&version=live&prid=166721&releasejsp=release ]. Cross-Site Scripting typically involves executing commands in a user's browser to display unintended content, or with the intent of stealing the user's login credentials or other personal information. This information can be used by the attacker to access web sites and services for which the compromised credentials are valid (e.g., identity theft). In some cases, the attacker might be able to use this information to hijack or further compromise the user's HTTP sessions.
Once this vulnerability was discovered, the Blojsom team was immediately notified and has applied a fix which is available in Blojsom 2.32. Users can be classified as both, users of a blogging site running Blojsom as well as users who actually host a Blojsom weblogging application. Cenzic's findings have been submitted to CERT (tracking number VU#366900) and have been verified by Bugtraq (BUGTRAQ #20026 http://www.securityfocus.com/bid/20026/info, http://www.securityfocus.com/archive/1/446009). Cenzic has also submitted signatures to Snort (www.snort.org), which are part of the Snort community rule set. Sig Ids SIDs 100000895-100000899.
CIA specializes in the continuous research of application vulnerabilities and the development of remediation strategies to assist customers with their web application security needs in enterprise environments. Since discovering the hole, Cenzic's research professionals have worked with the Blojsom team to provide counsel and support in addressing the issue.
Using a proprietary formula for calculating the severity of vulnerability information, Cenzic deemed this a threat worth recognition not only due to the technical aspects inherent to the threat, but also because of the popularity and widespread use of Blojsom technology.
"Blojsom and other popular blog technologies have been identified by the CIA Lab for cross-site scripting vulnerabilities, which fortunately can be fixed relatively quickly," said Ambarish Malpini, CTO of Cenzic. "Cenzic protects web applications not only against common threats such as these but also more serious threats such as phishing that could provide attackers access to confidential user information."
About Cenzic Intelligent Analysis (CIA) Research
The Cenzic Intelligent Analysis (CIA) team specializes in continuous research into application vulnerabilities and the latest tools and techniques used within the field of application security. The CIA team monitors the latest vulnerabilities and trends affecting application security by tracking Internet newsgroups, forums, mailing lists, and underground websites where vulnerability information is released. In addition to its research focus, CIA experts also perform vulnerability assessment, penetration testing, and security testing.
Cenzic has dedicated experts whose sole job is to perform ongoing research to not only analyze known vulnerabilities but also discover new or undisclosed vulnerabilities in custom, commercial, and open-source applications, and to make this information available to customers and to the community at large in the form of publications and security alerts. Cenzic Hailstorm is updated similar to anti-virus on a regular basis with new vulnerability information to give customers an advantage in staying ahead of new vulnerabilities.
About Cenzic
Cenzic is a leading provider of the next-generation enterprise software and a leading Managed Service offering for automated application security assessment and compliance that allows Fortune 1000 corporations, mid-sized corporations, and government organizations to dramatically improve the security of web applications. Cenzic® Hailstorm®, the most accurate and extensible product in the industry, enables security experts, QA professionals, and developers to work together to assess, analyze, and remediate applications for security vulnerabilities. Hailstorm benefits include reduced security risk and liability, lower development and testing costs, and faster time-to-market. Cenzic ClickToSecure™ service is one of the industry's first Software as a Service (SaaS) to combine the power of an enterprise-class application security assessment product with the flexibility of a managed security service. Cenzic Assessment Methodology completes the solution with a state-of-the-art business process consulting service to help customers improve their application security methodologies. Cenzic solutions are the most accurate, comprehensive, and extensible in the industry. Cenzic's current focus includes financial services, e-retail, healthcare, and government sectors. For more information, visit www.cenzic.com.
Contact: Angelique Faul Kulesa Public Relations for Cenzic, Inc. 513.233.2994 angelique@kulesapr.com
A Stock Cloud is a tag cloud like display of stock ticker symbols. The larger the ticker symbol the more frequent that company distributes press releases.