Показаны сообщения с ярлыком Positive Technologies. Показать все сообщения
Показаны сообщения с ярлыком Positive Technologies. Показать все сообщения

четверг, 15 октября 2009 г.

Some plug about Bitrix


Recently we conducted audit of new security functions of "1С-Bitrix: Site management " to assess the compliance with Web Application Firewall Evaluation Criteria requirements of Web Application Security Consortium.

The story has continued on Chaos Constructions CC9 Festival" that took place on 29-30 August 2009 in Saint Petersburg, Russia.

"More than six hundred Russian hackers have been trying to hack down a server-installed content management software in attempt to get over its sophisticated Proactive Protection system. There had been more than 25.000 attacks recorded and effectively repulsed during the software crash test competition hours. The competition was organized by the Bitrix, Inc. team and Positive Technologies IT experts"


Bitrix Real-Time Hack Competition in Russia

25.000 Russian Hack Attacks Repulsed by Bitrix in Two Days

WAF-protected, tested "by Russian Hackers", PCI Compliant site from the box. Not bad, is not it?

четверг, 19 марта 2009 г.

Webspider. Express vulnerability assesment

Concept preview of Webspider express security scanner (pure AJAX :) has been recently published – this is a tool that allows analyzing in seconds the software which is the most frequently used by attackers. The system is intended to make protection express analysis of Internet and Intranet users, users of electronic commerce systems and Internet provider clients.

You can test it here:

http://www.securitylab.ru/addons/webspider3/fast_check.php



The current version is able to detect a vulnerability in popular ActiveX components and plug-ins, Mozilla Firefox and Opera browsers, Java and Adobe Flash applications and also MS07-042, MS08-069 and MS09-002 updates.
We plan to publish a detailed article about the used techniques in April.

It's just preview, so be indulgently.

вторник, 10 марта 2009 г.

Positive Technologies Reasearch Lab

This year we decided to resume the publication of vulnerability details detected during researches and penetration testing.

http://en.securitylab.ru/lab/

In 2006, because of a number of reasons, we decided to shift the burden of publishing vulnerability details to software vendors and stop publishing the details about previously detected problems. However, many customers ask us to assist in vulnerability elimination in third-party vendor software. This induces us to resume the process.
The most interesting current problem (in my opinion) is a number of vulnerabilities in VMWare that allows attackers to gain access from guest to host OS. And right to the kernel.

I personally treated different methods to eliminate vulnerabilities in third-party vendor software, from Full-Disclosure extremism to selling vulnerabilities in the “white” market, for example, iDefense (http://labs.idefense.com/vcp/). Some thought are available here:
http://www.securitylab.ru/analytics/241826.php (Russian)