Showing posts with label web security. Show all posts
Showing posts with label web security. Show all posts

Wednesday, November 6, 2013

Yahoo launches $15,000 bug bounty program

Yahoo launches $15,000 bug bounty after $12.50 company voucher debacle
Web portal Yahoo launched a bug bounty programme on Friday following the scandal that unravelled last month, which saw a security firm rewarded with a $12.50 Yahoo Company Store voucher for uncovering a security flaw.

In what is good news for security researchers, Yahoo said that the bounty programme will now pay up to $15,000 to ethical hackers who find vulnerabilities in its web services, a much bigger reward than its previous policy of offering a company t-shirt. Read more at The Inquirer

Yahoo offers $15,000 to bug hunters
Yahoo is seeking to entice bug hunters with rewards up to $15,000 depending on the severity of the bug found. The web giant was criticized by security researchers for paying a measly $12.50 in Yahoo discount vouchers to security researchers at High-Tech Bridge for two cross site scripting (XSS) bugs they had reported. Yahoo's security head, Ramses Martinez, claimed later that he was behind the voucher reward program, and that he basically had been paying for them out of his own pocket. Read more at AfterDawn Oy

Following controversy, Yahoo officially launches bug bounty program
As promised, Yahoo formally kicked off its bug bounty program late last week, aiming to correct what many in the security industry viewed as misstep after it handed out a paltry $12.50 credit to a researcher for discovering a cross-site scripting error.

The company caught flak when in September when it was reported that the $12.50 – a scant prize as it is – came as a discount code that could be used toward Yahoo-branded merchandise like t-shirts, cups and pens from its store. Read more at Threatpost

Monday, September 16, 2013

Nasdaq website security vulnerabilities

NASDAQ

A penetration testing company uncovered security vulnerabilities on the NASDAQ website that remained open for two weeks after the stock exchange was notified.
NASDAQ Website Security Vulnerabilities Remained Open for Weeks After Alert (securityweek.com)

Exchange delayed fixing potentially critical website vulnerabilities despite multiple alerts, security firm says
Nasdaq waited two weeks to fix flaws (computerworld.com)

Ilia Kolochenko, head of Swiss information security company High-Tech Bridge, says he’s repeatedly warned Nasdaq.com that hackers could steal users’ browser history or confidential data, but claims the exchange has done nothing to fix the problem. 'It is quite frightening when you think about it,' he says.
Cypersecurity pro on Nasdaq website: 'I needed 10 minutes to hack' (nydailynews.com)

Thursday, September 12, 2013

ImmuniWeb® Self-Fuzzer Firefox Extension

ImmuniWeb® Self-Fuzzer fo Firefox High-Tech Bridge announced new Firefox Addon: ImmuniWeb® Self-Fuzzer.

ImmuniWeb® Self-Fuzzer is a simple and free extension that fuzzes user's HTTP requests in real-time to detect SQLi and XSS vulnerabilities on a website, demonstrating how easily these 2 most common web weaknesses can be found by anyone.

Description in PDF format: PDF: ImmuniWeb® Self-Fuzzer Firefox Extension

Also demo video available:

Tuesday, July 23, 2013

Security for brokers and insurers: Welcome to the World Wild Web

Basic and visual security awareness initiation for brokers and insurers was presented at 4th brokers forum which occurred in Chavannes-de-Bogis by Frederic Bourla, some of the threats which could deadly impact brokers businesses.

YouTube videos:

Related links:

Friday, July 5, 2013

SecurityWeek: OpenX Addresses New Security Flaws with Latest Update

Article by Steve Ragan:
OpenX, the open source ad serving platform, patched two flaws last week, after they were discovered by Geneva, Switzerland’s High-Tech Bridge. The platform has had several issues before, and is a favorite target of criminals operating using malvertising as an attack vector.

According to the High-Tech Bridge advisory, OpenX patched two flaws in the final days of June. The first was a file inclusion vulnerability, which if the attacker has administrative privileges, can be used to access stored files such as the webservers /etc/passwd file.

"Successful exploitation of these vulnerabilities requires administrative privileges, however they can also be exploited by a remote non-authenticated attacker via CSRF vector, since the application is prone to Cross-Site Request Forgery (CSRF) attacks. In order to do so an attacker should trick logged-in OpenX administrator to open a specially crafted web page with CSRF exploit code," the advisory explains.

Read Full Article at: SecurityWeek.com

Related posts:
HTB23155: OpenX PHP file inclusion & cross-site scripting
Serious vulnerabilities in OpenX ad platform expose millions to risk

Wednesday, June 5, 2013

Frost & Sullivan: High-Tech Bridge Moves Ethical Hacking to the Cloud with ImmuniWeb® SaaS

Movers & Shakers Interview with Ilia Kolochenko, CEO of High-Tech Bridge, a Leading Provider of Ethical Hacking Services in Europe

Mr. Kolochenko, the CEO of High-Tech Bridge and creative mind of ImmuniWeb® talked to Frost & Sullivan about the recent launch of ImmuniWeb® Beta, an innovative cloud-based ethical hacking SaaS solution for web applications.

The fundamentals of ImmuniWeb are ease and rapidity of use, and a powerful combination of human and machine. "ImmuniWeb is a hybrid of manual penetration testing, performed by security auditor, and automated security assessment under thorough control of the auditor. ImmuniWeb security assessment can be purchased and configured in less than 15 minutes on the ImmuniWeb Portal" Mr. Kolochenko says.

"ImmuniWeb presents a solution to three common issues of ethical hacking and the security auditing industry: lack of in-house technical knowledge among customers, administrative and regulatory complexities that takes lot of time, and relatively high market prices," he explains. "ImmuniWeb has a very attractive quality-price ratio and simplicity of use, making web application security assessment affordable to SMBs and even to private persons."

ImmuniWeb tackles one of the main end-user challenges when engaging ethical hacking services. "Although the ethical hacking market is quite well developed today, and there are many qualified players in the market, quite often customers still have to decide between buying either a good quality service at quite excessive price or a cheap service quality of which does not even worth its dumping price," Mr. Kolochenko explains. "We felt an obligation to find a solution that would be fair in terms of pricing, and technically efficient."

To read the entire interview and learn more on ImmuniWeb please see Movers & Shakers Interview with Ilia Kolochenko - CEO of High-Tech Bridge on frost.com.

Frost & Sullivan is proud to showcase Movers & Shakers interviews, highlighting dynamic companies and leaders in the corporate world. These organizations and individuals are recognized for achieving milestones such as launching a breakthrough technology, executing a key strategic acquisition, or implementing a revolutionary vision for the future of their industries.

About Frost & Sullivan

Frost & Sullivan, the Growth Partnership Company, works in collaboration with clients to leverage visionary innovation that addresses the global challenges and related growth opportunities that will make or break today's market participants.

Our "Growth Partnership" supports clients by addressing these opportunities and incorporating two key elements driving visionary innovation: The Integrated Value Proposition and The Partnership Infrastructure.

  • The Integrated Value Proposition provides support to our clients throughout all phases of their journey to visionary innovation including: research, analysis, strategy, vision, innovation and implementation.
  • The Partnership Infrastructure is entirely unique as it constructs the foundation upon which visionary innovation becomes possible. This includes our 360 degree research, comprehensive industry coverage, career best practices as well as our global footprint of more than 40 offices.

For more than 50 years, we have been developing growth strategies for the global 1000, emerging businesses, the public sector and the investment community. Is your organization prepared for the next profound wave of industry convergence, disruptive technologies, increasing competitive intensity, Mega Trends, breakthrough best practices, changing customer dynamics and emerging economies?

Contact Us: Start the discussion

Join Us: Join our community

Subscribe: Newsletter on "the next big thing"

Register: Gain access to visionary innovation

Contact:
Joanna Lewandowska
Frost & Sullivan
Corporate Communications – Europe
Phone: +48 22 481 62 20
Email: joanna.lewandowska (at) frost.com
http://www.frost.com

SOURCE: Frost & Sullivan

Wednesday, May 15, 2013

Web Security: High-Tech Bridge launches ImmuniWeb® Beta

High-Tech Bridge SA, a leading Swiss information security company recognized as one of the market leaders and best service providers in the ethical hacking industry by Frost & Sullivan in 2012, is pleased to introduce ImmuniWeb® Beta.

ImmuniWeb®

ImmuniWeb® is a next-generation web application security assessment solution with Software-as-a-Service delivery model. It is a unique hybrid of cutting-edge web security scanner and accurate manual web application penetration test.

Ilia Kolochenko, CEO of High-Tech Bridge, says: "Today many SMBs are unfairly prevented from securing their websites due to budget, internal technical skills or administrative restrictions. We are glad to launch our innovative SaaS ImmuniWeb® that enables SMBs to secure their websites in simple, efficient and cost-affordable manner. Starting today the service will run in Beta mode during some time in order to get feedback from our customers and probably add some additional features and options they will consider useful."

Marsel Nizamutdinov, Chief Security Research Officer, adds: "I am very glad that after several years of our hard work we can finally announce the launch of ImmuniWeb®. This will enable anyone to benefit from our skills, experience and research in the domain of web application security. Moreover, other similar products that make information security simple, efficient and fair are currently being developed. Our Corporate Management invests a lot into Research and Development and will continue to do so in the future to assure permanent growth and innovation.

Frederic Bourla, Chief Security Specialist, comments: "According to the recent ISTR 2013 study from Symantec, SMEs are now clearly a prime target for hackers. In 2012 businesses with fewer than 250 employees were targeted by nearly one third of worldwide cyber-attacks, which is approximately twice as much as the previous year. And from our own experience those figures are probably slightly lower than the reality in Switzerland, so we are now pleased to offer SMEs the opportunity to address this trend."

ImmuniWeb® Beta is currently available to the holders of Invite Codes distributed by High-Tech Bridge. It is also possible to leave a request for Invite Code on ImmuniWeb® Portal.

Source: High-Tech Bridge

Wednesday, January 23, 2013

Story about OpenX

OpenX-Server

OpenX Developers fixed vulnerabilities in OpenX 2.8.10 (September 28, 2012), which suffer from cross-site scripting and SQL injection vulnerabilities. After 4 months Golem.de at January 19, 2013 has published information about the further adventures of this vulnerabilities: BSI warnt vor Werbebannern mit Javascript-Malware.


Related Links:

Always stay secure.

The Ethical Hacker Network: Interview of Ilia Kolochenko

The Ethical Hacker Network (Donald C. Donzal, Editor-In-Chief) interviewed Ilia Kolochenko, CEO of High-Tech Bridge about penetration testing, Web Applications Security, Vulnerability Research and more: Interview: Ilia Kolochenko, CEO of High-Tech Bridge.

Ilia Kolochenko at invest'11 Ilia Kolochenko at invest'11.

Thursday, December 20, 2012

Web Applications Vulnerabilities CVSSv2 Calculator

High-Tech Bridge is pleased to announce CVSSv2 Calculator for vulnerabilities in web applications.

Web Applications Vulnerabilities CVSSv2 Calculator
The Common Vulnerability Scoring System (CVSS) provides an open framework for communicating the characteristics and impacts of IT vulnerabilities.

Read more: A Complete Guide to the Common Vulnerability Scoring System Version 2.0.