 |
 |
VERIO VPS All-inclusive, no hidden fees, 30-day guarantee! |  | HostGator - $4.95/mo 350GB Disk Space 3000GB Bandwidth
|  | Hostway Hosting Solutions for every size business.Free Consultation |  | HostForWeb - $4.95! 100% Satisfaction Or Your Money Back! |  | Cheap Reseller Host 5GB HDD,75GB bw,24/7 support,$1 for the first month |  | eBoundhost.com 24/7 Supp, UNLIMITED domains, 300G HD, 3,000G BW |  | PronetHosting $4.95 100GB Space/1000GB Bandwidth
Free Domain–Free Setup
|  | HostRocket - $4.99! 1000GB Disk Space Unlim. Bandwidth & 6 Months Free! |  | Earn residual income Join now & get 120% commission from Referback! |  | LYPHA's Amazing Deal 250GB Web Space, 6TB Xfer, UNLIMITED domains! |  |
|
 |
|
|
Cenzic Highlights Blog Technology Vulnerabilities |
 |
October 3, 2006 (HOSTSEARCH.COM) A recent report produced by Cenzic, Inc. (http:// www.cenzic.com), a provider of automated application security assessment and compliance solutions, has highlighted vulnerability to attacks by hackers in a leading blog technology. Researchers at the Cenzic Intelligent Analysis (CIA) Lab have discovered a cross-site scripting vulnerability in Blojsom - a Java-based multi-blog software package which could compromise a user's account.
Cross-Site Scripting occurs when execution commands in a user's browser display unintended content. This can be harnessed to steal user's login credentials and personal information, and ultimately make blog users victims of malicious attacks. Cenzic's findings have been submitted to CERT and verified by Bugtraq.
Although the Blojsom team has applied a fix which is available in Blojsom 2.32, the announcement comes as a concern to a number of companies who have adopted this blog technology, including Apple Computer who uses it for their OS X Server Weblog Server. Other popular blog technologies may also be vulnerable, the report said.
"Blojsom and other popular blog technologies have been identified by the CIA Lab for cross-site scripting vulnerabilities, which fortunately can be fixed relatively quickly," explained Ambarish Malpini, CTO of Cenzic. "Cenzic protects web applications not only against common threats such as these but also more serious threats such as phishing that could provide attackers access to confidential user information." |
|
|
|