On MovieTome: The 10 worst movies of 2009 so far!
BNET Business Network:
BNET
TechRepublic
ZDNet

July 29th, 2008

Fortify warns of configuration weaknesses in SOA deployments

Posted by Ryan Naraine @ 8:22 am

Categories: Arbitrary Code Execution, Complex Attacks, Data theft, Exploit code, Malware, Open source, Patch Watch, Pen testing, Reverse Engineering, Vulnerability research, Web Applications

Tags: Apache Software Foundation, SOA, Application Security, Attack, Veracode, Service-Oriented Architecture (SOA), Security, Middleware, Enterprise Software, Web Services

Fortify warns of SOA configuration weaknessesSecurity code review specialists Fortify Software has issued a warning about major configuration weaknesses affecting SOA (service oriented architecture) deployments from IBM, Microsoft and Apache.

According to Fortify, certain configurations of Apache Axis, Apache Axis 2, IBM WebSphere 6.1, Microsoft .NET Web Services Enhancements (WSE) 2.0 and Microsoft Windows Communication Foundation (WCF) can open doors to several classes of attacks — weak authentication, weak encryption, vulnerability to replay attack, XPath injection, and many other significant security vulnerabilities.

“In addition, applications that have been secured for Web attacks may still be insecure to attacks through SOA. To be clear, the frameworks themselves are secure, but they have to be appropriately configured and used in order to avoid serious security issues,” Fortify said in a statement.

Fortify warns of configuration weaknesses in SOA deploymentsSeparately, rival application security testing firm Veracode has announced a strategic investment and technology advancement agreement with In-Q-Tel, a deal that provides an entry for the Boston start-up to target government clients.

[ SEE: Dan Geer joins In-Q-Tel ]

With the strategic investment, Veracode says it will accelerate specific research areas for governmental, commercial and open source applications to further enhance its subscription-based application security solutions.

Veracode’s flagship SecurityReview service is based on static binary testing technology and Web scanning analysis that assesses application security threats, including vulnerabilities such as cross-site scripting (XSS), SQL injection, buffer overflows and malicious code such as hidden backdoors without exposing a company’s source code.

* Image credit: tanakawho’s Flickr photostream (Creative Commons 2.0)

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 1 Talkback(s)
SOA Applications  tcosta | 07/30/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here