Vulnerability Assessment Security Vulnerabilities Vulnerability Management
Security Vulnerabilities
Beyond Security Logo
Security Vulnerabilities
Security Vulnerabilities
Security Vulnerabilities 0 Day Black Box Testing
Security Vulnerabilities

WSSA Case Studies

WSSA - Revealing Security Issues Often Overlooked by Others.

The following case studies show how our customers have used WSSA to secure their networks and save valuable resources.

Customer A:
Large hi-tech firm developing CRM solutions for customers worldwide:

This customer's web server was hosted at a large ISP, well protected behind a firewall, content filtering applications, etc. To audit the defenses provided by the ISP, they contracted with Beyond Security to use WSSA for weekly scanning and security reports.

Soon after starting the scans a security vulnerability was identified, but not corrected by the ISP. Two months following the beginning of the scans, an attacker used the vulnerability to place a back door on the server. This provided complete access to the server and enabled the attacker to manipulate the information on that server, as well as use the server to "leap-frog" and attack other servers on the ISP's network from this compromised one.

WSSA's differential reporting immediately highlighted the newly opened back door. The security hole that led to this compromise had been previously reported by WSSA scans, but the administrator had disagreed with the risk severity assigned by WSSA.

Finding this back door just shortly after it was placed saved money and limited the damage caused by this compromise. In fact, the attacker did not have time to do anything other than place the back door, so the typical damage, expense and down time of a break in was avoided due to the quick identification of the incident



Customer B:

A company providing public services that have implications regarding national security.

This company had been conducting quarterly penetration tests using a top data security consulting company and had paid over $20,000 to perform each scan. As a side-check the company used Beyond Security's WSSA service on their external IP addresses. "High Risk" security issues were found during the initial test, issues that would have allowed an attacker to gain full access to the main server.

The company was shocked; especially due to the fact that the periodic (and expensive) penetration tests did not reveal those holes. As further proof that the vulnerability actually existed Customer B requested Beyond Security staff to use it to penetrate the server in order to show the magnitude of the problem. We did so, and our team was able to gain control over their database and add ourselves as a trusted "agent" in the system.

The vulnerability was not discovered during the penetration testing, done just weeks before we scanned, because the test performed was obsolete at the time it was done and did not include the most current attack modes. Customer B was able to quickly fix the issue using the solution provided in the WSSA report.


Customer C:
This governmental office was using an off-the-shelf information security product to secure their main web site from internet attacks.

The customer then contracted with Beyond Security to check the DMZ network for security weaknesses and found that it used a database that had its SQL service open to the outside. This would have allowed anyone who gained access to the DMZ to access the database and exploit vulnerabilities in it to further gain access to the server.

This government office did not know that its DMZ network was running a database in the background, or that this database was gathering sensitive information about their network activities. In addition, the official office policy is not to use any database products without coordinating this with the security officer, and this was clearly in breach of that policy.

The customer contacted their web security company and asked them to fix this security hole immediately, which was previously unknown to the vendor. This customer had additional Web sites that were 'protected' with the same tool and they found that all of them suffered the same problem.


WSSA is a hosted solution. For an appliance-based solution, click here.
 
Security Vulnerabilities
beSTORMbeSTORM
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities Security Vulnerabilities
Security Vulnerabilities
Scan your web site Secure programming from the start
beSTORM Fuzzer
Security Vulnerabilities Security Vulnerabilities
Security Vulnerabilities
Scan your web site Next generation security testing
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities
Security Vulnerabilities
Scan your web site Audit more applications with greater efficiency
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities
Automated Vulnerability Detection System Automated
Vulnerability
Detection
System
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities Security Vulnerabilities
Security Vulnerabilities
Scan your web site Daily automated security assessment
AVDS Scanning System
Security Vulnerabilities Security Vulnerabilities
Security Vulnerabilities
Scan your web site Solutions to vulnerabilities found
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities
Security Vulnerabilities
Scan your web site Manage vulnerabilities across the enterprise
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities
Web Security Audit
Web Site Security Audit
Web Security scan
Website Security scan web Security scanning Web Security Audit
Web Security Vulnerabilities
Scan your web site Scan your web site for security holes
Web Security Test
Security Vulnerabilities Website Security Vulnerabilities
Web Security risks
web security scan Fastest Scan Turnaround
website security testing
Security Vulnerabilities web security penetration testing
web security scan
Scan web site for vulnerabilites Get Help From Security Specialists
website scanning for vulnerabilities
Security Vulnerabilities Web server scanning
SecuriTeam Leading Security Portal
www.SecuriTeam.com
Best Security Portal
Security Vulnerabilities
About SQL Injection | Web Security And Web Scanning
Privacy Policy, Terms of Use
© Copyright 1998-2009 Beyond Security. All rights reserved.
Security Vulnerabilities

 
Security Vulnerabilities Among our Clients Security Vulnerabilities
Security Vulnerabilities
Customer Satisfaction

Security Vulnerabilities
Security Vulnerabilities

Contact Us

 

US: 1.800.801.2821

UK: +44.203.006.3022

Security Vulnerabilities
Red Hearing 100 Finalist Winner


Security Vulnerabilities News Headline Security Vulnerabilities
Security Vulnerabilities
Scan your web site ion-ip to offer Beyond Security's VA solutions in the Netherlands
Security Vulnerabilities
Scan your web site beSTORM the first security testing tool to introduce RMI fuzzing
Security Vulnerabilities
Scan your web site Beyond Security Finalist for the Red Herring 100 Global Awards 2007
Security Vulnerabilities
Scan your web site Beyond Security CTO's keynote in Malware 2007
Security Vulnerabilities
Security Vulnerabilities
Security Vulnerabilities
Security Vulnerabilities
Security Vulnerabilities Security News Security Vulnerabilities
Security Vulnerabilities
Scan your web site Cisco Unified Communications Manager IP Phone Personal Address Book Vulnerability.
Security Vulnerabilities
Scan your web site Garmin Communicator Plug-In Domain Locking Security Bypass.
Security Vulnerabilities
Scan your web site Ghostscript jbig2dec JBIG2 Processing Buffer Overflow.
Security Vulnerabilities
Scan your web site IBM BladeCenter Advanced Management Module Multiple vulnerabilities.
Security Vulnerabilities
Security Vulnerabilities
Security Vulnerabilities Security Vulnerabilities