home contact keylogger.org add keylogger.org to favorites set keylogger.org as homepage Anti-Keylogger.org
Keylogger testing and reviews

Keylogger testing policy

Press-releases

Keylogger developers

Links
Monitoring Software Keylogger articles

Get Free Software

Keylogger chat

Keylogger forum

Sponsorship & services
Advertising
Your Ad Here
Site News
Current section
Keylogger.Org Site News

November 27th, 2008

New version of XPC Spy Pro added!

Security World News
Keylogger.Org Security World News

December 04th, 2008

Microsoft and RSA partner on Data Loss Prevention

Worm uses familiar brands to lure people

Company data at the mercy of crooks

Norton AntiVirus Begone!

Criminals Take Control of CheckFree Web Site

Firefox Users Targeted by Rare Piece of Malware

Hacker threat: Rudd promises action

Lib Dems criticise 'shambolic' DNA database

Experts: US cybersecurity needs fresh ideas

Pentagon hacker tries one more time to avoid extradition

Virtually every Windows PC at risk, says Secunia

Sun patches at least 14 bugs in Java

Security, civil liberties experts question data mining

Voting

We are planning to redesign our site. We would like You to express your opinion in this respect. Would you like to leave the site as it is? What changes would you like to suggest?

Yes, I like the site as it is.
It's ok, but some changes are necessary.
It should be changed completely.
VotingView results
DISCLAIMER: Logging other people's keystrokes or breaking into other people's computer without their permission can be considered illegal by the courts of many countries. The monitoring software reviewed here is ONLY for authorized system administrators and/or owners of computers. We assume no liability and are not responsible for any misuse or damage caused by the keylogging software. The end user of this software is obliged to obey all applicable local, state, federal and other laws in his country of residence.

December 18th, 2007

Veracode pitches backdoor apps security

Veracode launched a new version of its binary code analysis service on Monday that focuses specifically on helping software engineers find potential backdoor vulnerabilities in their programs.

While some applications security companies scour source code for flaws, such as Fortify, and others specialize in testing programs already running in production, such as Cenzic, Veracode is spinning itself as an alternative by channeling its efforts into looking for vulnerabilities in binary code and offering the capabilities as a fully-hosted service.

Officials with the applications security startup - which was originally spun out of Symantec and launched its initial analysis service in Feb. 2007 - claim that the company's unique ability to find backdoors could be one of the differentiators that allow Veracode to grow its presence in the applications security sector.

With backdoor vulnerabilities in particular, said company officials, the use of binary code analysis is ideal for finding potential flaws that are hard to predict or address in other stages of development.

‘There are a lot of advantages to looking at binaries versus looking at source code, and it turns out that finding backdoors is one of those, and there hasn't been anything on the market that really addresses the problem in general,’ said Chris Wysopal, CTO at Veracode. ‘Some static analysis tools may look for static passwords, but if the code is even slightly obfuscated, they can't, and they don't, look for hidden keys or rootkit behavior, so this is truly something new that we're offering.’

Along with special credentials, which are most often embedded in applications code by developers as a means to get back into the programs, Veracode is also promising to chase down any hidden functionality, or secret sets of commands left inside many software systems by their authors.

The service also promises to look for warning signs of malicious code behavior, such as evidence of any rootkits built into a program, and unusual network activity, such as functionality that causes an application to mail out data to a predestined recipient.

As more companies outsource elements development of their applications, it will be vital for them to run such scans against their programs to look for the potential weak points, the CTO said.

Leaving backdoors in code is one of the oldest tricks on the book for developers looking for easy ways to get back into their programs to either fix them or carry out malicious schemes, Wysopal contends.

‘Sometimes it's just something that is meant to be left in for debugging purposes, other times its code that was meant to be removed but simply slipped through the cracks, either way these are vulnerabilities that need to be addressed,’ said Wysopal. ‘Most customers want a third-party review in this day, and we can offer that as a hosted service, so we think there's a lot of potential for how much interest backdoor scans can drive uptake of our services.’

Financial services firms in particular are very concerned that outsourced code developers may be leaving backdoors in place to sell to malware code writers or use to break into applications on their own for the purpose of stealing data, said the expert.

While some industry watchers have questioned how many firms will be willing to hand over their proprietary code to Veracode for testing, the CTO said that with businesses outsourcing more software development than ever, most large companies are already conditioned to working with third parties on that level - and willing to give someone a chance to examine their software for security purposes.

Commercial software vendors represent another significant opportunity for Veracode, and it has already run scans for three or four of the largest ISVs in the world, Wysopal said. The executive claims that the company is also currently serving four of the world's top ten financial services companies with its vulnerability discovery services.

The increasing popularity of open-source software in the business setting is another reason why Veracode's services make sense, he said. However, the problem is even more acute for proprietary programs.

‘When we did our research, we found that if a backdoor was placed in an open-source project, the lifetime was typically weeks, but for commercial products, the backdoors lived for years,’ said Wysopal. ‘Maybe you could find these problems if you did manual code reviews, but we know that is becoming harder than ever with shared libraries and outsourcing; we think that by becoming the leading experts in backdoors, we can grow our business even faster.’

Industry analysts downplayed the notion that binary analysis is the best way to look for backdoors, pointing out that source code scanning specialists like Ounce Labs and Fortify have just as good an opportunity to find the flaws.

However, the industry watchers said that Veracode might have an advantage in the process of finding the backdoor bugs compared to so-called ‘black box’ vendors, including Cenzic.

‘I don't think it is as large of an advantage as they might claim, but it does help them differentiate over the black box crowd,’ said Dr. Chenxi Wang, analyst with Forrester Research. ‘But with the issue of people being afraid to hand over their code to Veracode, I don't think that's as big of a deal as some have made it out to be either.’

The analyst said that Veracode is winning interesting deals with banks like Barclay's - which is using the company's scanning services to test the applications of its business partners that want to link to its own software systems.

Binary analysis and the ability to utilize Veracode's hosted model in such a fashion may in fact help the company grow the applications security space in general, she said.

‘Their approach so far has been pretty smart, you can see how the model being used with the banks may drive great interest in applications scanning, it's not that the market is flat but there's a lot of room for growth,’ Wang said. ‘We'll have to wait to see if Veracode can draw more customers, and see the size of those deals, but they do have an opportunity to shake things up.’


Source: INFOWORLD




All news for December 04th, 2008:
17:31Microsoft and RSA partner on Data Loss Prevention
17:29Worm uses familiar brands to lure people
17:27Company data at the mercy of crooks
17:23Norton AntiVirus Begone!
17:15Criminals Take Control of CheckFree Web Site
17:14Firefox Users Targeted by Rare Piece of Malware
17:12Hacker threat: Rudd promises action
17:11Lib Dems criticise 'shambolic' DNA database
17:10Experts: US cybersecurity needs fresh ideas
17:08Pentagon hacker tries one more time to avoid extradition
17:07Virtually every Windows PC at risk, says Secunia
17:06Sun patches at least 14 bugs in Java
17:05Security, civil liberties experts question data mining

All news for December 03rd, 2008:
15:18Hackers run Linux on iPhone
15:17Your face is easy to fake, says security company
15:15Microsoft opens up Vista SP2 beta
15:09Latest VB100 malware test brings good news
14:57Botnet Master Sees Himself as Next Bill Gates
14:53Apple removes Mac antivirus recommendation
14:51License server glitch exposes SonicWall users to e-mail security threats
14:50U.S. report sees major terror attack by 2013, ignores cyberattack risk
14:48Lenovo arms ThinkPads with Intel's built-in security
14:44Feds nab more members of alleged identity theft gang
14:43Apple's antivirus advice 'big to-do about nothing,' says researcher
14:42Opinion: Is there a hidden cost to data protection?
14:41Human error is top IT security concern
14:40Workers worried about job security might steal corporate data



All news for December, 2008
All news for 2008 year
All news for 2007 year
All news for 2006 year
All news for 2005 year
All news for 2004 year


DONATION: Keylogger.org is an independent research project supported by a team of enthusiasts. If you find this project useful or would like to help foster its continued development please consider making a donation using PayPal`s online secure payment service.

A PayPal account is not required. All major credit cards are accepted (MasterCard/Eurocard, Visa/Delta/Electron, American Express, Switch/Maestro, Solo). Simply click the button below.

Any amount would be useful and appreciated!

Thanks in advance for your support!

Advertising
Your Ad Here
| home | testing and reviews | testing policy | press_releases | developers |

| articles | contest | chat | forum | sponsorship & services | contacts | links |
Copyright © 2003-2008, Keylogger.Org Team. All Rights Reserved.
Use of any information from this website is permitted only with hypertext link to www.keylogger.org.