Seguridad Mania.com - España y América Latina
Portal sobre tecnologías para la seguridad física
- Destacamos »
- software Anti Blanqueo
SAN CARLOS, CA -- (Marketwired) -- 10/21/14 -- Check Point® Software Technologies Ltd. (NASDAQ: CHKP), the worldwide leader in securing the Internet, today announced that its Security Research Group has discovered vulnerabilities in the Admin WebUI portals of three network security vendors. If targeted and exploited, these vulnerabilities would give hackers administrative control over the vendors' security gateways, potentially leaving business networks exposed to attacks. In the wake of the recent ShellShock WebUI vulnerability, these additional vulnerabilities further increase exposure for certain security vendors.
"Check Point shared its findings with the affected vendors as part of its duty for responsible disclosure of vulnerabilities," said Oded Vanunu, security research group manager at Check Point Software Technologies. "Check Point is committed to ensuring the security of all organizations. As such, we are obligated to raise awareness of the vulnerabilities that can affect Admin WebUI portals. We strongly recommend that organizations using WebUI check with their vendors to ensure that they are not exposed to the uncovered vulnerabilities."
The vulnerabilities were discovered using a combination of Cross-site Scripting (XSS), Cross-site Request Forgery (CSRF) and Phishing attacks. To mitigate the risk of Admin WebUI exploits, Check Point strongly recommends organizations using security products with a WebUI portal to implement the following best practices:
"The WebUI approach introduces multiple attack vectors and our research has shown 21 of 23 network security vendors use a WebUI to manage their product security configuration," concluded Vanunu.
Check Point's Malware and Security Research Groups regularly perform assessments of common security products to ensure the security of Internet users worldwide. For more information on other research and vulnerabilities findings from Check Point, visit: http://www.checkpoint.com/advisories/index.html
Follow Check Point via:
Twitter: www.twitter.com/checkpointsw
Facebook: https://www.facebook.com/checkpointsoftware
YouTube: http://www.youtube.com/user/CPGlobal
About Check Point Software Technologies Ltd.
Check Point Software Technologies Ltd. (www.checkpoint.com), the worldwide leader in securing the Internet, provides customers with uncompromised protection against all types of threats, reduces security complexity and lowers total cost of ownership. Check Point first pioneered the industry with FireWall-1 and its patented stateful inspection technology. Today, Check Point continues to develop new innovations based on the Software Blade Architecture, providing customers with flexible and simple solutions that can be fully customized to meet the exact security needs of any organization. Check Point is the only vendor to go beyond technology and define security as a business process. Check Point 3D Security uniquely combines policy, people and enforcement for greater protection of information assets and helps organizations implement a blueprint for security that aligns with business needs. Customers include tens of thousands of organizations of all sizes, including all Fortune and Global 100 companies. Check Point's award-winning ZoneAlarm solutions protect millions of consumers from hackers, spyware and identity theft.
Publicamos interesante Informe de más de 48 págs y varios videos demostrativos sobre los posibles ataques a los robots de montaje de las fábricas. ... Leer más ►
Publicado el 22-Jun-2017 • 10.48hs
Publicado el 20-Jun-2017 • 20.22hs
Dirigido tanto a los principiantes, como a los expertos en seguridad informática y sistemas de control industrial (ICS), este libro ayudará a los lectores a comprender mejor la protección de normas de control interno de las amenazas electrónicas. ... Leer más ►
Publicado el 3-Ene-2012 • 20.16hs
Publicado el 25-Set-2009 • 01.26hs
Publicado el 17-Dic-2008 • 08.32hs
Publicado el 11-Oct-2016 • 12.48hs
Publicado el 15-Mar-2016 • 11.59hs
Publicado el 2-Feb-2017 • 11.38hs
Publicado el 20-Jun-2014 • 17.17hs
Publicado el 31-May-2011 • 05.13hs
Publicado el 25-Set-2008 • 17.54hs
Publicado el 1-Set-2016 • 16.11hs
Publicado el 31-Ago-2016 • 18.53hs
Publicado el 19-Ene-2017 • 15.47hs
Publicado el 4-Jul-2016 • 18.51hs