이이미웹

ImmuniWeb
이이미웹
유형사설
산업사이버보안
설립됨2019 (2019)
창시자일리아콜로첸코
본부
제네바
,
서비스 영역
유럽
북아메리카
APAC
주요인
일리아콜로첸코(대표이사)[1]
상품들ImmuniWeb AI 플랫폼
서비스애플리케이션 보안 테스트,
공격 표면 관리,
다크 웹 모니터링
직원수
50+
웹사이트www.immuniweb.com

ImmuniWeb은 과거 하이테크 브리지(High-Tech Bridge)였던 스위스 제네바에 본사를 둔 글로벌 애플리케이션 보안 기업이다.ImmuniWeb은 자사의 독점적인 ImmuniWeb AI 플랫폼을 통해 제공되는 SaaS 기반 애플리케이션 보안 솔루션을 위한 머신러닝 및 AI 기술을 개발한다.

얼리 시큐리티 리서치

보안 권고 사항

하이테크 교량 안전 보장 연구 팀 500보안 다양한 소프트웨어에 영향을 미치는 advisories[2], 문제 제품에 Sony,[3]McAfee[4]Novell,[5] 같은 잘 알려 진 많은 노점에서 많은 웹 취약성 인기 있는 오픈 소스와 osCommerce,[6]선종 카트와 같은 상업적 웹 사이트 어플리케이션,에 영향을 주기 외에 확인과 함께 출시되고 있다.마이크로 소프트 그녀 ,[7]리포인트, 슈가CRM 등.

하이테크 브리지의 시큐리티 리서치 은 MITRE가 CVE와 CWE 호환으로 등록했다.[8]전세계적으로 단 24개 기관 중 하나로 스위스에서는 처음으로 CWE 인증을 획득했다.

이 회사는 2013년 8월 현재 보안 권고사항에 CVE 식별자를 포함하는 81개 기관 중 하나이다.[9]

무료 온라인 서비스 및 관련 연구

하이테크 브릿지는 2015년 10월 SSL/TLS 구성 테스트 툴을 출시했다.[10]이 도구는 NIST 지침에 따라 이메일, 웹 또는 기타 TLS 또는 SSL 서버 구성을 검증할 수 있으며 PCI DSS 컴플라이언스를 검사할 수 있으며, 이는 Talk 데이터 침해에 대한 기사에서 인용되었다.[11][12]

보안 및 개인 정보 조사

하이테크 브릿지에 의한 야후! 사이트에서의 취약점 발견은 널리 보도되어 티셔츠 게이트 사건과 야후의 버그 바운티 프로그램의 변경으로 이어졌다.[13][14]그 회사는 야후 도메인에서 4개의 XSS 취약점을 찾아 보고했고, 그 결과 야후 도메인에서 25달러 상당의 상품권 2장을 받았다.[15][16][17][18]야후!의 취약점을 찾아낸 것에 대해 보안 연구원들에게 제공된 희박한 보상이 비난을 받아, 취약점을 발견한 것에 대한 감사 표시로 티셔츠를 보내는 야후를 반대하는 캠페인인 [19]티셔츠 게이트라고 불리게 되었다.하이테크 브릿지의 이러한 취약점 발견과 그에 따른 야후 보상 프로그램의 비판은 야후!가 사전 확립된 기준에 근거하여 보고된 이슈에 대해 150달러에서 15,000달러까지 제공하는 새로운 취약점 보고 정책을 출시하게 했다.[14][20]

2013년 12월 인기 소셜네트워크 및 이메일 서비스의 개인정보 보호에 관한 이 회사의 연구는[21] 소셜네트워크에 전송된 사적인 메시지를 스캔하여 회원의 사생활을 침해했다는 혐의로 집단소송에서 인용되었다[22][23].

2014년 10월에 회사는 PHP에서 원격 코드 실행 취약성을 발견했다.[24]이들은 2014년 12월 랜섬웨어 공격의 발달로 해커들이 웹서버를 인수해 이들 서버에 있는 데이터를 암호화한 뒤 파일 잠금 해제를 위한 대금을 요구하는 랜섬웨어 공격을 확인했다.[25]

2014년 4월 정교한 Drive-by download 공격의 발견은[26] 손상된 웹 리소스에 대한 인증 후 특정 웹 사이트 방문자를 대상으로 한 드라이브 바이 다운로드 공격이 어떻게 사용되는지를 밝혔다.

2015년 12월, 이 회사는 가장 인기 있는 무료 이메일 서비스 제공업체들을 대상으로 SSL/TLS 이메일 암호화를 테스트했다.[27]이전에 가장 안전한 이메일 제공 업체 중 하나로 여겨졌던 후쉬메일은 실패한 "F" 등급을 받았다.직후, SSL 구성을 업데이트해 「B+」[28]등급을 받았다.

참조

  1. ^ "Articles by Ilia Kolochenko". CSO Online. Retrieved 22 July 2015.
  2. ^ "Packet Storm - Files from High-Tech Bridge SA". PacketStorm.org. Retrieved 20 February 2016.
  3. ^ "Security Update Program for VAIO® Personal Computers". esupport.sony.com. Sony. Retrieved 20 January 2015.
  4. ^ "McAfee Security Bulletin - McAfee MVT & ePO-MVT update fixes an "Escalation of Privileges" vulnerability". kc.mcafee.com. McAfee. Retrieved 20 January 2015.
  5. ^ "Security Vulnerability: GroupWise Client for Windows Remote Untrusted Pointer Dereference Vulnerability". www.novell.com. Novell. Retrieved 20 January 2015.
  6. ^ "Researchers at Swiss-based security firm High-Tech Bridge have identified serious vulnerabilities in several popular web applications". SecurityWeek. Retrieved 20 February 2016.
  7. ^ "Critical Zen Cart vulnerability could spell Black Friday disaster for online shoppers". BetaNews. Retrieved 20 February 2016.
  8. ^ "Product from High-Tech Bridge Now Registered as Officially "CWE-Compatible"". MITRE. Retrieved 7 August 2014.
  9. ^ "Organizations with CVE Identifiers in Advisories". 26 June 2013. Retrieved 1 September 2013.
  10. ^ "Free PCI and NIST compliant SSL test". Help Net Security. Retrieved 23 October 2015.
  11. ^ "TalkTalk boss receives ransom demand as massive customer data breach deepens". The Inquirer. Archived from the original on October 24, 2015. Retrieved 23 October 2015.{{cite web}}: CS1 maint : 부적합한 URL(링크)
  12. ^ "TalkTalk CEO admits security fail, says hacker emailed ransom demand". The Register. Retrieved 23 October 2015.
  13. ^ "Yahoo to pay up to $15,000 for bug finds after 't-shirt gate' scandal". 3 October 2013.
  14. ^ a b Kirk, Jeremy (3 October 2013). "Yahoo security bounty program ditches T-shirts for cash". Retrieved 19 October 2013.
  15. ^ Rubenking, Neil J. (1 October 2013). "Yahoo Offers Sad Bug Bounty: $12.50 in Company Swag". PC Magazine. Retrieved 19 October 2013.
  16. ^ Bilton, Ricardo (1 October 2013). "I reported a major Yahoo security vulnerability and all I got was this lousy T-shirt". Retrieved 19 October 2013.
  17. ^ Frank, Blair Hanley (1 October 2013). "Researchers find critical vulnerabilities in Yahoo's site, offered $12.50 per bug". Retrieved 19 October 2013.
  18. ^ Hackney, Steve (7 October 2013). "Yahoo! Inc. (NASDAQ:YHOO) Removes Bugs Identified By High Tech Bridge". Retrieved 19 October 2013.
  19. ^ Osborne, Charlie (3 October 2013). "Yahoo changes bug bounty policy following 't-shirt gate'". Retrieved 19 October 2013.
  20. ^ Martinez, Ramses (2 October 2013). "So I'm the guy who sent the t-shirt out as a thank you". Retrieved 19 October 2013.
  21. ^ "Social networks: can robots violate user privacy?". Archived from the original on 2014-01-03. Retrieved 2014-01-13.
  22. ^ "Facebook sued for allegedly intercepting private messages".
  23. ^ "Is Facebook spying on you?". CNBC.
  24. ^ Brook, Chris. "PHP patches buffer overflow vulnerabilities". threatpost. Retrieved 27 October 2014.
  25. ^ Fox-Brewster, Thomas. "RansomWeb: Crooks Start Encrypting Websites And Demanding Thousands Of Dollars From Businesses". Forbes.com. Retrieved 1 February 2015.
  26. ^ Gallagher, Sean (13 April 2015). "Universal backdoor for e-commerce platform lets hackers shop for victims". arstechnica. Retrieved 14 April 2015.
  27. ^ "Testing Your SSL Encryption Can Provide Important Security Insights". IBM Security Intelligence. 15 December 2015. Retrieved 15 December 2015.
  28. ^ "High-Tech Bridge Grades Email Services on Security, Gives Fastmail Top Score". Talkin Cloud. 3 December 2015. Retrieved 3 December 2015.

외부 링크

참고 항목