All the latest UK technology news, reviews and analysis

Veracode launches service to detect cross-site scripting and SQL injection flaws

by Shaun Nichols

02 Aug 2011

Be the first to comment

  • Tweet this

Veracode has launched a service designed to help companies root out security flaws such as cross-site scripting (XSS) and SQL injection vulnerabilities in web-based applications.

The Dynamic MP service allows customers to quickly scan web applications for the vulnerabilities commonly used by attackers to exploit servers and steal data.

Sam King, senior vice president of product marketing at Veracode, told V3 that corporate interest in SQL and XSS vulnerabilties increased after hacking groups such as LulzSec used the flaws to execute major data breaches.

"They don't want to become the next Sony. As a result of all these breaches in recent months, there is a heightened sense of concern about the highest risk vulnerabilities in forward-facing web applications," he said.

The challenge many firms encounter is the testing process itself, according to King. Testing applications for vulnerabilities can require large amounts of time and resources, making full scanning of all applications all but impossible for many firms.

Veracode hopes to address this by moving its security analysis engine to the cloud, offering a parallel system that can scan code for vulnerabilties far more efficiently.

"Scanning activities that would have taken weeks or months can now be done in hours or days," King said. "You cannot achieve this scale and this efficiency if you have an on-premise solution."

Veracode is offering Dynamic MP at $150 per web site for a minimum of 500 sites.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

40%

0%

10%

50%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Business Development Executive

A Multi-national data analytic's and cloud computing...

C# Developer

A multi-national software solutions organisation are...

UI Application Designer

A multi-national software solution provider are looking...

Service Delivery Manager

Service Delivery Manager, Customer Service, PCT, Primary...

To send to more than one email address, simply separate each address with a comma.