<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE rss [<!ENTITY % HTMLlat1 PUBLIC "-//W3C//ENTITIES Latin 1 for XHTML//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml-lat1.ent">]>
<rss version="2.0" xml:base="http://www.infigo.hr">
<channel>
 <title>Infigo - New Document</title>
 <link>http://www.infigo.hr/taxonomy/term/32/0</link>
 <description></description>
 <language>en</language>
<item>
 <title>Whitepapers</title>
 <link>http://www.infigo.hr/whitepapers/start</link>
 <description>&lt;p align=&quot;justify&quot;&gt;Correct understanding of problems and terms related to information security is critical for global security awareness raise.&lt;/p&gt;
&lt;p align=&quot;justify&quot;&gt;INFIGO IS publishes whitepapers to provide better understanding of specific terms and problems in the information security area. Depth and topics of published whitepapers varies from detailed descriptions of specific technical topics intended for security experts up to the general description of information security management systems intended for security managers and broad audience.&lt;/p&gt;
&lt;p align=&quot;justify&quot;&gt;Whitepapers published on these pages are the sole property of INFIGO IS and can be used only in accordance with the &lt;a href=&quot;en/uvjeti_koristenja&quot;&gt;Terms of Use&lt;/a&gt;.&lt;/p&gt;
&lt;p align=&quot;right&quot;&gt;&lt;a href=&quot;en/taxonomy/term/32/0/feed&quot;&gt;&lt;img title=&quot;rss&quot; alt=&quot;rss&quot; src=&quot;files/rss2.gif&quot; border=&quot;0&quot; /&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p class=&quot;crvena_linija&quot; align=&quot;justify&quot;&gt;&amp;nbsp;&lt;/p&gt;
</description>
 <category domain="http://www.infigo.hr/en/dokumenti">New Document</category>
 <pubDate>Fri, 31 Mar 2006 10:44:03 +0200</pubDate>
</item>
<item>
 <title>Advanced PostgreSQL SQL Injection and Filter Bypass Techniques</title>
 <link>http://www.infigo.hr/whitepapers/doc_5</link>
 <description>&lt;table width=&quot;585&quot; border=&quot;0&quot; style=&quot;height: 264px&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; style=&quot;width: 17%&quot;&gt;&lt;font color=&quot;#000000&quot; class=&quot;crveni_tekst&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;font color=&quot;#0066cc&quot;&gt;&lt;a target=&quot;_blank&quot; href=&quot;files/INFIGO-TD-2009-04_PostgreSQL_injection_ENG.pdf&quot;&gt;Advanced PostgreSQL SQL Injection and Filter Bypass Techniques&lt;/a&gt;&lt;/font&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;2009-06-17&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Size:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;156 Kb&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&amp;nbsp;&lt;span class=&quot;crveni_tekst&quot;&gt;Category:&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/td&gt;
&lt;td&gt;Technical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&amp;nbsp;&lt;span class=&quot;crveni_tekst&quot;&gt;Complexity:&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/td&gt;
&lt;td&gt;&lt;strong&gt;&amp;nbsp;***&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot; align=&quot;justify&quot;&gt;
&lt;p&gt;According to the WhiteHat Website Security Statistics Report from 2009, SQL injection vulnerabilities make up to 17% of all web application vulnerabilities. Besides being very common, SQL injection vulnerabilities typically allow an attacker to read or even modify arbitrary data in the database used by the web application. This increases the risk resulting from such vulnerabilities.&lt;/p&gt;
&lt;p&gt;In order to increase the overall security of web applications, companies today often implement web application firewalls or filters. While web application firewalls can indeed stop certain attacks, they are not a complete solution to web application vulnerabilities.&lt;/p&gt;
&lt;p&gt;This document demonstrates advanced blind SQL injection vulnerabilities on PostgreSQL databases. The document is result of a penetration test performed on a real system, with real web application firewall protecting a vulnerable web application.&lt;/p&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
 <category domain="http://www.infigo.hr/en/dokumenti">New Document</category>
 <pubDate>Wed, 17 Jun 2009 14:36:22 +0200</pubDate>
</item>
<item>
 <title>Analysis of a Banker Trojan</title>
 <link>http://www.infigo.hr/whitepapers/doc_4</link>
 <description>&lt;table width=&quot;585&quot; border=&quot;0&quot; style=&quot;height: 264px&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; style=&quot;width: 17%&quot;&gt;&lt;font color=&quot;#000000&quot; class=&quot;crveni_tekst&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;font color=&quot;#0066cc&quot;&gt;&lt;a target=&quot;_blank&quot; href=&quot;files/INFIGO-TD-2008-02-Banker_ENG.pdf&quot;&gt;Analysis of a Banker Trojan&lt;/a&gt;&lt;/font&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;2008-12-22&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Size:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;371 Kb&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&amp;nbsp;&lt;span class=&quot;crveni_tekst&quot;&gt;Category:&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/td&gt;
&lt;td&gt;Technical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&amp;nbsp;&lt;span class=&quot;crveni_tekst&quot;&gt;Complexity:&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/td&gt;
&lt;td&gt;&lt;strong&gt;&amp;nbsp;***&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot; align=&quot;justify&quot;&gt;
&lt;p&gt;The rise of criminal activity on the Internet has been evident quite some time. In the last couple of years, the criminals have started targeting Internet banking users. The increasing number of targeted malware calls for additional caution.&lt;/p&gt;
&lt;p&gt;Croatian banks have historically been neglected by various Trojan horses, probably due to two main reasons: a perception of a smaller return of invested to the attackers and relatively high levels of protection implemented in Internet banking services typically found in Croatia.&lt;/p&gt;
&lt;p&gt;INFIGO IS&#039;s security research team regularly tracks and analyses malicious activities on the Internet. For the first time, a Trojan horse belonging to the Banker family that amongst foreign banks also attacks Croatian banks has been identified. The two biggest Croatian banks, &amp;quot;Zagrebacka banka&amp;quot; and &amp;quot;Privredna banka&amp;quot; are targeted by the Trojan. These banks are especially attractive to attackers due to their large number of clients.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
 <category domain="http://www.infigo.hr/en/dokumenti">New Document</category>
 <pubDate>Mon, 22 Dec 2008 10:36:00 +0100</pubDate>
</item>
<item>
 <title>Scaling of Values of Multiplicative Method for Risk Evaluation</title>
 <link>http://www.infigo.hr/whitepapers/doc_3</link>
 <description>&lt;table width=&quot;585&quot; border=&quot;0&quot; style=&quot;height: 264px&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; style=&quot;width: 17%&quot;&gt;&lt;font color=&quot;#000000&quot; class=&quot;crveni_tekst&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;font color=&quot;#0066cc&quot;&gt;&lt;a target=&quot;_blank&quot; href=&quot;files/INFIGO-MD-2007-02-RiskAnalysis_ENG.pdf&quot;&gt;Scaling of Values of Multiplicative Method for Risk Evaluation&lt;/a&gt;&lt;/font&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;2007-06-01&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Size:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;157 Kb&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&amp;nbsp;&lt;span class=&quot;crveni_tekst&quot;&gt;Category:&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/td&gt;
&lt;td&gt;Management&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&amp;nbsp;&lt;span class=&quot;crveni_tekst&quot;&gt;Complexity:&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/td&gt;
&lt;td&gt;&lt;strong&gt;&amp;nbsp;***&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p&gt;According to the multiplicative method of risk evaluation, risk is assessed as the product of resource values - AV (asset value), PT (threat probability) and IT (threat impact). This method allows arbitrary, independent value scales which all variables (AV, P, I) can assume, but the most common scales used in practice are identical, linear scales.&lt;/p&gt;
&lt;p&gt;The objects of this study are the possibilities of using nonlinear independent value scales for risk evaluation and their applicability in various practical situations. This paper will analyze the influence of nonlinear value scales in borderline cases when threat probability is considerably different than the threat impact.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
 <category domain="http://www.infigo.hr/en/dokumenti">New Document</category>
 <pubDate>Tue, 09 Dec 2008 17:14:00 +0100</pubDate>
</item>
<item>
 <title>Qualitative risk analysis method comparison</title>
 <link>http://www.infigo.hr/whitepapers/doc_2</link>
 <description>&lt;table width=&quot;585&quot; border=&quot;0&quot; style=&quot;height: 314px&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; style=&quot;width: 17%&quot;&gt;&lt;font color=&quot;#000000&quot; class=&quot;crveni_tekst&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;font color=&quot;#0066cc&quot;&gt;&lt;a target=&quot;_blank&quot; href=&quot;files/INFIGO-MD-2006-06-01-RiskAsses_ENG.pdf&quot;&gt;Qualitative risk analysis method comparison&lt;/a&gt;&lt;/font&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;2006-06-01&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Size:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;177 Kb&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&amp;nbsp;&lt;span class=&quot;crveni_tekst&quot;&gt;Category:&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/td&gt;
&lt;td&gt;Management&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&amp;nbsp;&lt;span class=&quot;crveni_tekst&quot;&gt;Complexity:&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/td&gt;
&lt;td&gt;&lt;strong&gt;&amp;nbsp;***&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot; align=&quot;justify&quot;&gt;
&lt;p&gt;Information security management is a business process part that is usually required by various regulatory laws.&lt;/p&gt;
&lt;p&gt;Security controls are defined by the business to ensure an adequate security level that is validated by a process called risk management. The risk management process allows the definition of strategy and goals in an organization&amp;rsquo;s information security.&lt;/p&gt;
&lt;p&gt;The most important part of this process, which is usually prone to errors, is the first step - risk assessment. Literature classifies risk assessment as qualitative and quantitative. Qualitative risk assessment calculates the risk level using plain judgment and assessor&amp;rsquo;s experience, while quantitative risk assessment depends on a numerical model (typically based on financial values).&lt;/p&gt;
&lt;p&gt;Although, in theory, quantitative risk assessment allows for a more detailed risk assessment, in practice this approach is usually not adequate, as an information resource&amp;rsquo;s value is based on its financial value (which does not show the true value of the information resource for a corporation). This is the main reason why a combination of qualitative and quantitative methods is preferred for risk assessment. As qualitative risk assessment is based on subjective judgment, it is prone to errors.&lt;/p&gt;
&lt;p&gt;This paper analyzes some qualitative (quantitative-qualitative) risk assessment methods. Special attention is given to the influence of various elements on risk assessment result and reliability.&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
 <category domain="http://www.infigo.hr/en/dokumenti">New Document</category>
 <pubDate>Tue, 09 Dec 2008 17:10:54 +0100</pubDate>
</item>
<item>
 <title>Using fuzzing to detect security vulnerabilities</title>
 <link>http://www.infigo.hr/whitepapers/doc_1</link>
 <description>&lt;table style=&quot;height: 314px&quot; width=&quot;585&quot; border=&quot;0&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 17%&quot; align=&quot;right&quot;&gt;&lt;font class=&quot;crveni_tekst&quot; color=&quot;#000000&quot;&gt;&lt;span class=&quot;crveni_tekst&quot;&gt;Title:&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/span&gt; &lt;/font&gt;&lt;/td&gt;
&lt;td&gt;&lt;font color=&quot;#0066cc&quot;&gt;&lt;a href=&quot;files/INFIGO-TD-2006-04-01-Fuzzing-eng.pdf&quot; target=&quot;_blank&quot;&gt;Using fuzzing to detect security vulnerabilities&lt;/a&gt;&lt;/font&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Date:&amp;nbsp; &amp;nbsp;&lt;/td&gt;
&lt;td&gt;2006-07-03&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Size:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td&gt;344&amp;nbsp;Kb&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&amp;nbsp;&lt;span class=&quot;crveni_tekst&quot;&gt;Category:&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/td&gt;
&lt;td&gt;Technical&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td align=&quot;right&quot;&gt;&amp;nbsp;&lt;span class=&quot;crveni_tekst&quot;&gt;Complexity:&lt;/span&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/td&gt;
&lt;td&gt;&lt;strong&gt;&amp;nbsp;***&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td class=&quot;crveni_tekst&quot; valign=&quot;top&quot; align=&quot;right&quot; class=&quot;crveni_tekst&quot;&gt;Summary:&amp;nbsp; &amp;nbsp; &lt;/td&gt;
&lt;td valign=&quot;top&quot;&gt;
&lt;p align=&quot;justify&quot;&gt;Most computer system intrusions are a result of security vulnerabilities in applications. Detection and identification of security vulnerabilities is an interesting process not only for security experts and system administrators, but also for intruders attempting to penetrate computer systems.&lt;/p&gt;
&lt;p align=&quot;justify&quot;&gt;In last couple of years, special attention was given to the technique called fuzzing. This method allows relatively fast detection of critical security vulnerabilities in various applications. Critical security vulnerabilities are usually variations of buffer overflow attacks, which allow an unauthorized user to overwrite critical parts of a vulnerable process memory. The result of exploiting this vulnerability is usually execution of a shellcode, a specially written code that was injected into a process by the unauthorized user in order to get access to the target system.&lt;/p&gt;
&lt;p align=&quot;justify&quot;&gt;This paper describes basic fuzzing categories and techniques. Several examples of fuzzing efficiency are also shown in the paper. Examples were produced by&amp;nbsp;&lt;a href=&quot;en/in_focus/tools&quot;&gt;Infigo FTPStress Fuzzer&lt;/a&gt; tool against FTP protocol.&lt;br /&gt;&amp;nbsp;&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
</description>
 <category domain="http://www.infigo.hr/en/dokumenti">New Document</category>
 <pubDate>Mon, 03 Jul 2006 17:12:24 +0200</pubDate>
</item>
</channel>
</rss>
