Using Encoded FTP Commands to Infect a Web server by Joshua Roback, SOC Analyst

When it comes to protecting a web server from outside attack, any decent administrator has gone though the ringer in preventing brute force, SQL injection, open port scans and other types of well-known vulnerabilities. Hours of research has been done on preventing remote file inclusion attacks and PHP injection attacks as well. Often missed though, [...]

Securing XO Communications’ Enterprise Cloud Communications

Today we announced a new partnership with XO Communications.  In brief, StillSecure will be providing all the managed security services, including 24x7x365 support from our Security Operations Center, for their Enterprise Cloud Communications service.  While this is certainly a very important partnership for us, we also believe it’s a big step in the right direction for how enterprises think about, and [...]

Two Factor Authentication exploit by Gabriel Bellas, Still Secure SOC Analyst

Companies utilize two-factor authentication to add an extra layer of security to their systems. This can be in the form of a debit card and pin combination, RSA key, smart card, etc. The idea is that a user needs to have a token, and a password to authenticate. A very popular form of two-factor authentication [...]