COMPANY NEWS

  • Accuracy and Time Costs of Web Application Security Scanner Report - February 3rd, 2010
    A new whitepaper by Larry Suto has been posted on the popular Ha.ckers.org blog.  Larry has followed up his 2007 review with a new analysis of the web app scanners on the market. This latest whitepaper details his findings when he compared six web application security scanners (Including NTOSpider) against six vulnerable test sites. From the report: Of the vulnerabilities on the web apps he scanned, the scanners missed an average of 49% of them. "NTOSpider found over twice as many vulnerabilities as the average competitor having a 94% accuracy rating, with Hailstorm having the second best rating of 62%, but only after extensive training by an expert. Appscan had the second best 'Point and Shoot' rating of 55% and the rest averaged 39%." "As clearly the leader in terms of quality results, NTOSpider performed very well. The results make a great case for using NTOSpider as the first choice for automated scanning." Read the full whitepaper   Update: Due to the number of counter-claims/accusations going around, we have posted our response. References on the web to this whitepaper: Ha.ckers.org Slashdot Darkreading An Information Security Place Podcast SemiAccurate (Part 1) / (Part 2) Infosec Island Alan Shimel's Blog Rootsecure Playnoevil Tactical Web App Security Security-dojo

  • NT Objectives Releases NTOSpider 5.0 - November 16th, 2009
    NTO is proud to release another major upgrade in only 6 month after the previous version. Here is a list of the major enhancements: Improvements to User Interface Updated navigation for configuration screens Live view of the vulnerabilities details during a scan Ability to view raw traffic for issues during a scan New attack module: Arbitrary File Upload New attack module: Remote File Include Ability to view raw traffic for each vuln in the reporting Improved Validate applet Improved Proxy support New cookie management Tabs for showing multi-request attacks New debugging capabilities (detailed logging) CAC Card support Applet proxy (Burp) support Added CWEID, CAPEC, OWASP, and OVAL ids mappings to reporting Improved performance with XSS attacks  

  • NTO Grows Its Podcasting Efforts - August 18th, 2009
    Dan Kuykendall, co-CEO of NT OBJECTives is joining the An Information Security Place Podcast as a regular host. The podcast id about general information securityand Dan will be the resident webappsec expert to comment on those topics. This will be in addition to the MightySeek Podcast that Dan currently hosts, and which is dedicated purely to Web Application Security

  • NT Objectives Releases NTOSpider 4.0 - May 1st, 2009
    NTO is proud to release this major upgrade that was 18 months in the making. Here is a list of the major enhancements: PCI / HIPPA / SOX Analysis and Reporting Cookie Attacking HTTP Header attack Privilege Escalation Session logout detection and re-establishment Malicious Script Analysis / External iFrame Analysis Next generation FORM parameter analysis and attacking engine Report scalability improvements New memory management system for greater scalability Enhanced solution for attacking Login Pages without losing session Second Generation AJAX analysis Enhanced Reflection Analysis processing for partial reflections and multi reflection points Improvements in all core attacking modules (SQL, BSQL, XSS,CMDI) for reduced false positives, plus expanded number of attacks Crawler Enhancements - better analysis of image URLs with parameters Improved handling of .NET and _VIEWSTATE technologies Multiple Encoding support for all attack modules Ability to view raw traffic for all Vulnerability findings Web Application Firewall Integration (Imperva)

  • Nebulas Solutions selects NTO - March 5th, 2009
    "Nebulas Solutions has signed three more vendors to its Technology Incubatorscheme" including "web applicationvulnerability assessment tools vendor NT Objectives" Read the full press release

  • NTO Partners with eEye Digital Security - March 13th, 2008
    “Web 2.0 and SaaS are rapidly becoming the predominant delivery model for software,” said Kamal Arafeh, CEO, eEye Digital Security. “Traditional firewalls, SSL VPNs and other security products cannot fully protect against flaws in these web applications. eEye believes that the vulnerability landscape needs to change and evolve yet again to meet this new set of challenges. For the past ten years, eEye products have addressed operating system and application vulnerabilities and now with Retina Web Security Scanner, we are innovating further to address web application vulnerabilities and flaws.” Read the full press release

  • Analyzing the Effectiveness and Coverage of Web Application Security Scanners - October 14th, 2007
    Larry Suto, an independent consultant for many large organizations, has published a whitepaper that compares NTOSpider, WebInspect and AppScan. This study focuses on each scanners ability to be used in "Point and Shoot" usage. The report demonstrates our ability to perform very well in this usage and additionally highlights the quality of our scan results and ability to avoid False Positives.

  • NTO Partners with Veracode - August 8th, 2007
    "We believe NT OBJECTives' technology will be a strong addition toVeracode’s on-demand platform based on its comprehensive coverage,accuracy and market leading automation" said Chris Wysopal, VeracodeCTO Read the full press release

  • Assessing Assessment: Top 10 Questions When Evaluating Application Vulnerability Scanners - November 29th, 2005
    Assessing Assessment: Top 10 Questions When Evaluating Application Vulnerability Scanners Read full article

  • ITSecuirty: Web Application Security: We Need to Increase Our Budget... - October 28th, 2005
    Web Application Security: We Need to Increase Our Budget Read full article

  • Sarbanes-Oxley Compliance Journal: Targeted Remediation of Vulnerablilities - October 11th, 2005
    Targeted Remediation of Vulnerablilities Read full article

  • Enterprise Systems: Targets Shift for Application Security Attacks - September 13th, 2005
    Targets Shift for Application Security Attacks Read full article

  • CIO Decisions: Security Outsourcing Grabs Hold - September 5th, 2005
    Security Outsourcing Grabs Hold Read full article

  • Network World: NT OBJECTives tests your Web apps for vulnerabilities - August 15th, 2005
    Network World - NT OBJECTives tests your Web apps for vulnerabilities Read full article

  • InformationWeek: NTO Speeds Financial Product Delivery - August 11th, 2005
    Ken Pfeil says, "We're securing the application about 20% faster than we have in the past"

  • USA Today: Hackers shift focus to swiping ID information - July 18th, 2005
    Hackers shift focus to swiping ID information Read full article

  • SAP INFO: Website Attacks Skyrocket - July 18th, 2005
    Website Attacks Skyrocket Read full article

  • Information Week: Companies Experience Exponential Rise In Web Attacks: Survey - July 15th, 2005
    Companies Experience Exponential Rise In Web Attacks: Survey Read full article

  • Comprehensive Technology and Knowledgeable Experts Help Organizations Discover Threats, Analyze Risk and Develop Sound Security Strategies - May 19th, 2005
    Comprehensive Technology and Knowledgeable Experts Help Organizations Discover Threats, Analyze Risk and Develop Sound Security Strategies Read full article

  • ITsecurity: NT OBJECTives Offers Freeware to Strengthen Website Security - May 17th, 2005
    NT OBJECTives Offers Freeware to Strengthen Website Security Read full article

  • Windows IT Pro: NT OBJECTives Offers Two Free Security Tools - May 17th, 2005
    NT OBJECTives Offers Two Free Security Tools Read full article

  • SD Times: Expanding Array of App Security Offerings - May 1st, 2005
    Expanding Array of App Security Offerings Read full article

  • Credit Union Tech-Talk: NT OBJECTives Launches Automated Application Security Solution - April 18th, 2005
    NT OBJECTives Launches Automated Application Security Solution Read full article

  • EnterpriseITPlanet: NTOSpider Automated Web Application Vulnerability Scanner - April 14th, 2005
    NTOSpider Automated Web Application Vulnerability Scanner Read full article

  • PCReview: NTO Helps CapitalIQ with Time to Market - April 12th, 2005
    NTO Helps CapitalIQ with Time to Market Read full article

  • CompliancePipeline: NT OBJECTives App Security Helps Capital IQ With Time To Market - April 11th, 2005
    NT OBJECTives App Security Helps Capital IQ With Time To Market Read full article

  • FreshNews: NTO Launches Automated Application Security Solution - April 11th, 2005
    NTO Launches Automated Application Security Solution Read full article

  • Red Herring: Next Wave - Security Hole Offers Way In - October 1st, 2004
    Next Wave: Security Hole Offers Way In Read full article