Security Analysis with Bamboo Plugin

25 Oct 2017 by Martin Bednorz

RIPS Bamboo Integration

Bamboo is a widely used software that enables continuous integration, deployment, and delivery of software applications. It is developed by the Australian company Atlassian that is also well known for their products JIRA and BitBucket. This blog post introduces our Bamboo integration and how it can be used to continuously analyze your PHP application with RIPS. By automatically detecting and warning about security issues, your production server can be protected from new vulnerabilities.

Read More ...

Security Analysis with SonarQube Plugin

4 Aug 2017 by Martin Bednorz

SonarQube

SonarQube is one of the leading products for continuous code quality inspection and is used by more than 80,000 organizations world-wide to automatically detect a large variety of code quality issues. But in today’s world the detection of security issues is even more important. RIPS Technologies enables to integrate its awarded security analysis solution directly into SonarQube through a plugin. It allows to continuously scan existing SonarQube projects for security threats and for quality issues so that the deployment of unstable applications can be prevented.

Read More ...

What's new in RIPS 2.0.0?

18 Apr 2017 by Martin Bednorz

New User Interface

We are happy to announce the next iteration of our static analysis software for PHP! The new release RIPS 2.0.0 includes the following major changes:

  • A complete new interface with optimized performance (demo.ripstech.com)
  • A new extensive REST API for full feature automation (api.ripstech.com)
  • Team and user privilege management
  • Application-specific analysis profiles
  • More detailed code summaries and issue descriptions
  • Issue categorization for PCI DSS compliance requirements
  • Improved analysis precision and performance
  • Detection of Cookie Misconfiguration issues (CWE-613, CWE-614, CWE-1004)
  • Detection of Insufficient Certificate Validation issues (CWE-295, CWE-297)

Find out more about the top 5 new features in this blog post.

Read More ...

AbanteCart 1.2.8 - Multiple SQL Injections

21 Dec 2016 by Martin Bednorz

AbanteCart

In our 21st advent calendar gift, we cover AbanteCart, a very popular e-commerce solution that just turned 5 years old last month. RIPS found multiple SQL injections, PHP object injections, and the complementary cross-site scriptings so that the more severe vulnerabilities can be exploited. Interestingly, the AbanteCart website was defaced just moments before we send out our analysis report to the development team.

Read More ...

Kliqqi 3.0.0.5: From Cross-Site Request Forgery to Code Execution

20 Dec 2016 by Martin Bednorz

Kliqqi

Today’s gift in our advent calendar contains descriptions of vulnerabilities in Kliqqi, the successor to the popular Pligg CMS mostly used for the creation of interactive social communities. Due to missing CSRF protection, an attacker is able to prepare a website that ultimately leads to code execution on the applications server when visited by a target.

Read More ...