SlideShare a Scribd company logo
1 of 4
Download to read offline
J AVA S C R I P T S E C U R I T Y
BLUECLOSURE
BULLETPROOF YOUR CODE.
PROTECT YOUR USERS.
www.blueclosure.com
BC DETECT BC DETECT ENTERPRISE
THE LEADING PLATFORM FOR
JAVASC R IP T SE C URITY
AUTOMATION
Client Side scanner
Control & Orchestrate
View Alerts
BC DETECT ENTERPRISE
NEW SCAN
function setMessage() {
var t = location.hash.slice(1);
$(”div[id=” + t + “]”).html(”Message from
the name” + window.name);
}
$(document).ready(setMessage);
$(window).bind(“hashchange”, setMessage)
HTTPS://WWW.WEBSITE.COM
BC DETECT ENTERPRISE
Bc Detect Enterprise is a product designed to automate client-side JavaScript security
analysis,and to provide continuous integration with DevOps teams for testing Web client
side security issues.
SCANNING AUTOMATION: BC Detect Enterprise comes with a spider engine able to crawl all the web pages of a
domain simulating the user interaction.It can analyse at run time all the code that is running on the DOM of the browser
automatically.
EXPLOIT GENERATOR: BC Detect Enterprise has now the ability to create a Proof of Concept that can demonstrate the
attack for consultants who aren’t JavaScript experts but who come across potential issues whilst on other tests.It is also
able to automatically label findings on successful exploit execution.
REPORT GENERATOR: it is possible to export the results of a scan in PDF or CSV format.Auditor report comprise the list
of all vulnerabilities with exploits PoC.Developer report focuses on all the information useful to fix the vulnerabilities.
DUPLICATES HANDLING: duplicates are automatically aggregated to a single one saving the time spent in reviewing all
results.This is also useful on DevSecOps environments.
DevSecOps INTEGRATION SERVICES: the product comes with REST API giving users the chance to have full scan
control,findings notification and details analysis and exfiltration.
The following are the features of BlueClosure BC Detect Enterprise.
HTTPS://WWW.WEBSITE.COM
Client Side scanner
Control & Orchestrate
View Alerts
OPERATOR
BC DETECT BROWSER
BC DETECT
BC Detect (DOMinatorPro NG) helps security testers to analyse and automatically discover
DOM Based Cross Site Scripting issues thanks to its IAST Engine together with the Smart
Fuzzer module.
Blueclosure is a suite of products that represent a JavaScript security platform for developers, auditor,
testers, SOC in order to identify, detect and response to JavaScript security flaws in the code.
DISCOVER JAVASCRIPT FLAWS BEFORE ANYONE ELSE DOES
Client side vulnerabilities like DOM based Cross Site Scripting (XSS) are currently the most widespread advanced attacks.
FIND CLIENT SIDE VULNERABILITIES EASILY
Dynamic execution flows,browser quirks,different interpreters:few of the many factors that add up to the inherent difficul-
ty to pinpoint JavaScript security flaws.Conventional tools cannot find them:and if you can't find a flaw,you can't fix it.
A DIFFERENT APPROACH FOR THE DETECTION
BlueClosure BC Detect implements a IAST approach with runt time anlysis of the data flow that is running on the browsers.
BCDetect uses taint propagation so it is 100% sure the final data is controllable by a source.
USEFUL INFORMATION FOR A EASY FIXING
BCDetect adds more information about where the issue happens on the JavaScript code.That will help devs to give more
information about specific code fixing and the data flow.
J AVA S C R I P T S E C U R I T Y
BLUECLOSURE
BlueClosure is a registered trademark by Minded Security
Minded Security UK Limited
66 College Road, Harrow Middlesex. HA1 1BE
London - UK
VAT: UK 194 1370 06
Minded Security Srl
Via Duca D’Aosta, 20 - 50129
Firenze - Italy
More information:
info@mindedsecurity.com
http://www.mindedsecurity.com
Minded Security © 2017 - All rights reserved

More Related Content

More from Minded Security

Matteo meucci Software Security - Napoli 10112016
Matteo meucci   Software Security - Napoli 10112016Matteo meucci   Software Security - Napoli 10112016
Matteo meucci Software Security - Napoli 10112016Minded Security
 
Matteo Meucci Software Security in practice - Aiea torino - 30-10-2015
Matteo Meucci   Software Security in practice - Aiea torino - 30-10-2015Matteo Meucci   Software Security in practice - Aiea torino - 30-10-2015
Matteo Meucci Software Security in practice - Aiea torino - 30-10-2015Minded Security
 
Advanced JS Deobfuscation
Advanced JS DeobfuscationAdvanced JS Deobfuscation
Advanced JS DeobfuscationMinded Security
 
Sandboxing JS and HTML. A lession Learned
Sandboxing JS and HTML. A lession LearnedSandboxing JS and HTML. A lession Learned
Sandboxing JS and HTML. A lession LearnedMinded Security
 
Concrete5 Sendmail RCE Advisory
Concrete5 Sendmail RCE AdvisoryConcrete5 Sendmail RCE Advisory
Concrete5 Sendmail RCE AdvisoryMinded Security
 
Concrete5 Multiple Reflected XSS Advisory
Concrete5 Multiple Reflected XSS AdvisoryConcrete5 Multiple Reflected XSS Advisory
Concrete5 Multiple Reflected XSS AdvisoryMinded Security
 

More from Minded Security (8)

Matteo meucci Software Security - Napoli 10112016
Matteo meucci   Software Security - Napoli 10112016Matteo meucci   Software Security - Napoli 10112016
Matteo meucci Software Security - Napoli 10112016
 
Matteo Meucci Software Security in practice - Aiea torino - 30-10-2015
Matteo Meucci   Software Security in practice - Aiea torino - 30-10-2015Matteo Meucci   Software Security in practice - Aiea torino - 30-10-2015
Matteo Meucci Software Security in practice - Aiea torino - 30-10-2015
 
Advanced JS Deobfuscation
Advanced JS DeobfuscationAdvanced JS Deobfuscation
Advanced JS Deobfuscation
 
Sandboxing JS and HTML. A lession Learned
Sandboxing JS and HTML. A lession LearnedSandboxing JS and HTML. A lession Learned
Sandboxing JS and HTML. A lession Learned
 
Concrete5 Sendmail RCE Advisory
Concrete5 Sendmail RCE AdvisoryConcrete5 Sendmail RCE Advisory
Concrete5 Sendmail RCE Advisory
 
Concrete5 Multiple Reflected XSS Advisory
Concrete5 Multiple Reflected XSS AdvisoryConcrete5 Multiple Reflected XSS Advisory
Concrete5 Multiple Reflected XSS Advisory
 
PHP Object Injection
PHP Object InjectionPHP Object Injection
PHP Object Injection
 
iOS Masque Attack
iOS Masque AttackiOS Masque Attack
iOS Masque Attack
 

Recently uploaded

定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一Fs
 
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书rnrncn29
 
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一z xss
 
Film cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasaFilm cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasa494f574xmv
 
Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...Excelmac1
 
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)Christopher H Felton
 
Q4-1-Illustrating-Hypothesis-Testing.pptx
Q4-1-Illustrating-Hypothesis-Testing.pptxQ4-1-Illustrating-Hypothesis-Testing.pptx
Q4-1-Illustrating-Hypothesis-Testing.pptxeditsforyah
 
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一Fs
 
Git and Github workshop GDSC MLRITM
Git and Github  workshop GDSC MLRITMGit and Github  workshop GDSC MLRITM
Git and Github workshop GDSC MLRITMgdsc13
 
Top 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxTop 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxDyna Gilbert
 
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一Fs
 
Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Paul Calvano
 
Contact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New DelhiContact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New Delhimiss dipika
 
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作ys8omjxb
 
NSX-T and Service Interfaces presentation
NSX-T and Service Interfaces presentationNSX-T and Service Interfaces presentation
NSX-T and Service Interfaces presentationMarko4394
 
Elevate Your Business with Our IT Expertise in New Orleans
Elevate Your Business with Our IT Expertise in New OrleansElevate Your Business with Our IT Expertise in New Orleans
Elevate Your Business with Our IT Expertise in New Orleanscorenetworkseo
 
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书rnrncn29
 
Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Sonam Pathan
 

Recently uploaded (20)

定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
定制(Lincoln毕业证书)新西兰林肯大学毕业证成绩单原版一比一
 
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
『澳洲文凭』买拉筹伯大学毕业证书成绩单办理澳洲LTU文凭学位证书
 
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
办理(UofR毕业证书)罗切斯特大学毕业证成绩单原版一比一
 
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Serviceyoung call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
young call girls in Uttam Nagar🔝 9953056974 🔝 Delhi escort Service
 
Film cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasaFilm cover research (1).pptxsdasdasdasdasdasa
Film cover research (1).pptxsdasdasdasdasdasa
 
Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...Blepharitis inflammation of eyelid symptoms cause everything included along w...
Blepharitis inflammation of eyelid symptoms cause everything included along w...
 
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
A Good Girl's Guide to Murder (A Good Girl's Guide to Murder, #1)
 
Q4-1-Illustrating-Hypothesis-Testing.pptx
Q4-1-Illustrating-Hypothesis-Testing.pptxQ4-1-Illustrating-Hypothesis-Testing.pptx
Q4-1-Illustrating-Hypothesis-Testing.pptx
 
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
定制(AUT毕业证书)新西兰奥克兰理工大学毕业证成绩单原版一比一
 
Hot Sexy call girls in Rk Puram 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in  Rk Puram 🔝 9953056974 🔝 Delhi escort ServiceHot Sexy call girls in  Rk Puram 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Rk Puram 🔝 9953056974 🔝 Delhi escort Service
 
Git and Github workshop GDSC MLRITM
Git and Github  workshop GDSC MLRITMGit and Github  workshop GDSC MLRITM
Git and Github workshop GDSC MLRITM
 
Top 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptxTop 10 Interactive Website Design Trends in 2024.pptx
Top 10 Interactive Website Design Trends in 2024.pptx
 
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
定制(Management毕业证书)新加坡管理大学毕业证成绩单原版一比一
 
Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24Font Performance - NYC WebPerf Meetup April '24
Font Performance - NYC WebPerf Meetup April '24
 
Contact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New DelhiContact Rya Baby for Call Girls New Delhi
Contact Rya Baby for Call Girls New Delhi
 
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
Potsdam FH学位证,波茨坦应用技术大学毕业证书1:1制作
 
NSX-T and Service Interfaces presentation
NSX-T and Service Interfaces presentationNSX-T and Service Interfaces presentation
NSX-T and Service Interfaces presentation
 
Elevate Your Business with Our IT Expertise in New Orleans
Elevate Your Business with Our IT Expertise in New OrleansElevate Your Business with Our IT Expertise in New Orleans
Elevate Your Business with Our IT Expertise in New Orleans
 
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
『澳洲文凭』买詹姆士库克大学毕业证书成绩单办理澳洲JCU文凭学位证书
 
Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170Call Girls Near The Suryaa Hotel New Delhi 9873777170
Call Girls Near The Suryaa Hotel New Delhi 9873777170
 

BlueClosure BC Detect Brochure 2017

  • 1. J AVA S C R I P T S E C U R I T Y BLUECLOSURE BULLETPROOF YOUR CODE. PROTECT YOUR USERS. www.blueclosure.com BC DETECT BC DETECT ENTERPRISE THE LEADING PLATFORM FOR JAVASC R IP T SE C URITY
  • 2. AUTOMATION Client Side scanner Control & Orchestrate View Alerts BC DETECT ENTERPRISE NEW SCAN function setMessage() { var t = location.hash.slice(1); $(”div[id=” + t + “]”).html(”Message from the name” + window.name); } $(document).ready(setMessage); $(window).bind(“hashchange”, setMessage) HTTPS://WWW.WEBSITE.COM BC DETECT ENTERPRISE Bc Detect Enterprise is a product designed to automate client-side JavaScript security analysis,and to provide continuous integration with DevOps teams for testing Web client side security issues. SCANNING AUTOMATION: BC Detect Enterprise comes with a spider engine able to crawl all the web pages of a domain simulating the user interaction.It can analyse at run time all the code that is running on the DOM of the browser automatically. EXPLOIT GENERATOR: BC Detect Enterprise has now the ability to create a Proof of Concept that can demonstrate the attack for consultants who aren’t JavaScript experts but who come across potential issues whilst on other tests.It is also able to automatically label findings on successful exploit execution. REPORT GENERATOR: it is possible to export the results of a scan in PDF or CSV format.Auditor report comprise the list of all vulnerabilities with exploits PoC.Developer report focuses on all the information useful to fix the vulnerabilities. DUPLICATES HANDLING: duplicates are automatically aggregated to a single one saving the time spent in reviewing all results.This is also useful on DevSecOps environments. DevSecOps INTEGRATION SERVICES: the product comes with REST API giving users the chance to have full scan control,findings notification and details analysis and exfiltration. The following are the features of BlueClosure BC Detect Enterprise.
  • 3. HTTPS://WWW.WEBSITE.COM Client Side scanner Control & Orchestrate View Alerts OPERATOR BC DETECT BROWSER BC DETECT BC Detect (DOMinatorPro NG) helps security testers to analyse and automatically discover DOM Based Cross Site Scripting issues thanks to its IAST Engine together with the Smart Fuzzer module. Blueclosure is a suite of products that represent a JavaScript security platform for developers, auditor, testers, SOC in order to identify, detect and response to JavaScript security flaws in the code. DISCOVER JAVASCRIPT FLAWS BEFORE ANYONE ELSE DOES Client side vulnerabilities like DOM based Cross Site Scripting (XSS) are currently the most widespread advanced attacks. FIND CLIENT SIDE VULNERABILITIES EASILY Dynamic execution flows,browser quirks,different interpreters:few of the many factors that add up to the inherent difficul- ty to pinpoint JavaScript security flaws.Conventional tools cannot find them:and if you can't find a flaw,you can't fix it. A DIFFERENT APPROACH FOR THE DETECTION BlueClosure BC Detect implements a IAST approach with runt time anlysis of the data flow that is running on the browsers. BCDetect uses taint propagation so it is 100% sure the final data is controllable by a source. USEFUL INFORMATION FOR A EASY FIXING BCDetect adds more information about where the issue happens on the JavaScript code.That will help devs to give more information about specific code fixing and the data flow.
  • 4. J AVA S C R I P T S E C U R I T Y BLUECLOSURE BlueClosure is a registered trademark by Minded Security Minded Security UK Limited 66 College Road, Harrow Middlesex. HA1 1BE London - UK VAT: UK 194 1370 06 Minded Security Srl Via Duca D’Aosta, 20 - 50129 Firenze - Italy More information: info@mindedsecurity.com http://www.mindedsecurity.com Minded Security © 2017 - All rights reserved