Speedy and low-cost! Quickly detect vulnerabilities in servers and web applications.
The vulnerability assessment service "Site-Audit" is a diagnostic service that quickly and cost-effectively identifies security flaws (vulnerabilities) in servers and applications. 【This service addresses the following challenges】 - I cannot spend a lot on security measures but want to understand the current risks. - I want to take immediate action against website tampering and personal information leaks. - I want to conduct assessments in compliance with security standards and guidelines. 【Main Features】 1. Platform Assessment: Comprehensive diagnosis of server and OS vulnerabilities based on CVSS/CVE with over 140,000 patterns. 2. Application Assessment: Detection of risks such as SQL injection and cross-site scripting (XSS) through simulated attacks based on OWASP/CWE. 3. Clear Report Submission: A report summarizing the assessment results and issues will be provided. As a first step in security measures, this service is ideal for continuously and easily understanding the current situation.
Inquire About This Product
basic information
【Diagnosis Menu】 ■ Platform Diagnosis - Vulnerabilities in OS/middleware, validity of certificates, presence of guessable passwords, possibility of eavesdropping on communications (encryption suite evaluation), careless exposure of databases and samples, etc. ■ Application Diagnosis - SQL injection, cross-site scripting (XSS), CSRF, path traversal/directory traversal, code/XSLT injection, buffer overflow, etc. 【Provision Conditions】 - Target: Websites, public servers, etc. (Note: In principle, diagnosis on shared servers is not allowed) - The package fee includes an initial diagnosis and a "re-diagnosis" after countermeasures, totaling two times. - Options: Vulnerability response support, diagnosis result reporting session.
Price range
Delivery Time
Applications/Examples of results
【Purpose】 - Preliminary inspection of websites that handle customer personal information and credit card information, such as e-commerce sites and reservation sites. - Security checks before the launch and regular security checks of corporate websites and web services. - Obtaining diagnostic evidence when requested for security audit reports by business partners or industry organizations.
Detailed information
-

Provision of a detailed vulnerability investigation report. We will create and submit a diagnostic report that clearly organizes the risk levels of detected vulnerabilities and specific issues.
-

[Vulnerabilities of the OS] We diagnose vulnerabilities and configuration deficiencies in older versions of server OS to proactively identify risks that could be exploited by attackers.
-

[Validity of Certificates] We check for improper SSL/TLS certificates and configuration errors to prevent misuse for phishing sites and eavesdropping on communications.
-

Easily guessable passwords for management screens and services are detected. This prevents unauthorized logins and intrusions.
-

[Vulnerabilities in Middleware] Investigate the improper version settings of web servers and middleware to block attackers' entry points.
-

[Presence of Sample Scripts] Detects and removes sample code and test scripts that are left publicly accessible by default, preventing misuse.
-

[Verification of Communication Encryption] Detection of the use of weak cipher suites. Prevents the risk of eavesdropping and tampering by third parties.
-

【Database Vulnerabilities】 We thoroughly diagnose risks such as SQL injection and the careless external exposure of DB management tools.
-

Third-Party Relay (SPAM) Check for risks of spam relay due to improper email server configuration, protecting the company's credibility.
Company information
Consistent contract development from "requirements definition" to "after follow-up" Aicell was established in 1989 as a system technology research institute focused on building business systems for companies. In 2000, it merged with Aitec, a company specializing in embedded software development, and began its journey as an IT company with two core businesses. We provide system solutions that drive innovation for companies across various industries and sectors. We excel particularly in building web-based business systems and are also skilled in proposing a series of solutions that include hardware, thanks to collaboration with our embedded business. In an era where IT systems are utilized in various scenes, we are focusing on development using smart devices and software development leveraging the latest technologies. Additionally, our development areas continue to expand, including ground-based software development that supports communication protocols, in-vehicle systems, and attitude and orbit control for satellites. With a commitment to "constantly creating new solutions," Aicell, backed by technological innovation, integration, high technical capabilities, and a flexible development system supported by broad and deep experience, creates new value as a trusted partner.





![[Issue] I want to improve the vulnerabilities of network applications.](https://image.mono.ipros.com/public/product/image/2067551/IPROS1684380536771232486.png?w=280&h=280)



