Speedy and low-cost! Quickly detect vulnerabilities in servers and web applications.
The vulnerability assessment service "Site-Audit" is a diagnostic service that quickly and cost-effectively identifies security flaws (vulnerabilities) in servers and applications. 【This service addresses the following challenges】 - I cannot spend a lot on security measures, but I want to understand the current risks. - I want to immediately take measures against website tampering and personal information leaks. - I want to conduct assessments in compliance with security standards and guidelines. 【Main Features】 1. Platform Assessment: Comprehensive assessment of server and OS vulnerabilities in accordance with CVSS/CVE, covering over 140,000 patterns. 2. Application Assessment: Detection of risks such as SQL injection and cross-site scripting (XSS) through simulated attacks based on OWASP/CWE. 3. Clear Report Submission: A report summarizing the assessment results and issues will be provided. This service is ideal as the first step in security measures, allowing for continuous and easy understanding of the current situation.
Inquire About This Product
basic information
【Diagnostic Menu】 ■ Platform Diagnosis - Vulnerabilities in OS/middleware, validity of certificates, presence of guessable passwords, possibility of eavesdropping on communications (encryption suite evaluation), careless exposure of databases and samples, etc. ■ Application Diagnosis - SQL injection, cross-site scripting (XSS), CSRF, path traversal/directory traversal, code/XSLT injection, buffer overflow, etc. 【Provision Conditions】 - Target: Websites, public servers, etc. (Diagnosis on shared servers is generally not permitted) - The package fee includes an initial diagnosis and a "re-diagnosis" after countermeasures, totaling two times. - Options: Vulnerability response support, diagnostic result reporting meeting.
Price range
Delivery Time
Applications/Examples of results
【Purpose】 - Preliminary inspection of websites that handle customer personal information and credit card information, such as e-commerce sites and reservation sites. - Security checks before the launch and regular security checks of corporate websites and web services. - Obtaining diagnostic evidence when requested for security audit reports by business partners or industry organizations.
Detailed information
-

Provision of Vulnerability Assessment Report We will create and submit a diagnostic report that clearly organizes the risk levels of detected vulnerabilities and specific issues.
-

[Vulnerabilities of the OS] We diagnose vulnerabilities and configuration deficiencies in older versions of server OS to proactively identify risks that could be exploited by attackers.
-

**Validity of Certificates** We check for improper SSL/TLS certificates and configuration errors to prevent misuse for phishing sites and eavesdropping on communications.
-

Easily guessable passwords for management screens and services are detected. This prevents unauthorized logins and intrusions.
-

[Vulnerabilities in Middleware] Investigate the improper version settings of web servers and middleware to block attackers' entry points.
-

[Presence of Sample Scripts] Detects and removes sample code and test scripts that are publicly available by default to prevent misuse.
-

[Verification of Communication Encryption] Detection of the use of weak cipher suites. Prevents the risk of eavesdropping and tampering by third parties.
-

【Database Vulnerabilities】 We thoroughly diagnose risks such as SQL injection and the careless external exposure of DB management tools.
-

【Third-Party Relay (SPAM)】 We check for the risk of spam relay due to improper email server settings and protect the company's credibility.
Company information
Consistent contract development from "requirements definition" to "after follow-up" Aicel was established in 1989 as a system technology research institute to build business systems for companies. In 2000, it merged with Aitec, which focuses on embedded software development, and started as an IT company with two main business pillars. We provide system solutions that drive innovation for companies across various industries and business types. We excel particularly in building web-based business systems and, through collaboration with our embedded business, we are also skilled in offering a series of proposals that include web applications and hardware. In an era where IT systems are utilized in various scenes, we are focusing on development utilizing smart devices and software development using the latest technologies. Additionally, our development areas continue to expand, including ground-based software development that supports communication protocols, in-vehicle systems, and attitude and orbit control for satellites. With a commitment to "constantly creating new solutions," Aicel, backed by technological innovation and integration, high technical skills, and a flexible development system supported by broad and deep experience, creates new value as a trusted partner.







