Security testing
Web Security Testing Cookbook
Submitted by Karen N. Johnson on Fri, 24/10/2008 - 03:48. security testing | security testing toolsHere’s a look at the table of contents -
Claims testing in New York taxis
Submitted by Erik Petersen on Sat, 29/12/2007 - 12:52. perspectives | security testing | usability testingI hope no one tries to test some recent claims by a vendor of technology for New York City taxis. They now have GPS installed, as well as some other extras. It seems someone went for a taxi ride recently, found a PC screen mounted on the seat back, clicked past an error message, and did some mischief. They then blogged about it, then it was picked up in the media (via a comment on the blog post). Of course the technology company had to respond, both with a blog comment and to the media. The claims of the technology company include such gems as “ There are extensive contract-required security protocols in place, which have exceeded government and credit card industry standards and have been stringently tested by our internal and external security experts, which fully prevent access to anything other than media content files residing in the taxicab itself. There is no potential for any malicious activity,”.
Windows command line tools
Submitted by Mike Kelly on Tue, 19/09/2006 - 14:16. security testingFrom Lesson 2 - Basic commands in Linux and Windows I learned three cool new Windows tools I didn't know about.
tracert host
Show the route that packets follow to reach the machine "host". The command tracert is the abbreviation of trace route, which allows you to learn the route that a packet follows from the origin, (your machine) to the destination machine. It can also tell you the time it takes to make each jump. At the most, 30 jumps will be listed. It is sometimes interesting to observe the names of the machines through which the packets travel.
route print
Display the routing table. The command route serves to define static routes, to erase routes or simply to see the state of the routes.
netstat
Displays information on the status of the network and established connections with remote machines.
Fun with Google
Submitted by Mike Kelly on Fri, 15/09/2006 - 12:57. security testingI'm doing some self education with security testing again. It's been a while. I'm back to Hacker High School working the lessons.
Today, it's fun with Google. I can't hack any real sites, so I thought I would try to find stuff on some of my sites. I found a lot of good detail by reading Google Hacking Mini-Guide by Johnny Long.
"Regretfully, we don't know how to protect data even though we spend millions on it every year..."
Submitted by Mike Kelly on Fri, 19/05/2006 - 19:03. security testingWe value the trust people place in |Company|. Regretfully, we have learned that a computer, which contained information about you including your name, address, Social Security Number from your |Company| inquiry or application on |Date|, is missing and may have been stolen. The computer had two layers of security, and we have no indication that the information has been accessed or misused.
Security Testing
Submitted by Mike Kelly on Wed, 18/01/2006 - 19:09. security testingFirst, a must read article Anatomy Of A Break-In by Ira Winkler. What an incredible experience report.
Second, I've been reading Security in Computing, 3rd Edition by Pfleeger and Pfleeger. I'm reading this text for a class. In general, I hate textbooks. I think they tend to say in 700 pages what a good author can say in 200 pages. I'm pleased to say that (for the most part) I find this one well written, challenging, and informative.
Security Testing
Submitted by Mike Kelly on Mon, 02/01/2006 - 17:17. security testing- Andrew Andrada
- Charlie Audritsh
- Mike Goempel
- Michael Kelly
- Marc Labranche
- Kenn Petty
- Vishal Pujary
- Tate Stuntz
June 2005 Professional Tester : A review
Submitted by neill mccarthy on Thu, 30/06/2005 - 08:29. security testingJune 2005's professional tester is now out and came through my door this morning, interesting trick i thought, till I remembered the invention of the letter box.
There are a couple of articles of interest, not all on this issues slant on security testing either.
Three articles really stand out for me this time round:
"Julian Harty":http://www.commercetest.com/: A Primer in software security testing.
