RE: Application Assessment

From: Ory Segal (osegal_at_watchfire.com)
Date: 08/11/05

  • Next message: Pete Herzog: "Re: Nmap/netwag problem."
    Date: Thu, 11 Aug 2005 13:16:29 +0300
    To: "goenw" <goenw.mailinglist@gmail.com>
    
    

     Hi,

    You should also check: http://www.webappsec.org (Web Application
    Security Consortium)

    With regards to utilities, you can download the free Watchfire
    Powertools (HTTP Proxy, HTTP request editor, etc.), here's the link:
    http://www.watchfire.com/securityzone/download/default.aspx

    At the same link, you can also download eval versions of Watchfire's
    AppScan product (An automated application security scanner).

    You can also find basic and advanced whitepapers on the subject at:
    http://www.watchfire.com/news/whitepapers.aspx

    -Ory

    -----Original Message-----
    From: Glyn Geoghegan [mailto:glyng@corsaire.com]
    Sent: Thursday, August 11, 2005 4:48 AM
    To: goenw
    Cc: pen-test@securityfocus.com; Webappsec
    Subject: Re: Application Assessment

    On 8 Aug 2005, at 12:53, goenw wrote:

    > Hi,
    >
    > anybody have experience with application assessment ? I am a network
    > guy, dont know much about the apps PT.
    > 1. is there any tools that allow me to do the assessment throughly ?

    If you're talking web-applications, check out www.owasp.org for a wealth
    of information on the subject. You may also want to take a look at the
    webappsec mailing list at www.securityfocus.com.

    Typically, the kind of tools you'll need are the personal-proxy
    category, allowing you to intercept and modify communications between
    the client and server - see Paros Proxy, Odysseus and Burp Proxy, for
    example.

    There are fully automated tools, but in my personal experience the
    manual approach has worked more effectively.

    Fat client/binary assessment is a slightly different (and arguably more
    complex) beast, and probably off-topic for this list.

    > 2. should i have external party conduct this, what are the things i
    > should expect from them (success criteria) ?
    > any comments are appriciated.

    That depends on how confident you are with your abilities, the drivers
    for the assessment and a wealth of factors. Normally, some coding or
    development background is essential to identify and understand potential
    vulnerabilities.

    Check out www.application-testing.com for our guide on the world of
    Application Security Assessments.

    --
    -------------------------------------------------------
    G l y n   G e o g h e g a n                   BSc, ARCS
    Principal Consultant                       Corsaire Ltd
    3 Tannery House, Tannery Lane
    Send, Surrey, GU23 7EF, UK      UK: +44 (0)1483 226 000
    http://www.corsaire.com        Fax: +44 (0)1483 226 001
    -------------------------------------------------------
    ------------------------------------------------------------------------------
    FREE WHITE PAPER - Wireless LAN Security: What Hackers Know That You Don't
    Learn the hacker's secrets that compromise wireless LANs. Secure your
    WLAN by understanding these threats, available hacking tools and proven
    countermeasures. Defend your WLAN against man-in-the-Middle attacks and
    session hijacking, denial-of-service, rogue access points, identity
    thefts and MAC spoofing. Request your complimentary white paper at:
    http://www.securityfocus.com/sponsor/AirDefense_pen-test_050801
    -------------------------------------------------------------------------------
    

  • Next message: Pete Herzog: "Re: Nmap/netwag problem."

    Relevant Pages

    • RE: Converged Network Assessment - VoIP Security
      ... second annual VoIP Security Conference at Illinois Institute of Technology ... Subject: Converged Network Assessment ... convergence is going to have a lot to do with integrating VoIP ...
      (Pen-Test)
    • Some over-classified al Qaeda files left on a train in England.
      ... The two reports were assessments made by the government's Joint ... According to the BBC's security correspondent, Frank Gardner, ... intelligence assessment on al-Qaeda is so sensitive that every ... Police are investigating a "serious" security breach after a civil ...
      (sci.military.naval)
    • Re: Pentesting tool - Commercial
      ... For the assessment work I've done in the past two years on ... Comparing GFI LANguard Network Security Scanner 8 to Qualys ... How does the client acquire new software? ... vulnerability research businesses, and "security" consulting companies ...
      (Pen-Test)
    • RE: ISSAF 0.2 release
      ... Systems Security Assessment Framework. ... more established OSSTMM? ... assessment of patch management, vulnerability management and version ...
      (Pen-Test)
    • RE: Converged Network Assessment
      ... I think one of the additional implications here is the realization that VoIP ... Several simple observations on the convergence impact: ... Subject: Converged Network Assessment ... security industries is "standardization". ...
      (Pen-Test)