Re: Security Search Engine



Hi Erick,

Thanks for the feedback. The idea for this search index is to be
somewhat neutral. For e.g. all the vendors say on their website that
their IDS is the best IDS in the universe. Now if I exclude all the
vendors from the index, then when somebody search for IDS, they would
get results of non-vendor specific sites, which will rather
(hopefully) discuss the pros/cons of a certain IDS product. I hope I
am making sense.

I idea here is NOT to build a new search engine, but to provide a list
of unbiased site to someone who is researching about a certain
technology.

As far Cisco is concerned I am planning not to include that site,
instead include site that talk the security of the network gear in
general.

Also remember this is just an experiment in creating a medium purely
for unbiased research.

On 10/24/06, Erick Jensen <ejensen@xxxxxxxxxxx> wrote:
It sounds like a fantastic idea. I would use it daily! My only
observation is this, I can't find any Cisco info NOT on the Cisco site.
So if you exclude vendor sites, where would that fall?

Also, Google is starting to block sites based on "someone's" opinion of
malicious software or malware. Oxid's Cain/Able comes to mind....
Google it and see!

So how would that come into play if you use Google's engine?

-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of Saqib Ali
Sent: Tuesday, October 24, 2006 11:47 AM
To: security-basics
Subject: Security Search Engine

Hello All,

I am building a Search Engine exclusively for the Security and
eSecurity Community using Google's Coop program.

I would like to NOT include any vendor site but just index sites that
are vendor neutral. Would this is be a good strategy or not?

The URL for the search engine is
http://www.xml-dev.com

Any suggestion, or new URLs are welcome.
Note: I won't include any security vendor website in the index for right
now.

--
Saqib Ali, CISSP, ISSAP
http://www.full-disk-encryption.net

------------------------------------------------------------------------
---
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic
Excellence
in Information Security. Our program offers unparalleled Infosec
management
education and the case study affords you unmatched consulting
experience.
Using interactive e-Learning technology, you can earn this esteemed
degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
------------------------------------------------------------------------
---




--
Saqib Ali, CISSP, ISSAP
http://www.full-disk-encryption.net

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • RE: Security Search Engine
    ... When you say 'exclude vendor specific' I can see this includes open ... Subject: Security Search Engine ... We use an open-source search engine on SecurityFocus. ... like SEC-BASICS or BUGTRAQ or all 34 mailing lists. ...
    (Security-Basics)
  • Re: Security Search Engine
    ... But vendors often have a lot of information on their products that may be difficult to find elsewhere, so I think you'd be doing your search engine a disservice to not include those sites. ... Other vendor sites also offer whitepages, FAQs, HOWTO's, etc. for download, and it would be good to include those in your search index, for sure. ... I won't include any security vendor website in the index for right now. ... The NSA has designated Norwich University a center of Academic Excellence in Information Security. ...
    (Security-Basics)
  • [NEWS] Wonderware SuiteLink Denial of Service Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... Vendor Information, Solutions and Workarounds ... Core sends the advisory draft to Wonderware support team. ...
    (Securiteam)
  • [Full-Disclosure] Security Industry Under Scrutiny: Part 3
    ... > varying degrees of 'faith' in the security industry. ... site admins and other whitehats. ... > architect would be notifying the software vendor alone... ... Full disclosure isn't so much a tool to get vunerability information ...
    (Full-Disclosure)
  • [NT] Internet Explorer Zone Elevation Restrictions Bypass and Security Zone Restrictions Bypass (MS0
    ... Get your security news from a reliable source. ... Internet Explorer Zone Elevation Restrictions Bypass and Security Zone ... Vendor Information, Solutions and Workarounds: ... Core sends an advisory ...
    (Securiteam)