Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: On product vulnerability history and vulnerability complexity

Re: On product vulnerability history and vulnerability complexity

From: Gadi Evron <ge_at_linuxbox.org>
Date: Tue, 04 Apr 2006 02:34:00 +0200

Forrest J. Cavalier III wrote:
> Just a half-baked idea. Does selling software quality assurance make
> sense?

If you will allow me to answer only that part of your email, I honestly
don't know - but:

Standardization and regulation is where we are all heading in many
different directions whether we like it or not. Today people believe
such testing can not reliably be done. I disagree.

Point is, that whether I am right or wrong we may see a demand by
companies to do just that so that they can meet said standardization or
regulation.

So, I am not sure if selling it makes sense, but where there is a demand
there is a market and I believe today people look for the HOW. Code
analysis and auditing are important steps, as well as secure coding and
QA security. That said that process has proven itself to, in the macro
level, be a complete failure.

I tend to agree with Dave Aitel that Fuzzers may be part of the solution
to that. I would add that they are, once they reach a level of maturity
and efficiency that merits such treatment.
Such certification is coming and such technology exists / can be found
in a few places.
That said (full disclosure), on these last two sentences you should take
what I say with a grain of salt as I currently work for a fuzzing vendor.

        Gadi.
Received on Apr 04 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]