Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



WebApp Sec: Re: Content monitorting in Application Security

Re: Content monitorting in Application Security

From: Martin Schapendonk <martin.schapendonk_at_gmail.com>
Date: Mon, 24 Jan 2005 08:28:45 +0100

I like the suggestion to check for (multiple) occurrences of
SQL-statements etc.. If you think of it, it's just like UCE/UBE
filtering.

Maybe it's possible to use software like SpamAssassin and/or
BogoFilter to determine if a file is "definitely insecure",
"definitely secure" or "not sure". Of course, they would require a
whole different ruleset and perhaps some extra training depending on
the site, but I do think this may have some perspective.

Also, performance wise this may be a good idea: SA and BF are designed
for realtime email processing, so I don't see why they shouldn't be
able to process a sufficient number of files, even on modest hardware.

Regards,

Martin

-- 
  Martin Schapendonk, martin.schapendonk_at_gmail.com
Received on Jan 24 2005
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]