Re: [SC-L] Seeking vulnerable server-side scripts

2009-05-06 Thread security curmudgeon
: There are several applications designed specifically for this: : : Mutillidae : http://www.irongeek.com/i.php?page=security/mutillidae-deliberately-vulnerable-php-owasp-top-10 : : Foundstone's Hacme Bank and Hacme Travel : http://www.foundstone.com/us/resources-free-tools.asp : : WebGoat :

Re: [SC-L] Seeking vulnerable server-side scripts

2009-05-06 Thread security curmudgeon
Hi Jeremy, : I'm experimenting (on paper initially) with a technique for improving : resiliency of web applications, and to do so am looking for examples : of server side scripts (PHP, Perl, whatever) that have security : vulnerabilities, to see if the technique would work. If you have : If

Re: [SC-L] COBOL Exploits

2007-11-02 Thread security curmudgeon
Hi Mark, : The adolescent minds that engage in exploits wouldn't know COBOL if a : printout fell out a window and onto their heads. I'm sure you can write : COBOL programs that crash, but it must be hard to make them take control : of the operating system. COBOL programs are heavy into unit

Re: [SC-L] Economics of Software Vulnerabilities

2007-03-23 Thread security curmudgeon
On Wed, 21 Mar 2007, Steven M. Christey wrote: : With rare exceptions, in general, I do not find that the : open source community is that much more security consciousness : than those producing closed source. Certainly this seems true : if measured in terms of vulnerabilities and we measure