Re: [SC-L] What do you like better Web penetration testing or static code analysis?

2010-04-25 Thread Arian J. Evans
To: Peter Neumann; Secure Code Mailing List Subject: Re: [SC-L] What do you like better Web penetration testing or static code analysis? I hereby resonate with my esteemed colleague and mentor pgn.  But no puns from me. gem On 4/22/10 1:57 PM, Peter Neumann neum...@csl.sri.com wrote

Re: [SC-L] What do you like better Web penetration testing or static code analysis?

2010-04-24 Thread Brian Chess
...@securecoding.org [mailto:sc-l-boun...@securecoding.org] On Behalf Of Gary McGraw Sent: Thursday, April 22, 2010 2:15 PM To: Peter Neumann; Secure Code Mailing List Subject: Re: [SC-L] What do you like better Web penetration testing or static code analysis? I hereby resonate with my esteemed

Re: [SC-L] What do you like better Web penetration testing or static code analysis?

2010-04-24 Thread Kevin W. Wall
Brian Chess wrote: I like your point Matt. Everybody who's responded thus-far has wanted to turn this into a discussion about what's most effective or what has the most benefit, sort of like we were comparing which icky medicine to take or which overcooked vegetable to eat. Maybe they don't

Re: [SC-L] What do you like better Web penetration testing or static code analysis?

2010-04-23 Thread Matt Parsons
Neumann; Secure Code Mailing List Subject: Re: [SC-L] What do you like better Web penetration testing or static code analysis? I hereby resonate with my esteemed colleague and mentor pgn. But no puns from me. gem On 4/22/10 1:57 PM, Peter Neumann neum...@csl.sri.com wrote: Matt Parsons

Re: [SC-L] What do you like better Web penetration testing or static code analysis?

2010-04-23 Thread Chris Wysopal
Neumann; Secure Code Mailing List Subject: Re: [SC-L] What do you like better Web penetration testing or static code analysis? I hereby resonate with my esteemed colleague and mentor pgn. But no puns from me. gem On 4/22/10 1:57 PM, Peter Neumann neum...@csl.sri.com wrote: Matt Parsons

Re: [SC-L] What do you like better Web penetration testing or static code analysis?

2010-04-19 Thread Kevin W. Wall
Matt Parsons wrote: What do you like doing better as application security professionals, web penetration testing or static code analysis? McGovern, James F. (P+C Technology) wrote: Should a security professional have a preference when both have different value propositions? While there is

Re: [SC-L] What do you like better Web penetration testing or static code analysis?

2010-04-15 Thread Matt Parsons
What do you like doing better as application security professionals, web penetration testing or static code analysis? I offered my thoughts in today's blog. http://parsonsisconsulting.blogspot.com/2010/04/what-do-you-like-better-secu re-code.html Matt Parsons, MSM, CISSP