Re: [SC-L] COBOL Exploits

2007-11-18 Thread Andrew van der Stock
I've been researching web app - mainframe security from a software engineering perspective for about the last six months. If anyone from a mainframe background wants to collaborate, I'd be more than happy to share as I have a few challenges: a) I'm working from secondary resources (web

Re: [SC-L] Mainframe Security

2007-11-18 Thread Andrew van der Stock
In my experience of reviewing COBOL and mainframes in general, it's worthwhile to evaluate doing bad things to the business logic. The designers are literal in their translation of the business requirements to specifications, and never think of the mis-use cases. Mainframe coders aren't

Re: [SC-L] OWASP Publicity

2007-11-18 Thread Benjamin Tomhave
I agree and disagree with these comments, as I think they possibly represent an outmoded way of thinking when it comes to IT management. Execs and senior mgmt _must_ have a certain understanding of security that will at least give them a basis for making risk decisions. It seems today that they