[SC-L] A new blog on application security - armoredcode.com

2012-03-20 Thread Paolo Perego
Hi list, just 2 lines for promoting my new blog on application security: http://armoredcode.com The idea is to talk about appsec using the developers language so talking about testing frameworks and practices, libraries to enforce security, how to read a penetration test report, some "hands on" wit

Re: [SC-L] A new blog on application security - armoredcode.com

2012-03-22 Thread Paolo Perego
On 21 March 2012 13:55, Jeffrey Walton wrote: > On Fri, Mar 16, 2012 at 12:50 PM, Paolo Perego > wrote: > > If you would like to add it on your feed, it would be great. > For the love of , please discuss the tool chain's static > analysis capabilities, and suggest a clea

Re: [SC-L] "Bumper sticker" definition of secure software

2006-07-18 Thread Paolo Perego
Hi list, I'll introduce myself with a claim: "Software is like Titanic, pleople claim it was unsinkable. Securing is providing it power steering"   thesp0nge  On 7/18/06, Gadi Evron <[EMAIL PROTECTED]> wrote: On Mon, 17 Jul 2006, Rajeev Gopalakrishna wrote:> Reliability is concerned only with acci

Re: [SC-L] Perspectives on Code Scanning

2007-06-08 Thread Paolo Perego
On 6/6/07, McGovern, James F (HTSC, IT) <[EMAIL PROTECTED]> wrote: > I really hope that this email doesn't generate a ton of offline emails and > hope that folks will talk publicly. It has been my latest thinking that the > value of tools in this space are not really targeted at developers but sh

Re: [SC-L] Perspectives on Code Scanning

2007-06-10 Thread Paolo Perego
ying tools to developers. > > Give away the developer tools in the same way Microsoft does and you will > accelerate your potential sales from the bottom up. Not all sales within > places are driven top down... > > -Original Message- > From: [EMAIL PROTECTED] > [mailto

[SC-L] Orizon v0.50 announce

2007-11-01 Thread Paolo Perego
Hi there, I'd like to announce as delivery for Owasp Spring of Code 2007 project, the 0.50 release of Orizon. Orizon is a source code review engine, built with the aim to give developers something usable to build code review tools. Orizon is independent from the language used to write the sources

[SC-L] Code review pool

2007-11-05 Thread Paolo Perego
Hi guys, trying to improve Owasp Orizon project in a better way, I released a poll over my blog here: http://thesp0nge.livejournal.com/5687.html It would be great having your feedback about your vision to code review and safe coding as developers and security specialist. Thanks for participating.

Re: [SC-L] Code review pool

2007-11-05 Thread Paolo Perego
publish results to another post to my blog. Again sorry :( thesp0nge On 05/11/2007, ljknews <[EMAIL PROTECTED]> wrote: > At 12:50 PM +0100 11/5/07, Paolo Perego wrote: > > > Hi guys, trying to improve Owasp Orizon project in a better way, I > > rele

[SC-L] Project announce: The OWASP Source Code Flaws Top 10

2008-12-16 Thread Paolo Perego
Hello leaders, I'm really happy to announce a new documentation project I started today. Our Top 10 most critical web app vulnerabilities is the standard de facto when trying to summarize findings when you assess a web application. And it is great. Looking at source code assessment (or code review