Archive for the 'Framework' Category

Starting A Computer Security Incident Response Team ?

Tuesday, August 21st, 2007

In case you neded a place to start in evaluating the steps required for building a Computer Security Incident Response Team (CSIRT) , look no further. CERT/CC has released the Action List for Developing a Computer Security Incident Response Team (CSIRT) .

Posted in Framework, Articles | No Comments »

The Standard of Good Practice for Information Security

Wednesday, August 8th, 2007

Today I came across the The Standard of Good Practice for Information Security which has been produced by the Information Security Forum (ISF), an international association of over 260 leading organisations which fund and co-operate in the development of a practical research programme in information security.
The ISF’s work probably represents the most comprehensive and […]

Posted in Framework, Guidelines | No Comments »

PIRANA, the SMTP fuzzing and bruteforce tool

Thursday, July 5th, 2007

PIRANA is a SMTP fuzzing and bruteforce exploitation framework that tests the security of a SMTP content filter. By means of a vulnerability database, the content filter to be tested will be bombarded by various emails containing a malicious payload intended to compromise the SMTP server

Posted in Framework, Brute Force, Tools | No Comments »

Common Vulnerability Scoring System CVSS 2.0 unifies vulnerability scoring

Friday, June 29th, 2007

The Common Vulnerability Scoring System (CVSS) provides an open framework for communicating the characteristics and impacts of IT vulnerabilities.

Posted in Vulnerabilities, Framework | No Comments »

w3af, the Web Application Attack and Audit Framework

Friday, June 15th, 2007

Andres Riancho has released w3af 1.0 - the Web Application Attack and Audit Framework.This framework is written in python and resembles a bit to metasploit having an architecture based on plugins

Posted in Framework, Web Applications, Tools | No Comments »

New European ICT Security Standards Roadmap

Friday, June 8th, 2007

One of the objectives of this security standards portal named “ICT Security Standards Roadmap” is to provide a central tracking facility for NIS standards. It facilitates identification of standards and standardization activities, as well as coordination among standardization bodies, reduction of duplicate work and easier identification of existing gaps.

Posted in Framework, Guidelines | No Comments »

NIST CSRC Special Publications June Update

Tuesday, June 5th, 2007

NIST publications : Guidelines on Cell Phone Forensics, Guide for Assessing the Security Controls in Federal Information Systems, Guidelines on Securing Public Web Servers, User’s Guide to Securing External Devices for Telework and Remote Acces, Specification for the Extensible Configuration Checklist Description Format (XCCDF)

Posted in Framework, Guidelines, Articles | 1 Comment »

Software Security Assurance: A Framework for Software Vulnerability Management and Audit

Friday, June 1st, 2007

Ounce Labs released a valuable resource for everybody involved in the Software Security business. “Software Security Assurance: A Framework for Software Vulnerability Management and Audit” is more than a framework, it’s a call to action driven by the need for better understanding of roles and responsibilities in software security assurance.

Posted in Reviews, Code Audit, Framework | No Comments »

Metasploit Framework version 3.0 RELEASED

Tuesday, March 27th, 2007

Metasploit is pleased to announce the immediate, free availability of the Metasploit Framework version 3.

Posted in Penetration Testing, Framework | No Comments »

Web App Audit in 3 easy steps - powered by SANS

Thursday, March 22nd, 2007

SANS released a paper on Web Applications Audit. It’s more of a guide to low hanging fruit website assessment, but still is a good resource . The article begins with setting up , adjusting and configuring the tool arsenal and then walks the reader trough implementation and conclusions.

Posted in Penetration Testing, Framework, Web Applications | No Comments »