Sage Advice

A False Sense of Security

View all posts by Alex Crittenden

Alex Crittenden

August 23, 2012

My point in all of this is that automated vulnerability scanning is certainly useful and, with large environments or applications, absolutely necessary (we use some of these tools in our assessment process), but don’t be lulled into a false sense of security. If this is all that you are doing to identify and address potential vulnerabilities within your network or critical application environments then you have a problem.
READ POST

NetsPWN: Assessment Services

Manual vs. Automated Testing

View all posts by Seth Peter

Seth Peter

January 22, 2010

. . . no single application assessment or code review product could find more than about 35% of the total vulnerabilities GE could find with a manual process. That alone should encourage anyone serious about eradicating vulnerabilities within their applications to step it up a notch!
READ POST

NetsPWN: Assessment Services

Application Security-An Introductory Post

View all posts by Paul Johnson

Paul Johnson

July 15, 2009

NetSPI is embarking on an initiative to provide opinions and insight to security practitioners in the form of periodic blog entries covering four specific subject areas, one of which is Application Security. Entries in this blog category will be providedby members of NetSPI’s Application Security team and will [...]
READ POST