LWN.net Logo

Security site

From:  "Jay R. Ashworth" <jra@baylink.com>
To:  lwn@lwn.net
Subject:  Security site
Date:  Mon, 2 Jun 2003 20:33:34 -0400
Cc:  risks@csl.sri.com


I'm fixin' (damn, but it's nice to live in the South :-) to flang up a
bunch of websites for friends and clients using WebGUI, and it occured
to me that if there was an automated tester for website security,
that'd be a good thing to play with.

In my search therefore, I came across a pretty spiffy site that
apparently *used* to be called Ideahamster (and indeed, that's the
domain name still) which includes the "Open Source Security Testing
Methodology" manual.

http://www.ideahamster.org/

Hain't read it yet, but it's got a groovy name, no?

If anyone has pointers to any *other* frameworks for this sort of
thing; I'd appreciate hearing about them.

Cheers,
-- jra
-- 
Jay R. Ashworth                                                jra@baylink.com
Member of the Technical Staff     Baylink                             RFC 2100
The Suncoast Freenet         The Things I Think
Tampa Bay, Florida        http://baylink.pitas.com             +1 727 647 1274

   "If you don't have a dream; how're you gonna have a dream come true?"
     -- Captain Sensible, The Damned (from South Pacific's "Happy Talk")


(Log in to post comments)

Web app security tools

Posted Jun 6, 2003 8:49 UTC (Fri) by tekNico (guest, #22) [Link]

> If anyone has pointers to any *other* frameworks for this sort of
> thing; I'd appreciate hearing about them.

Jay,
you may find documentation about this topic at OWASP:

http://www.owasp.org/


A couple of lists of tools:

http://www.webhackingexposed.com/tools.html

http://www.sikurezza.org/devel/msg00109.html


A good mailing list concerning this topic is WebAppSec at SecurityFocus:

http://www.securityfocus.com/archive/107

Copyright © 2003, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds