发新话题
打印

[转载]Interpreting the Results of a Vulnerability Assessment

[转载]Interpreting the Results of a Vulnerability Assessment

原始出处:http://www.infosecwriters.com/te ... essment_KBeaver.pdf
文章作者:Kevin Beaver, CISSP, and Caleb Sima

Web application security testing tools are extremely savvy and are able to root out vulnerabilities in minutes that would take the best hacker in the world hours, months, or more to find. The issue is that you’ve got to take the tool results and determine what actually matters in your environment. We’ve seen inexperienced Web application security consultants, managed security service providers, and auditors run vulnerability assessment scans and then hand the results over to their clients purporting they have a bunch of problems that need to be fixed. Likewise, we’ve seen network administrators absolutely freak out when they see that their Web application security testing tool has found a dozen or more vulnerabilities. They believe the sky is falling and immediately run to management asking for more budget to buy more technology to fix the problems.

附件

Vuln_Assessment_KBeaver.rar (82 KB)

2007-3-23 19:13, 下载次数: 52

曾几何时,有人对我说:装B遭雷劈。我说:去你妈的。于是,这个人又对我说:如果再说脏话,上帝会惩罚你的。我说:我操上帝。结论:彪悍的人生不需要上帝。

TOP

发新话题