Beefy Boxes and Bandwidth Generously Provided by pair Networks
P is for Practical

comment on

( #3333=superdoc: print w/replies, xml ) Need Help??

I have just come across a great implementation of Open Source and security. has taken security practices in general and security in relation to programming and brought these practices out in the open to peer review. These practices have been combined into workable standards for administrators and programmers.

The project is run by a former IBM Network Security Auditor (White Hat Hacker), who was running into roadblocks when discussing security strategies with other companies. This project seems to have sprouted from the idea that security, as a whole, will only be achieved if everyone combines their resources. This philosophy unfortunately is not accepted as a sound idea by most PHB's, so it was moved a more beneficial environment Open Source

The Secure Programming Standards Methodology Manual is a pre-release version (V.90) of a complete secure programming standard (only available HTML right now). It is language independent and very close completion. It covers many areas including: Logging, Stack Smashing, Remote Compromise, Output, … but it still needs more input. I would highly recommend this as a read if you have ever thought about contributing to an Open Source project or have ever been concerned about the security of your programs. has also released it’s The Open Source Security Testing Methodology Manual V2 preview release 6 for review (PDF or HTML). It is a fully comprehensive security plan for any company (e.g. small, large or in-between), which can be implemented by 1 or 100 people.

Quoted from the Introduction:
“Introduction This manual is a definitive standard for unpriviledged security testing in any environment from the outside to the inside. This focus requires that the tester has no special access point or permission different from that which is shared with the general public. The concept of this manual has and always will be to create one accepted method for performing a thorough security test. Regardless of the credentials of the security tester, the size of the security firm, financing, or vendor backing, any network or security expert who meets the outline requirements in this manual is said to have completed a successful security scattershot. This does not mean one cannot perform a test faster, more in depth, or of a different flavor. The tester following the methodology within this manual is said to have followed the standard model and therefore if nothing else, has been thorough. In doing so, the tester still must report the results of all modules and tasks fulfilled to include OSSTMM certification in a report.”

grep> grep clue /home/users/*

In reply to Security Standards by grep

Use:  <p> text here (a paragraph) </p>
and:  <code> code here </code>
to format your post; it's "PerlMonks-approved HTML":

  • Are you posting in the right place? Check out Where do I post X? to know for sure.
  • Posts may use any of the Perl Monks Approved HTML tags. Currently these include the following:
    <code> <a> <b> <big> <blockquote> <br /> <dd> <dl> <dt> <em> <font> <h1> <h2> <h3> <h4> <h5> <h6> <hr /> <i> <li> <nbsp> <ol> <p> <small> <strike> <strong> <sub> <sup> <table> <td> <th> <tr> <tt> <u> <ul>
  • Snippets of code should be wrapped in <code> tags not <pre> tags. In fact, <pre> tags should generally be avoided. If they must be used, extreme care should be taken to ensure that their contents do not have long lines (<70 chars), in order to prevent horizontal scrolling (and possible janitor intervention).
  • Want more info? How to link or or How to display code and escape characters are good places to start.
Log In?

What's my password?
Create A New User
Domain Nodelet?
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others imbibing at the Monastery: (1)
As of 2021-09-26 01:11 GMT
Find Nodes?
    Voting Booth?

    No recent polls found