<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The FYRM Blog &#187; Application Security</title>
	<atom:link href="http://blog.fyrmassociates.com/category/application-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fyrmassociates.com</link>
	<description></description>
	<lastBuildDate>Tue, 10 Aug 2010 14:50:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.fyrmassociates.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/29bd7a6974e2b2222578faa640e336b0?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>The FYRM Blog &#187; Application Security</title>
		<link>http://blog.fyrmassociates.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.fyrmassociates.com/osd.xml" title="The FYRM Blog" />
	<atom:link rel='hub' href='http://blog.fyrmassociates.com/?pushpress=hub'/>
		<item>
		<title>We&#8217;re Doing It Wrong</title>
		<link>http://blog.fyrmassociates.com/2010/05/12/were-doing-it-wrong/</link>
		<comments>http://blog.fyrmassociates.com/2010/05/12/were-doing-it-wrong/#comments</comments>
		<pubDate>Wed, 12 May 2010 15:44:29 +0000</pubDate>
		<dc:creator>Matthew Flick</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Security Awareness]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=188</guid>
		<description><![CDATA[As an industry, we have failed. Miserably. Web application security professionals&#8211;yes, including myself&#8211;have implemented a broken methodology and graduated from failing to properly identify the problem to failing to present an effective solution. The net sec methodology of: 1. Scan for Vulnerabilities, and then 2. Apply Security Patch, simply does not work for the custom [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=188&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As an industry, we have failed. Miserably. Web application security professionals&#8211;yes, including myself&#8211;have implemented a broken methodology and graduated from failing to properly identify the problem to failing to present an effective solution. The net sec methodology of: 1. Scan for Vulnerabilities, and then 2. Apply Security Patch, simply does not work for the custom web application environment. This statement may seem obvious, but it&#8217;s exactly what the industry has tried to do.</p>
<p>Our first failure was in identifying the problem. Early warning professionals considered web application vulnerabilities similar to those of other applications, and that they could be identified with vulnerability scanning tools and then remediated with a patch (albeit a custom patch). They were at least partially correct in theory; the problem was in the practice. This failure led to the development of web application vulnerability scanning products as the basis of the web application security industry.</p>
<p>We finally realized that the root cause of the problem was related to application development. More specifically, the security of an application is in the hands of its developers. And what was our solution to this problem? Inject security people into the development process. We trained developers how to break their applications. We tested pre-alpha code that will be significantly changed another dozen times. And some people did threat modeling, which I still have not found to produce useful results.</p>
<p>Security comes down to control. For application security, this means who is in control of the functionality and data available within the application. This is why it is necessary that current and future application developers and computer security professionals learn the foundation of how to build secure applications from the start. To promote this effort, we are offering a discounted AppTrust Developer Training course at Virginia Tech this summer to ensure that the next generation doesn’t fall into the trap of doing it wrong and starts off doing it right.</p>
<p>To learn more <a title="AppTrust @ Virginia Tech" href="http://guest.cvent.com/EVENTS/Info/Invitation.aspx?e=e4d6f3d8-54de-4420-8718-2c0436b7bbdb" target="_blank">visit the event site</a>. <!--EndFragment--></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/188/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/188/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/188/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/188/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/188/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/188/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/188/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/188/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=188&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2010/05/12/were-doing-it-wrong/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Matthew Flick</media:title>
		</media:content>
	</item>
		<item>
		<title>XAB Presentation @ USF Whitehatters Club</title>
		<link>http://blog.fyrmassociates.com/2010/01/27/xab-presentation-usf-whitehatters-club/</link>
		<comments>http://blog.fyrmassociates.com/2010/01/27/xab-presentation-usf-whitehatters-club/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 20:25:43 +0000</pubDate>
		<dc:creator>Tony Flick</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=160</guid>
		<description><![CDATA[Matt and I will be giving a presentation on XAB (Cross Site Scripting Anonymous Browser) at the University of South Florida&#8217;s Whitehatters Computer Security Club&#8217;s next meeting on January 29th at 5:00PM. If you are a student at USF interested in learning about computer security, I highly encourage you to get involved with the club. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=160&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Matt and I will be giving a presentation on XAB (Cross Site Scripting Anonymous Browser) at the University of South Florida&#8217;s Whitehatters Computer Security Club&#8217;s next meeting on January 29th at 5:00PM. If you are a student at USF interested in learning about computer security, I highly encourage you to get involved with the club. See you there!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/160/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/160/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=160&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2010/01/27/xab-presentation-usf-whitehatters-club/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">tonyflick</media:title>
		</media:content>
	</item>
		<item>
		<title>Introducing AppTrust</title>
		<link>http://blog.fyrmassociates.com/2009/11/12/introducing-apptrust/</link>
		<comments>http://blog.fyrmassociates.com/2009/11/12/introducing-apptrust/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 14:09:10 +0000</pubDate>
		<dc:creator>Matthew Flick</dc:creator>
				<category><![CDATA[Application Security]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=141</guid>
		<description><![CDATA[FYRM Associates is proud to announce our new AppTrust offering that enables organizations to produce secure applications in a timely and cost-cutting manner. The typical, flawed approach to application security is based on the network security model of “when we find a vulnerability, we patch it.&#8221; This forces your organization into a never-ending game of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=141&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>FYRM Associates is proud to announce our new AppTrust offering that enables organizations to produce secure applications in a timely and cost-cutting manner. The typical, flawed approach to application security is based on the network security model of “when we find a vulnerability, we patch it.&#8221; This forces your organization into a never-ending game of catch-up with attackers that is nothing more than a costly and time-consuming strategic failure.</p>
<p>The AppTrust Assessment, Training, and Certification solutions break this mold with a strategy that enables your organization to implement applications that are secure as soon as they enter production.</p>
<p>You can read more about FYRM Associates&#8217; new AppTrust offering at our Web site, <a title="http://apptrust.fyrmassociates.com" href="http://apptrust.fyrmassociates.com" target="_self">http://apptrust.fyrmassociates.com</a>, or contact FYRM Associates at <a href="http://scr.im/fyrmsales">http://scr.im/fyrmsales</a> or (877) 752-7170 for more information.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/141/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/141/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/141/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=141&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2009/11/12/introducing-apptrust/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Matthew Flick</media:title>
		</media:content>
	</item>
		<item>
		<title>XAB &#8211; Cross Site Scripting Anonymous Browser updated and seeking help</title>
		<link>http://blog.fyrmassociates.com/2009/11/10/xab-cross-site-scripting-anonymous-browser-updated-and-seeking-help/</link>
		<comments>http://blog.fyrmassociates.com/2009/11/10/xab-cross-site-scripting-anonymous-browser-updated-and-seeking-help/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 08:16:21 +0000</pubDate>
		<dc:creator>Matthew Flick</dc:creator>
				<category><![CDATA[Application Security]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=136</guid>
		<description><![CDATA[A new release of XAB, the framework that allows one to browse the web via XSS has been updated. This release will now accommodate all content-types, thus allowing any file format to be transferred through the framework. The latest release can be found at sourceforge: xab.sourceforge.net. We&#8217;re seeking volunteers to help out with development. We&#8217;d [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=136&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A new release of XAB, the framework that allows one to browse the web via XSS has been updated.  This release will now  accommodate all content-types, thus allowing any file format to be transferred through the framework.  The latest release can be found at sourceforge: <a href="http://xab.sourceforge.net/">xab.sourceforge.net</a>.</p>
<p>We&#8217;re seeking volunteers to help out with development.  We&#8217;d like to take this from a small research project to a community driven effort to expand the possibilities of what can be done with XSS.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/136/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=136&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2009/11/10/xab-cross-site-scripting-anonymous-browser-updated-and-seeking-help/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Matthew Flick</media:title>
		</media:content>
	</item>
		<item>
		<title>XAB Presentation @ OWASP DC Chapter Meeting on 9/2</title>
		<link>http://blog.fyrmassociates.com/2009/08/25/xab-presentation-owasp-dc-chapter-meeting-on-92/</link>
		<comments>http://blog.fyrmassociates.com/2009/08/25/xab-presentation-owasp-dc-chapter-meeting-on-92/#comments</comments>
		<pubDate>Wed, 26 Aug 2009 02:11:36 +0000</pubDate>
		<dc:creator>Matthew Flick</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[DC]]></category>
		<category><![CDATA[XAB]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=129</guid>
		<description><![CDATA[I will be giving an update on XAB (Cross Site Scripting Anonymous Browser) with Jeff Yestrumskas at the OWASP DC Chapter&#8217;s next meeting on September 2 at 6:30PM. More details can be found here. See you there!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=129&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I will be giving an update on XAB (Cross Site Scripting Anonymous Browser) with Jeff Yestrumskas at the OWASP DC Chapter&#8217;s next meeting on September 2 at 6:30PM. More details can be found <a href="http://www.owasp.org/index.php/Washington_DC#tab=Next_Meeting">here</a>. See you there!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/129/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/129/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/129/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=129&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2009/08/25/xab-presentation-owasp-dc-chapter-meeting-on-92/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Matthew Flick</media:title>
		</media:content>
	</item>
		<item>
		<title>OWASP AppSec DC 2009 Sponsor</title>
		<link>http://blog.fyrmassociates.com/2009/08/20/owasp-appsec-dc-2009-sponsor/</link>
		<comments>http://blog.fyrmassociates.com/2009/08/20/owasp-appsec-dc-2009-sponsor/#comments</comments>
		<pubDate>Thu, 20 Aug 2009 23:25:56 +0000</pubDate>
		<dc:creator>Matthew Flick</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Conferences]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=127</guid>
		<description><![CDATA[OWASP just launched the official AppSec DC 2009 site @ http://appsecdc.org. We&#8217;ll be out in force and will most definitely have some type of party/event. Check back here often or follow us on Twitter (getFYRM) for updates. We&#8217;ll see you there!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=127&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>OWASP just launched the official AppSec DC 2009 site @ <a href="http://appsecdc.org">http://appsecdc.org</a>. We&#8217;ll be out in force and will most definitely have some type of party/event. Check back here often or follow us on Twitter (getFYRM) for updates. We&#8217;ll see you there!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/127/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/127/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/127/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=127&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2009/08/20/owasp-appsec-dc-2009-sponsor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Matthew Flick</media:title>
		</media:content>
	</item>
		<item>
		<title>LAN Party anyone? Let’s volunteer to hack Government websites&#8230;</title>
		<link>http://blog.fyrmassociates.com/2009/06/21/lan-party-anyone-let%e2%80%99s-volunteer-to-hack-government-websites/</link>
		<comments>http://blog.fyrmassociates.com/2009/06/21/lan-party-anyone-let%e2%80%99s-volunteer-to-hack-government-websites/#comments</comments>
		<pubDate>Sun, 21 Jun 2009 06:06:23 +0000</pubDate>
		<dc:creator>Matthew Flick</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Penetration Testing]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=93</guid>
		<description><![CDATA[hack govt, volunteer, pen-tests, Jeremiah Grossman, cybersecurity, SC Magazine, National Guard, ISC^2<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=93&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Would I volunteer my time? Sure, why not. Is it really a good or realistic idea to have our Military and Government solicit an army of volunteers to test their web sites? Probably not. Jeremiah Grossman, CTO and founder of WhiteHat Security, this past week voiced <a href="http://jeremiahgrossman.blogspot.com/2009/06/legalize-it-hacking-gov-and-mil-website.html">his opinion</a> on a topic that isn&#8217;t entirely new, but hasn&#8217;t been brought up by an industry pundit for a while. He estimates “fewer than ten percent of United Stats .GOV and .MIL websites are professionally tested for custom Web application vulnerabilities” and suggests getting vulnerability researchers to volunteer to test those web sites.  I honestly didn’t see his blog entry until late Thursday and up til now sort of waited to see all the comments to his thoughts. It seems feedback is back and forth with the more detailed responses are on the “not so good” idea side of the fence. Jack Mannino had a <a href="http://jack-mannino.blogspot.com/2009/06/my-response-to-dangerous-idea.html">good response</a>, which Jeremiah is planning to respond to.</p>
<p>Here are my thoughts: Have you ever worked directly for/with the government? Not a rhetorical question or being a smart a$$, but seriously. It’s a given that the US Federal government doesn’t spend enough money or resources on cybersecurity [see previous blogs]. I cannot imagine how difficult it would be to attempt to coordinate these “volunteer tests” with the Federal Agency, the government security teams that protect the site, the network and system folks responsible for the site, and then all the contractors involved in monitoring and supporting the site… that’s just a fraction of the folks on the government site. We’ve done contract work with the Federal Government and doing a simple scan of a small environment from a single source address took a tremendous amount of coordination and planning. It would be insanity to try to coordinate dozens of volunteers. And that is just one of a couple pre-planning obstacles I can see.</p>
<p>What about from a slightly tangent ethics view; is it volunteers or freebies? The Federal Government from what I’ve experienced has pushed procurement and purchasing folks through different types of ethics training to prevent inappropriate kickbacks to individuals and organizations. Could a big corporate entity like “Big Yellow” for example be allowed to volunteer a team of young staffers to “pen-test”? Wouldn’t it then be ironic if that same company down the line got a chance to bid on projects or even technologies to be implemented? You got to expect someone out there to try to take advantage of it.</p>
<p>The one point that Jack made mention that I’m not going to rehash too much but agree with is regarding incident response. Could you imagine being the contractor or GS-10 sitting in the SOC during “volunteer pen-test day”? If the government doesn’t have the tools to assess their own web sites, I wonder if they would have the technologies or resources in place to review the logs generated to figure out what is considered “normal” vs. “bad” traffic.</p>
<p>I’m not entirely sure if Jeremiah really thinks it’s a good idea or is throwing it out there for media fodder (I see <a href="http://www.scmagazineus.com/Security-expert-wants-feds-to-recruit-volunteer-pen-testers/article/138752/">SC Magazine</a> already picked it up). It does bring up some interesting early debate but the more I think about it, it just doesn’t seem reasonable.</p>
<p>However one thought I did come up with and please pardon me if there is already an organization like this, is taking a page from the National Guard. It would still require some money, background checks, a tremendous amount of coordination and volunteering. How about a “Cybersecurity National Guard” unit, where people can volunteer X hours a month and have one of the core responsibilities testing government and military web sites. I’m deeply familiar with the military and intelligence community programs and teams that do this, but this “volunteer” group could be staffed with vulnerability researchers who have extra time or want to do something more valuable for ISC^2 CPEs ;)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/93/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/93/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/93/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=93&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2009/06/21/lan-party-anyone-let%e2%80%99s-volunteer-to-hack-government-websites/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Matthew Flick</media:title>
		</media:content>
	</item>
		<item>
		<title>Cross Site Scripting Anonymous Browser (XAB) Proof-of-Concept Released</title>
		<link>http://blog.fyrmassociates.com/2009/05/19/cross-site-scripting-anonymous-browser-xab-proof-of-concept-released/</link>
		<comments>http://blog.fyrmassociates.com/2009/05/19/cross-site-scripting-anonymous-browser-xab-proof-of-concept-released/#comments</comments>
		<pubDate>Wed, 20 May 2009 00:20:37 +0000</pubDate>
		<dc:creator>Matthew Flick</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[XAB]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=80</guid>
		<description><![CDATA[Today I finally found the time to release the XAB Proof-of-Concept code. An apology to those of you who have been emailing us wondering when we would publish it. We&#8217;ve decided on Sourceforge and you can download the code from the XAB project page located at: http://sourceforge.net/projects/xab We&#8217;ve submitted talks to Black Hat and Defcon [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=80&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Today I finally found the time to release the XAB Proof-of-Concept code. An apology to those of you who have been emailing us wondering when we would publish it.</p>
<p>We&#8217;ve decided on Sourceforge and you can download the code from the XAB project page located at:</p>
<ul>
<li><a title="http://sourceforge.net/projects/xab" href="http://sourceforge.net/projects/xab" target="_blank">http://sourceforge.net/projects/xab</a></li>
</ul>
<p>We&#8217;ve submitted talks to Black Hat and Defcon for the updates we&#8217;re working on, so hopefully we&#8217;ll have the chance to catch everyone up&#8230;solicit some more feedback&#8230;and grab a brew. Or two&#8230;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/80/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/80/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/80/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=80&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2009/05/19/cross-site-scripting-anonymous-browser-xab-proof-of-concept-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Matthew Flick</media:title>
		</media:content>
	</item>
		<item>
		<title>Black Hat DC 2009 Presentation</title>
		<link>http://blog.fyrmassociates.com/2009/01/28/black-hat-dc-2009-presentation/</link>
		<comments>http://blog.fyrmassociates.com/2009/01/28/black-hat-dc-2009-presentation/#comments</comments>
		<pubDate>Wed, 28 Jan 2009 20:41:30 +0000</pubDate>
		<dc:creator>Matthew Flick</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Conferences]]></category>

		<guid isPermaLink="false">http://blog.fyrmassociates.com/?p=58</guid>
		<description><![CDATA[My abstract for this year’s Black Hat DC was picked up. I’ll be presenting the XSS Anonymous Browser tool, or XAB for short. I’m currently hammering out some of the more technical aspects of the tool, but I’ll have a working proof of concept ready for the conference. Plus if there’s time (who am I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=58&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>My abstract for this year’s Black Hat DC was picked up. I’ll be presenting the XSS Anonymous Browser tool, or XAB for short. I’m currently hammering out some of the more technical aspects of the tool, but I’ll have a working proof of concept ready for the conference. Plus if there’s time (who am I kidding?), I’ll release a second tool that is a great defense against the attack vectors that XAB utilizes. You can read more about the XAB tool presentation at the Black Hat DC 2009 Speakers Briefings page,</p>
<p><a href="http://www.blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Flick">http://www.blackhat.com/html/bh-dc-09/bh-dc-09-speakers.html#Flick</a></p>
<p>For those of you in the Tampa area, I will be presenting the same tool at the OWASP Tampa meeting on February 18. You can check out the Tampa Chapter’s page here,</p>
<p><a href="https://www.owasp.org/index.php/Tampa">https://www.owasp.org/index.php/Tampa</a></p>
<p>I hope to see you at either or both presentations and SafeSurfing&#8230;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/58/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/58/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/58/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=58&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2009/01/28/black-hat-dc-2009-presentation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Matthew Flick</media:title>
		</media:content>
	</item>
		<item>
		<title>The New PCI 6.6</title>
		<link>http://blog.fyrmassociates.com/2008/11/20/the-new-pci-66/</link>
		<comments>http://blog.fyrmassociates.com/2008/11/20/the-new-pci-66/#comments</comments>
		<pubDate>Thu, 20 Nov 2008 16:43:42 +0000</pubDate>
		<dc:creator>Matthew Flick</dc:creator>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[6.6]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[waf]]></category>

		<guid isPermaLink="false">http://fyrmassociates.wordpress.com/?p=33</guid>
		<description><![CDATA[All Your Public facing Web Apps Are Relevant To Us I’m going to start off this post with the moral of the story: Good intentions often have bad, unintended consequences. The following is the ‘Testing Procedures’ text of requirement 6.6 from the new PCI DSS v1.2 (source: https://www.pcisecuritystandards.org/security_standards/pci_dss_download.html): For public-facing web applications, ensure that either [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=33&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>All Your Public facing Web Apps Are Relevant To Us</p>
<p>I’m going to start off this post with the moral of the story: Good intentions often have bad, unintended consequences. The following is the ‘Testing Procedures’ text of requirement 6.6 from the new PCI DSS v1.2 (source: https://www.pcisecuritystandards.org/security_standards/pci_dss_download.html):</p>
<p style="padding-left:30px;"><em>For public-facing web applications, ensure that either one of the following methods are in place as follows:</em><em></em></p>
<p style="padding-left:60px;"><em>• Verify that public-facing web applications are reviewed (using either manual or automated vulnerability security assessment tools or methods), as follows:</em></p>
<p style="padding-left:90px;"><em> </em><em>– At least annually </em><br />
<em>– </em><em>After any changes </em><br />
<em>– </em><em>By an organization that specializes in application security </em><br />
<em>– </em><em>That all vulnerabilities are corrected</em><em> </em><br />
<em>– </em><em>That the application is re-evaluated after the corrections</em></p>
<p style="padding-left:60px;"><em>• </em><em>Verify that a web-application firewall is in place in front of public-facing web applications to detect and prevent web-based attacks.</em></p>
<ul></ul>
<p style="padding-left:30px;">
<p>Note that for ease of reading I’m going to shorten “PCI DSS v1.2 Requirement 6.6” to just “PCI 6.6” since nearly everyone already refers to it as such.</p>
<p>Without further clarification, this requirement now compels an organization that stores, processes, or transmits cardholder data (“CHD”) to apply PCI 6.6 to all of their “web applications” that are publicly accessible, regardless of whether the applications participate in the storage, processing, or transmission of CHD. We must assume also that this requirement will be applicable regardless of other security controls as well, such as network segmentation. Disregarding all other changes to the PCI DSS, this one requirement could significantly increase the level of effort and cost of PCI assessments.</p>
<p>Before I get into advice for dealing with the new requirement, let’s examine the two options in relation to the change. First option is to have an application security organization perform security testing on the applications, correct identified vulnerabilities, re-test and repeat if necessary. Furthermore, such testing must occur “at least annually”, which should not be a huge problem…and “after any changes”, which could very easily force an organization to simply stop making any changes to its web applications. Unintended consequences.</p>
<p>The second option seems rather simple, straightforward, and innocuous unless you have actual experience with web application firewalls (“WAFs”). At a high level, WAFs have two basic modes of defense: 1. Blacklisting attack strings, typically pushed down by the vendor like anti-virus signature updates, and 2. Custom rule checking, which requires training the WAF to understand more of the application it is protecting. Both modes can often lead to false positives; the second and more effective mode requires a lot of human interaction throughout the system’s lifecycle. Add to the mix the large price tag for commercial WAFs and the new requirement that requires protection for all public facing web applications, and what you likely end up with is an organization implementing an easily defeated blacklist of your standard attack strings (XSS, SQL injection, etc). Unintended consequences</p>
<p>I do not want to be accused of PCI hate speech. In fact, I would like to sincerely applaud their efforts in helping to drive application security education and strongly encouraging organizations to address the problems. My concern, though, is that the more stringent the requirements become, the more likely organizations will continue (or begin) to do only the bare minimum in order to “check the box” instead of fixing the root cause of the problem. This is similar to the problem of progressively raising taxes: the higher the tax rate climbs, the more people will invest to identify loopholes, legal or otherwise. Or, in Star Wars terms, “The more you tighten your grip, Tarkin, the more star systems will slip through your fingers.” &#8211;Princess Leia</p>
<p>With this information in mind, we now come to the issue of how to approach PCI 6.6. I’m going to suggest the most pragmatic approach that should work for most or all organizations, or at least those organizations that must endure PCI DSS assessments. In step-by-step format, naturally:</p>
<ol>
<li>Classify applications – Separate all public facing web applications into a grid by user type (e.g. internal users only, external users only, mixed) and data sensitivity (e.g. CHD, public, internal/corporate, internal/sensitive).</li>
<li>Shorten list – If possible, move all web applications with internal users only to the internal network and provide external access via VPN. This should be an obvious move and something that should have been done well before PCI 6.6, but you might be surprised how often I see this situation.</li>
<li>Create assessment plan – First determine the budget for performing automated runtime vulnerability scans (the &#8220;cheap&#8221; option) against all remaining public facing web applications. Then the remaining budget—if any—can be reserved to add more effective assessment tasks to the most relevant applications, obviously starting with those that store, process, or transmit CHD.</li>
</ol>
<p>As a general rule, I suggest using the results of a vulnerability scan/assessment against one application to identify and remediate potential weaknesses in other applications that either use the same codebase or were developed in similar fashion. This approach should lessen the number of findings in subsequent tests.</p>
<p>If all the advice in this post seemed familiar or common sense, then congratulations…you’ve been paying attention! The security industry has been evangelizing a risk-based approach for a long time now. Or at least some of us in the industry have been.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/fyrmassociates.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/fyrmassociates.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/fyrmassociates.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/fyrmassociates.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/fyrmassociates.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/fyrmassociates.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/fyrmassociates.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/fyrmassociates.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/fyrmassociates.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/fyrmassociates.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/fyrmassociates.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/fyrmassociates.wordpress.com/33/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/fyrmassociates.wordpress.com/33/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/fyrmassociates.wordpress.com/33/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.fyrmassociates.com&amp;blog=5398781&amp;post=33&amp;subd=fyrmassociates&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.fyrmassociates.com/2008/11/20/the-new-pci-66/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Matthew Flick</media:title>
		</media:content>
	</item>
	</channel>
</rss>