OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Web Site Certification

From: Admin Dbtech (admindbtech.org)
Date: Thu Apr 27 2006 - 10:34:53 CDT


Hey,

To be very honest, I believe most of these services are nothing less
then a very false sense of security.

In the past I have had many clients who relied on these organizations
for their security testing however during penetration testing I
successfully compromised these clients either through the web
application or with known exploits from the metasploit framework.

Anyone who is involved with security can testify that automated services
can NEVER replace a human audit and anyone that says that they guarantee
security doesn't know what they are talking about.

Regards,
Yash Kadakia
Senior Security Researcher
Deadbolt Computer Technologies
http://www.dbtech.org

Marco Passarella wrote:
> Hi all,
> what do you think about the remote services that promise your site to
> be "hacker free"?
> Can you really monitor remotely the security of a site using a scanner?
> Here is an example:
> http://www.scanalert.com/
>
> Thanks,
> Mark
>
> -------------------------------------------------------------------------
> Sponsored by: Watchfire
>
> Watchfire's AppScan is the industry's first and leading web
> application security testing suite, and the only solution to provide
> comprehensive remediation tasks at every level of the application.
> Change the way you think about application security testing - See for
> yourself. Download a Free Trial of AppScan 6.0 today!
>
> https://www.watchfire.com/securearea/appscansix.aspx?id=701300000007kaF
> --------------------------------------------------------------------------
>
>
>
>

-------------------------------------------------------------------------
Sponsored by: Watchfire

Watchfire's AppScan is the industry's first and leading web application
security testing suite, and the only solution to provide comprehensive
remediation tasks at every level of the application. Change the way you
think about application security testing - See for yourself.
Download a Free Trial of AppScan 6.0 today!

https://www.watchfire.com/securearea/appscansix.aspx?id=701300000007kaF
--------------------------------------------------------------------------