July 29th, 2008 chris
Insecure networks are caused by insecure systems which are built on insecure software methodology. Yes, the problem of security for today is caused by the bad practices of organizations who built the software that runs the corporate system and networks. To fix this practice, one needs to revamp old habits, dig deep under the foundation and pour on high grade cement practices on software development. Build up heavy duty pillars to carry the ceiling which will secure the shielding roof from storm threats in your organization. These pillars that carries the load to keep you safe and secure are the following:
- Applied Risk Management
- Software Security Touchpoints
- Knowledge
Posted in Software Security
July 25th, 2008 chris
Is this a typo or what, should this title be ending with a word that starts with “O” as in Optimization. Many of us who have been on the web business and have been busy fixing our site’s html tags like the div’s, em’s, and a’s most of our time are used to seeing the word optimization next to search engine. Well, i have news for you, the word “Marketing” is now the IN word today or since a year ago. It really does fit the word search engine, it makes a more strong case in the word. But its not just a word change, it does not even replace the SEO word, its a higher level word or a parent word. Funny though that the child came first before its parent in the cyber lingo. Search Engine Marketing or SEM has more meat and more flavorings. SEO is just one of its flavorings and further we define this to the following:
Search Engine Marketing is maximizing the number of searchers coming to your site by taking specific actions to attract visitors to your site from search sites.
Posted in SEO / SEM
July 24th, 2008 chris
To capitalize on your assets in cyberspace, you need to have it receive a lot of visits from potential clients and be known. One way to do this is by having the search engines like Yahoo and Google list your site whenever someone types in for searches on a particular subject which relates to your services and products. And not only that, you need these search engines list your site on the first page of the results and near the top if not the top, or else your potential clients who are very busy or lazy would not have the chance to get a glimpse of your site’s name. One method to doing this is called Search Engine Optimization or SEO. But how does this method let you get on the Top and the first page of the search results. Well, it does this by customizing the elements of your website. In short, the meaning of SEO is the science of customizing elements of your web site to achieve the best possible search engine ranking.
Posted in SEO / SEM
July 23rd, 2008 chris
Security nowadays is more of a necessity than a luxury. Due to the influx of networks and the internet, every system is a sitting duck for the predator. There are three trends that have a great influence on the growth and evolution of the security problem. They are called the Trinity of Trouble and they are the following:
- Connectivity
- Extensibility
- Complexity
Posted in Software Security
July 23rd, 2008 chris
The Test Plan Document describes the scope, approach, resources, and schedule of the testing activities.
It is composed of the following 16 Sections:
- Test plan identifier
- Introduction
- Test items
- Features to be tested
- Features not to be tested
- Approach
- Item pass/fail criteria
- Suspension criteria and resumption requirements
- Test deliverables
- Testing tasks
- Environmental needs
- Responsibilities
- Staffing and training needs
- Schedule
- Risks and contingencies
- Approvals
Posted in Software Testing
July 23rd, 2008 chris
Eight documents that can be used in software testing according to IEEE Standard for Software Test Documentation
- Test plan
- Test design specification
- Test case specification
- Test procedure specification
- Test item transmittal report
- Test log
- Test incident report
- Test summary report
Posted in Software Testing
July 23rd, 2008 chris
The following are the five issues to watch for on Shared Hosting
- Exposed Source Code
- Exposed Session Data
- Session Injection
- Filesystem Browsing
- Safe Mode
Posted in Software Security
July 23rd, 2008 chris
The following are the four issues to watch for on Authentication and Authorization
- Brute Force Attacks
- Password Sniffing
- Replay Attacks
- Persistent Logins
Posted in Software Security
July 23rd, 2008 chris
The following are the three issues to watch for on Files and Commands
- Transversing the Filesystem
- Remote File Risks
- Command Injection
Posted in Software Security
July 23rd, 2008 chris
The following are the four issues to watch for on Includes
- Exposed Source Code
- Backdoor URLs
- Filename Manipulation
- Code Injection
Posted in Software Security