Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Application Security: We Still Have A Long Way To Go
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
planetlevel
50%
50%
planetlevel,
User Rank: Author
12/9/2013 | 12:58:09 PM
Re: App security tools ?
@danielcawrey At least as far as security is concerned, I believe that the lack of management support is a direct result of the lack of visibility into security.  Management gets a very unclear and spotty view of security across their application portfolio -- even on projects where security is a priority.  Developers can improve this visibility dramatically by writing test cases and other simple tools that demonstrate the security of their code.  For example, write a tool that shows all of your HTTP headers are set properly.  Or that every controller has the proper access control checks.  You'll find problems earlier and create the visibility that allows management to support you better!

--Jeff
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
12/9/2013 | 12:14:33 PM
Re: Re : Application Security: We Still Have A Long Way To Go
Gr8 advice, Jeff. Thanks. Here's the link to the OWASP DependencyCheck for anyone interested. This is also a good venue -- while you've got Jeff's ear -- to let him know how you like it and else resources you'd like to see in the OWASP libraries and frameworks.
planetlevel
50%
50%
planetlevel,
User Rank: Author
12/9/2013 | 11:57:57 AM
Re: Re : Application Security: We Still Have A Long Way To Go
@SachinEE -- Probably the first and best thing to do is to make sure you're using the latest version of your libraries and frameworks.   At least the ones with known vulnerabilities.  There are a few commercial tools, but the OWASP DependencyCheck is a great way to start.  Long term, we are going to a lot more help finding, selecting, integrating, maintaining, updating, and generally managing our libraries and frameworks.

--Jeff
planetlevel
50%
50%
planetlevel,
User Rank: Author
12/9/2013 | 11:54:07 AM
Re: App security tools ?
Hi irakov,

You're right that developers are often put into the very difficult position of being blamed for security problems without the proper process/tools/time/etc... to actually make that happen.  I gave a talk recently "Application Security at DevOps Speed and Portfolio Scale" that presents a new approach to this dilemma.  I'll be writing more about this, but I'd love to hear your thoughts.  youtube.com/watch?v=cIvOth0fxmI

--Jeff
SachinEE
50%
50%
SachinEE,
User Rank: Apprentice
11/27/2013 | 1:09:29 AM
Re : Application Security: We Still Have A Long Way To Go
This is quite understandable that when developers have to leverage their app with other sources like libraries which are not under their control they are dealing with danger. What could possibly be done about it? Should they be selective about giving access to libraries considering potential vulnerabilities which come with them? Or they can actually do something about those vulnerabilities?
SachinEE
100%
0%
SachinEE,
User Rank: Apprentice
11/27/2013 | 1:09:24 AM
Re : Application Security: We Still Have A Long Way To Go
@ danielcawrey, I strongly agree with you on this. It is a problem developers have always been complaining about that they are not given sufficient time to do their job thoroughly and their own way. When you are tightly running against time, you are sure to miss out on some minor things which in case of application development don't prove to be that minor vulnerabilities.
Chuck Brooks
50%
50%
Chuck Brooks,
User Rank: Apprentice
11/26/2013 | 1:01:52 PM
applications security
Beyond encryption, new technologies/processes (keyless authentication) for secure applications are being developed. I believe that that will be the future of data integrity.
J_Brandt
50%
50%
J_Brandt,
User Rank: Apprentice
11/24/2013 | 4:54:35 PM
Re: OWASP A9 & Components
Time is not given for appropriate security testing because security still doesn't rate high enough in enough people's minds.  That has to change.
marktroester
50%
50%
marktroester,
User Rank: Apprentice
11/22/2013 | 2:33:02 PM
OWASP A9 & Components
Thanks for article Jeff, and your presentations at AppSecUSA! It's great to see that OWASP has recognized the prevalence of components in today's applications. Sonatype has done research that indicates that the average application consists of 80% or more open source components. While using components like web frameworks, logging utilities, database access routines, etc., speed development, if organizations don't manage the use of components, they can put the organization at risk.

We published a whitepaper that addresses the A9 requirement and application components -

http://www.sonatype.com/resources/whitepapers

There is also a PCI related whitepaper as well.

Thanks, 

Mark Troester

Sonatype

@mtroester

 
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
11/22/2013 | 8:08:55 AM
Re: App security tools ? & deadlines and security priorities
I've heard that complaint from developers many times, danielcawrey. What do you think management should know about the software development process that would lead to better application security? 
Page 1 / 2   >   >>


When It Comes To Security Tools, More Isn't More
Lamont Orange, Chief Information Security Officer at Netskope,  1/11/2021
US Capitol Attack a Wake-up Call for the Integration of Physical & IT Security
Seth Rosenblatt, Contributing Writer,  1/11/2021
IoT Vendor Ubiquiti Suffers Data Breach
Dark Reading Staff 1/11/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3113
PUBLISHED: 2021-01-17
Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/list/allActiveSession request. For example, the attacker can discover the admin's cookie if the admin account happens to be logged in when the allActiveSession request occurs, and ...
CVE-2020-25533
PUBLISHED: 2021-01-15
An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct ...
CVE-2021-3162
PUBLISHED: 2021-01-15
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
CVE-2021-21242
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. This Servlet does not enforce any authentication or a...
CVE-2021-21245
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location (`request.getHeader("File-Name")`). This issue may lead to arbitrary file upload which can be used to u...