While trying to running a TeamMentor UnitTest in Chrome I got this error:
A personal blog about: transforming Web Application Security into an 'Application Visibility' engine, the OWASP O2 Platform, Application/Data interoperability and a lot more
Thursday, 10 January 2013
Coding Firefox in C# in real-time using Selenium's Firefox driver
The best way to write and debug Selenium Web Automation scripts is to be able to be able to write code snippets in real time (in a REPL)
This post will show how I just did that for the TeamMentor’s UnitTests environment that Michael Hidalgo is working on.
This post will show how I just did that for the TeamMentor’s UnitTests environment that Michael Hidalgo is working on.
Labels:
NUnit,
REPL,
Selenium,
TeamMentor,
Unit Tests
Dangerous bug between Git, GitHub and Windows (duplicate directories with different capitalization)
After doing this rename, here is what GitHub looks like:
Labels:
Git,
GitHub,
TeamMentor
Using VisualStudio C# REPL to quickly find issue
While refactoring a TeamMentor UnitTest, I hit on this error:
Labels:
REPL,
TeamMentor,
Unit Tests,
VisualStudio
Just moved from MSTest to NUnit
Because although we did try to use MSTest for TeamMentor UnitTesting, it lacked a couple key features (namely the ability to define generic types in the Class Attribute).
Here is Michael’s commit that shows a simple NUnit test with multiple Browser invocations (note the TestFixture attributes):
Here is Michael’s commit that shows a simple NUnit test with multiple Browser invocations (note the TestFixture attributes):
Labels:
NUnit,
TeamMentor,
Unit Tests
Nice way to give Feedback to Google
Ok, now this is quite cool (and I just used it to send a link of my last blog post to Google)
Choosing the 'Send feedback' link:
Choosing the 'Send feedback' link:
Labels:
Design
Blogger just changed the way it handles post edits (i.e. it changes the date now)
Blogger must have pushed an update that changed the date of an post everytime there is a minor edit on it.
This means that the couple (old) posts that I just changed a couple labels, have now the wrong date!!!
Labels:
Rant
Viewing an Azure WebSite IIS Logs
On Azure created websites, the main Azure UI provides some interesting stats:
Labels:
Azure,
TeamMentor
Why does windows Azure need to '0wn' my GitHub Account?
While creating an Azure website (part of TeamMentor CI) I tried to connect Azure with GitHub and got this request:
Labels:
Azure,
Rant,
Security as TAX
On how to get paid to work on OWASP projects
Here is an old blog post (from May 2012) that I never got around to publish (got lost on the drafts folders), that provides more info on why OWASP cannot pay its leaders, and how to get paid to work on OWASP projects
Labels:
OWASP
Nice SI 2012 Q4 Newsletter
SI just published its 2012 Q4 AppSec Report newsletter which looks really good, and has a couple sections about TeamMentor :)
You can get the pdf from here or view it online here (or below)
You can get the pdf from here or view it online here (or below)
Labels:
TeamMentor
IBM AppScan eval downloads - and what is the difference between Standard, Source, Enterprise and Dynamic?
If you go the IBM AppScan download page you can see four downloads:
- IBM Security AppScan Standard V8.6 Evaluation Windows
- IBM Security AppScan Source for Analysis V8.6 Evaluation Multiplatform
- IBM Security AppScan Enterprise Server V8.6 Evaluation Multiplatform
- IBM Security AppScan Enterprise Dynamic Analysis Scanner V8.6 Evaluation
Labels:
IBM
Wednesday, 9 January 2013
First PoC of TeamMentor integration with HubSpot
Here is a Video that shows a PoC of consuming and manipulating HubSpot user database (called Contacts) natively from inside TeamMentor:
Labels:
TeamMentor,
Video
Tuesday, 8 January 2013
Anonymous Vulnerability Reporting Service
Is there an Anonymous Vulnerability Reporting Service out there?
Basically one where it is possible to report a vulnerability on a website without worrying about the other side throwing a tantrum and accusing the messenger with 'malicious hacking'?
It is a sad state of our industry that this is needed, but with the current computer criminal laws making all internet users a potential criminal, it is too risky to put a carrer in a the hands of the company that created the vulnerable product or service.
Ideally this service would allow:
Basically one where it is possible to report a vulnerability on a website without worrying about the other side throwing a tantrum and accusing the messenger with 'malicious hacking'?
It is a sad state of our industry that this is needed, but with the current computer criminal laws making all internet users a potential criminal, it is too risky to put a carrer in a the hands of the company that created the vulnerable product or service.
Ideally this service would allow:
Labels:
Question
My focus, O2 as the Open Platform, why IBM needs open standards and O2+AppScan research project
Here is an email (with minor edits) that I wrote recently to an (retired) IBMer and Bill Cheswick an Network Security guru (where I tried to answer the questions: "What are you trying to do? What is O2? and how can O2 help IBM?")
Hi Bill
My focus is on Web Application Security, namely on how to create secure applications.
Hi Bill
My focus is on Web Application Security, namely on how to create secure applications.
My key objectives are to:
- enable developers to write secure code
- enable buyers/users to make informed and risk-based 'application security' decisions
- scale application security knowlege
In order to make this happen, I wrote an Open Platform (called the OWASP O2 Platform) which allows the creation of custom 'analysis engines'. These engines are created from security expert's knowledge/workflows and the output/capabilities of Application Security Tools (like the ones from IBM AppScan, HP Fortify, Veracode, CheckMarx, etc...). I am also the lead architect and developer of the TeamMentor product (from Security Innovation) which is aimed at providing hyperlinked Security Knowledge to developers (e.g. prescriptive guidance for developers mapped to corporate policies)
Labels:
IBM,
O2,
Philosophy,
Security
Monday, 7 January 2013
Teaching kids how to code - UK's CodeClub
CodeClub looks like a great way to be involved in the UK in teaching kids how to program (which I believe to be very important).
The first lessons seem to use Scratch from MIT.
The first lessons seem to use Scratch from MIT.
Labels:
Education
Interesting spam message
The key is in the link of the poster name (which points to a YouTube video trying to sell a product).
This is a good example of one of the current malicious business models: Web Traffic Generation
This is a good example of one of the current malicious business models: Web Traffic Generation
Labels:
Security
Friday, 4 January 2013
Adding git support to IIS (maybe using Kudu?)
What is the best way to allow git publishing via an IIS site? Namely from a TeamCity build?
As nicely described on Deploying: Add Git support to your IIS server, maybe Kudo could be a good option (kudu is used by Windows Azure)
As nicely described on Deploying: Add Git support to your IIS server, maybe Kudo could be a good option (kudu is used by Windows Azure)
VersionOne.com - interesting tool and good site
We’re looking at a better way to manage the TM dev team and Michael suggested VersionOne which looks really interesting.
I also like the layout of its main page and the way the video clearly shows how the tool works (that kind of animation is really powerful)
I also like the layout of its main page and the way the video clearly shows how the tool works (that kind of animation is really powerful)
Labels:
Tools
Another feedback form that fails – this time from Telerik JustCode
I just uninstalled JustCode, was asked to provide feedback:
Thursday, 3 January 2013
Can you put this on a Hyperlinkable location?
"Can you Hyperlink that?" is a question that over the years I have been asking more and more.
The idea is that if information is not in an Hyperlinkable location, then it can't be easily found (or indexed or refereed to).
The idea is that if information is not in an Hyperlinkable location, then it can't be easily found (or indexed or refereed to).
Labels:
Philosophy,
TeamMentor
if you make it easy people will buy it (vs 'steal it')
A while back (I think in early 2000) when I was more involved in the music industry I remember reading an amazing research paper that basically said: "...If the music industry, instead of fighting Napster, creates a solution where the normal user/consumer can easily buy music at a 'fair' price, then most users will do it..." (unfortunately I was not blogging back then, so I lost that link :( )
Of course that this advise was not listened to and it took Steve Jobs to actually make it happen.
Of course that this advise was not listened to and it took Steve Jobs to actually make it happen.
Labels:
Philosophy
I think the time as come for OWASP to have its own secure browser(s)
The idea is to create a customised version of a popular browser (like Chrome or Firefox) that has been customised to be secure out-of-the-box.
It could even be something like http://www.srware.net/ but I want to leverage the trust-network that OWASP has (and its potential to peer-review) to create a piece of software that I actually trust (or that it can earn my trust with time)
It could even be something like http://www.srware.net/ but I want to leverage the trust-network that OWASP has (and its potential to peer-review) to create a piece of software that I actually trust (or that it can earn my trust with time)
Labels:
Half-baked Idea,
OWASP
2013 wish list and objectives
Happy new year. I’m just back from spending a week in the US where I actually didn’t touch my laptop (for work or coding) and was able to relax, read a number of books and spend a great time with family and friends.
On the way back I started writing on my (paper-based) molenskine notebook a bunch of ideas/concepts/plans (which should appear in future blog posts)
One of the things I wrote down was this (unedited and not-in-specific order) 2013 wish list and objectives:
On the way back I started writing on my (paper-based) molenskine notebook a bunch of ideas/concepts/plans (which should appear in future blog posts)
One of the things I wrote down was this (unedited and not-in-specific order) 2013 wish list and objectives:
Labels:
Wish lists
Subscribe to:
Posts (Atom)