Thursday, 10 January 2013

OpenQA.Selenium.DriverServiceNotFoundException on Chrome

While trying to running a TeamMentor UnitTest in Chrome I got this error:

Coding Firefox in C# in real-time using Selenium's Firefox driver

The best way to write and debug Selenium Web Automation scripts is to be able to be able to write code snippets in real time (in a REPL)

This post will show how I just did that for the TeamMentor’s UnitTests environment that Michael Hidalgo is working on.

Dangerous bug between Git, GitHub and Windows (duplicate directories with different capitalization)

After doing this rename, here is what GitHub looks like:

Using VisualStudio C# REPL to quickly find issue

While refactoring a TeamMentor UnitTest, I hit on this error:

Just moved from MSTest to NUnit

Because although we did try to use MSTest for TeamMentor UnitTesting, it lacked a couple key features (namely the ability to define generic types in the Class Attribute).

Here is Michael’s commit that shows a simple NUnit test with multiple Browser invocations (note the TestFixture attributes):

GitHub is having some probs today

Here is what a GitHub Commit page looks like:

Nice way to give Feedback to Google

Ok, now this is quite cool (and I just used it to send a link of my last blog post to Google)

Choosing the 'Send feedback' link:

Blogger just changed the way it handles post edits (i.e. it changes the date now)

Blogger must have pushed an update that changed the date of an post everytime there is a minor edit on it.

This means that the couple (old) posts that I just changed a couple labels, have now the wrong date!!! 

Viewing an Azure WebSite IIS Logs

On Azure created websites, the main Azure UI provides some interesting stats:

Why does windows Azure need to '0wn' my GitHub Account?

While creating an Azure website (part of TeamMentor CI) I tried to connect Azure with GitHub and got this request:

On how to get paid to work on OWASP projects

Here is an old blog post (from May 2012) that I never got around to publish (got lost on the drafts folders), that provides more info on why OWASP cannot pay its leaders, and how to get paid to work on OWASP projects

Nice SI 2012 Q4 Newsletter

SI just published its 2012 Q4 AppSec Report newsletter which looks really good, and has a couple sections about TeamMentor :)

You can get the pdf from here or view it online here (or below)

IBM AppScan eval downloads - and what is the difference between Standard, Source, Enterprise and Dynamic?

If you go the IBM AppScan download page you can see four downloads:
  • IBM Security AppScan Standard V8.6 Evaluation Windows 
  • IBM Security AppScan Source for Analysis V8.6 Evaluation Multiplatform
  • IBM Security AppScan Enterprise Server V8.6 Evaluation Multiplatform
  • IBM Security AppScan Enterprise Dynamic Analysis Scanner V8.6 Evaluation

Wednesday, 9 January 2013

First PoC of TeamMentor integration with HubSpot

Here is a Video that shows a PoC of consuming and manipulating HubSpot user database (called Contacts) natively from inside TeamMentor:

Tuesday, 8 January 2013

Anonymous Vulnerability Reporting Service

Is there an Anonymous Vulnerability Reporting Service out there?

Basically one where it is possible to report a vulnerability on a website without worrying about the other side throwing a tantrum and accusing the messenger with 'malicious hacking'?

It is a sad state of our industry that this is needed, but with the current computer criminal laws making all internet users a potential criminal, it is too risky to put a carrer in a the hands of the company that created the vulnerable product or service.

Ideally this service would allow:

My focus, O2 as the Open Platform, why IBM needs open standards and O2+AppScan research project

Here is an email (with minor edits) that I wrote recently to an (retired) IBMer and Bill Cheswick an Network Security guru (where I tried to answer the questions: "What are you trying to do? What is O2? and how can O2 help IBM?")


Hi Bill

My focus is on Web Application Security, namely on how to create secure applications.

My key objectives are to:
  • enable developers to write secure code
  • enable buyers/users to make informed and risk-based 'application security' decisions
  • scale application security knowlege
In order to make this happen, I wrote an Open Platform (called the OWASP O2 Platform) which allows the creation of custom 'analysis engines'. These engines are created from security expert's knowledge/workflows and the output/capabilities of Application Security Tools (like the ones from IBM AppScan, HP Fortify, Veracode, CheckMarx, etc...). I am also the lead architect and developer of the TeamMentor product (from Security Innovation) which is aimed at providing hyperlinked Security Knowledge to developers (e.g. prescriptive guidance for developers mapped to corporate policies)

Monday, 7 January 2013

Teaching kids how to code - UK's CodeClub

CodeClub looks like a great way to be involved in the UK in teaching kids how to program (which I believe to be very important).

The first lessons seem to use Scratch from MIT.

Interesting spam message

The key is in the link of the poster name (which points to a YouTube video trying to sell a product).

This is a good example of one of the current malicious business models: Web Traffic Generation

Friday, 4 January 2013

Adding git support to IIS (maybe using Kudu?)

What is the best way to allow git publishing via an IIS site? Namely from a TeamCity build?

As nicely described on Deploying: Add Git support to your IIS server, maybe Kudo could be a good option (kudu is used by Windows Azure)

VersionOne.com - interesting tool and good site

We’re looking at a better way to manage the TM dev team and Michael suggested VersionOne which looks really interesting.

I also like the layout of its main page and the way the video clearly shows how the tool works (that kind of animation is really powerful)

image

Another feedback form that fails – this time from Telerik JustCode

I just uninstalled JustCode, was asked to provide feedback:

Thursday, 3 January 2013

Can you put this on a Hyperlinkable location?

"Can you Hyperlink that?" is a question that over the years I have been asking more and more.

The idea is that if information is not in an Hyperlinkable location, then it can't be easily found (or indexed or refereed to).

if you make it easy people will buy it (vs 'steal it')

A while back (I think in early 2000) when I was more involved in the music industry I remember reading an amazing research paper that basically said: "...If the music industry, instead of fighting Napster, creates a solution where the normal user/consumer can easily buy music at a 'fair' price, then most users will do it..." (unfortunately I was not blogging back then, so I lost that link :(  )

Of course that this advise was not listened to and it took Steve Jobs to actually make it happen.

I think the time as come for OWASP to have its own secure browser(s)

The idea is to create a customised version of a popular browser (like Chrome or Firefox) that has been customised to be secure out-of-the-box.

It could even be something like http://www.srware.net/ but I want to leverage the trust-network that OWASP has (and its potential to peer-review) to create a piece of software that I actually trust (or that it can earn my trust with time)

2013 wish list and objectives

Happy new year. I’m just back from spending a week in the US where I actually didn’t touch my laptop (for work or coding) and was able to relax, read a number of books and spend a great time with family and friends.

On the way back I started writing on my (paper-based) molenskine notebook a bunch of ideas/concepts/plans (which should appear in future blog posts)

One of the things I wrote down was this (unedited and not-in-specific order) 2013 wish list and objectives: