<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title>Fuzzing and Product Security</title><description>2009-03-18 10:08:05 - Ari Takanen's blog :    Finally, some real data on the usage of fuzzing is emerging Who isusing fuzzing How do people see fuzzing being used in the productsecurity process Forrester has included questions regarding use offuzzing in to their questionnaire that they send to key industry CIOs,CSOs and CISOs Security companies such as Cigital are publishingtheir findings I have talked with these organizations and will bediscussing my findings in this blog and the upcoming webinarread moreAdd to digg Add to StumbleUpon Add to Twitter Add to Slashdot</description><link>http://www.secuobs.com/revue/news/72040.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/72040.shtml</guid></item>
<item><title>Greatest Challenge in VoIP Security</title><description>Secuobs.com : 2009-01-20 04:38:06 - Ari Takanen's blog -    The greatest challenge in VoIP security is that there are very fewgood example case studies available There are some very good VoIPdeployments But try to find a white-paper with someone disclosing allthe their success stories in building a perfect VoIP network No luckUnfortunately much of that data is hidden in confidential documentsStill, I have really loved to see VoIP security emerge and evolve frombeing a hindrance in VoIP deployment, into a key marketing valueFinally some of those success stories will get a chance to seedaylightread more</description><link>http://www.secuobs.com/revue/news/53018.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/53018.shtml</guid></item>
<item><title>VoIP security auditing is becoming more and more complex  Not</title><description>Secuobs.com : 2009-01-20 04:38:06 - Ari Takanen's blog -    I am curious how people can conduct penetration tests of a complexVoIP system when they barely understand how VoIP infrastructure worksToday, security people are still stuck to auditing practices from1990s When asked to do a penetration test, a consultant often is onlylooking at past issues that can be detected using variousvulnerability scanners Very few of them know that vulnerabilityscanners have extremely bad coverage of vulnerabilities in VoIPsolutions And even if the tools did know VoIP, who really cares aboutpast issues that might have been relevant several years agoread more</description><link>http://www.secuobs.com/revue/news/53017.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/53017.shtml</guid></item>
<item><title>Is There Motivation for VoIP Fuzzing</title><description>Secuobs.com : 2009-01-20 04:38:06 - Ari Takanen's blog -    What have we learned during these six or so years of proactivesecurity work with VoIP fuzzing Here is my top ten discoveriesread moreAdd to digg Add to StumbleUpon Add to Twitter Add to Slashdot</description><link>http://www.secuobs.com/revue/news/53016.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/53016.shtml</guid></item>
<item><title>Reason Behind Vulnerabilities</title><description>Secuobs.com : 2009-01-20 04:38:06 - Ari Takanen's blog -    Now something completely unrelated to VoIP: Reason behind allvulnerabilities in software I read an article that explained howvulnerabilities are basically created by the fact that people tend todrift from good development principles into practices that are justsimply Fun The engineers among us know that software development canbe enormously interesting, something you would happily even do in yourleisure time But can fun be converted into reliable softwareread moreAdd to digg Add to StumbleUpon Add to Twitter Add to Slashdot</description><link>http://www.secuobs.com/revue/news/53015.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/53015.shtml</guid></item>
<item><title>VoIP Still Not Ready For Carrier-Grade Networks</title><description>Secuobs.com : 2009-01-20 04:38:06 - Ari Takanen's blog -    After a quick tour of some Really Talented Groups dedicated to fuzzingresearch, I noticed three things: 1 Most teams are focused on fuzzingVoIP 2 Most if not all VoIP devices still break with fuzzing 3 MostVoIP vendors still do not get it The tour continuesread moreAdd to digg Add to StumbleUpon Add to Twitter Add to Slashdot</description><link>http://www.secuobs.com/revue/news/53014.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/53014.shtml</guid></item>
<item><title>Good VoIP Deployment Guidelines Do Not Exist</title><description>Secuobs.com : 2009-01-20 04:38:06 - Ari Takanen's blog -    I get questions regarding VoIP deployment all the time Sometimes itis someone looking for simple and cheap Enterprise VoIP, who areunsure if VoIP can be deployed securely with those two parameters inthe equation More often it is the security aware people who arewilling to invest almost anything to make it work, but cannot Asalways, there is no silver bullet solution for either If you look atmy past opinions, I keep changing my mind between cheap that works,and secure that doesn't What do you think Which way should we go inVoIPread moreAdd to digg Add to StumbleUpon Add to Twitter Add to Slashdot</description><link>http://www.secuobs.com/revue/news/53013.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/53013.shtml</guid></item>
<item><title>Fuzzing Is Still Widely Unknown</title><description>Secuobs.com : 2009-01-20 04:38:06 - Ari Takanen's blog -    As a part of my new year resolution to change my blog here into moregeneric fuzzing blog, I will start by sharing my experiences in thecurrent state of fuzzing market Based on a recent study, all majorproduct security teams apparently use fuzzing But most even securityspecialists still misunderstand what fuzzing really is about So, Iwill focus on that here also Enter the world of fuzzingread moreAdd to digg Add to StumbleUpon Add to Twitter Add to Slashdot</description><link>http://www.secuobs.com/revue/news/53012.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/53012.shtml</guid></item>
</channel>
</rss>
 
