Core Security
info@coresecurity.com  | +1.617.399.6980 | Contact Us   Core Blog Core Blog Twitter LinkedIn youtube
Events and Webcasts
SHARE
SANS What Works in Penetration Testing & Web Application Attacks

Title: Penetration Testing Lessons from the Field
Presenter: Alberto Soliño
Date: Monday June 1, 2009
Location: Paris Hotel, Las Vegas, NV
Event Information: http://www.sans.org/pentesting09_summit/index.php


Abstract:
Web applications developers are still taught to consider security as a secondary concern, after uptime and functionality, and many unapproved commercial applications get onto networks and devices driven by user demand, regardless of policies. Meanwhile, organizations remain focused on check-box compliance tasks and don’t have resources to focus on underlying security issues and needed remediation, a situation that can often be compounded as they grow via mergers and acquisitions. In this summary of real-world penetration testing results, we’ll explore many of the common mistakes that organizations are making in attempting to build and defend their Web apps, and how these issues are leaving these companies open to a litany of potential cyber-attacks.

Related Content