List Info

Thread: SoC 2008 suggestion : Security audit




SoC 2008 suggestion : Security audit
user name
2008-03-01 04:18:13
So I was perusing the SANS RISK report, as you do, and
I noticed quite 
a few vulnerabilities listed for Joomla - a popular php
based "Content 
management and web application framework"

http://tinyurl.com/24wf3f

One of the selling points for Bricolage is that we don't try
to be a 
delivery system so it's much easier to secure a Bricolage
instance from 
unauthorised visitors. With Joomla being a delivery system
too, it's 
impossible to do this so it is inherently more vulnerable.

However, I wondered if it might be an interesting project
for a student 
interested in security to audit Bricolage, in a structured
& rigorous 
way and ideally fix any problems that are found.

Thoughts?

Simon.

-- 
Digital Craftsmen Ltd
Exmouth House, 3 Pine Street, bond. EC1R 0JH
t 020 7183 1410 f 020 7099 5140 m 07951 758698
w http://www.digitalcr
aftsmen.net/

Re: SoC 2008 suggestion : Security audit
user name
2008-03-01 18:42:29
On Mar 1, 2008, at 02:18, Simon Wilcox wrote:

> However, I wondered if it might be an interesting
project for a  
> student interested in security to audit Bricolage, in a
structured &  
> rigorous way and ideally fix any problems that are
found.
>
> Thoughts?

Wanna mentor it?

David

Re: SoC 2008 suggestion : Security audit
user name
2008-03-04 02:41:42
David E. Wheeler wrote:
> On Mar 1, 2008, at 02:18, Simon Wilcox wrote:
> 
>> However, I wondered if it might be an interesting
project for a 
>> student interested in security to audit Bricolage,
in a structured & 
>> rigorous way and ideally fix any problems that are
found.
>>
>> Thoughts?
> 
> Wanna mentor it?

Yep. Happy to give it a go.

S.

-- 
Digital Craftsmen Ltd
Exmouth House, 3 Pine Street, bond. EC1R 0JH
t 020 7183 1410 f 020 7099 5140 m 07951 758698
w http://www.digitalcr
aftsmen.net/

[1-3]

about | contact  Other archives ( Real Estate discussion Medical topics )