<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.itworld.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>fuzzing</title>
 <link>http://www.itworld.com/fuzzing</link>
 <description></description>
 <language>xx</language>
<item>
 <title>Fuzzing and Product Security</title>
 <link>http://www.itworld.com/security/64502/fuzzing-and-product-security</link>
 <description>Finally, some real data on the usage of fuzzing is emerging. Who is using fuzzing? How do people see fuzzing being used in the product security process? Forrester has included questions regarding use of fuzzing in to their questionnaire that they send to key industry CIOs, CSOs and CISOs. Security companies such as Cigital are publishing their findings. I have talked with these organizations and will be discussing my findings in this blog and the upcoming webinar.
</description>
 <comments>http://www.itworld.com/security/64502/fuzzing-and-product-security#comments</comments>
 <category domain="http://www.itworld.com/security">Security</category>
 <category domain="http://www.itworld.com/best-practice">Best practice</category>
 <category domain="http://www.itworld.com/analyst">analyst</category>
 <category domain="http://www.itworld.com/fuzzing">fuzzing</category>
 <category domain="http://www.itworld.com/penetration-testing">penetration testing</category>
 <category domain="http://www.itworld.com/qa">QA</category>
 <category domain="http://www.itworld.com/research">research</category>
 <category domain="http://www.itworld.com/security-testing">security testing</category>
 <pubDate>Wed, 18 Mar 2009 04:40:30 -0400</pubDate>
 <dc:creator>Ari Takanen</dc:creator>
 <guid isPermaLink="false">64502 at http://www.itworld.com</guid>
</item>
<item>
 <title>Fuzzing Is Still Widely Unknown</title>
 <link>http://www.itworld.com/security/61015/fuzzing-still-widely-unknown</link>
 <description>Based on a recent study by Gary McGraw and other well known security gurus, all major product security teams apparently use fuzzing. But most (even security specialists) still seem to misunderstand what fuzzing really is about. Enter the world of fuzzing!
</description>
 <comments>http://www.itworld.com/security/61015/fuzzing-still-widely-unknown#comments</comments>
 <category domain="http://www.itworld.com/development">Development</category>
 <category domain="http://www.itworld.com/endpoint-security">Endpoint security</category>
 <category domain="http://www.itworld.com/internet">Internet</category>
 <category domain="http://www.itworld.com/mobile-wireless">Mobile &amp;amp; wireless</category>
 <category domain="http://www.itworld.com/networking">Networking</category>
 <category domain="http://www.itworld.com/operating-systems">Operating systems</category>
 <category domain="http://www.itworld.com/security">Security</category>
 <category domain="http://www.itworld.com/software">Software</category>
 <category domain="http://www.itworld.com/opinion">Opinion</category>
 <category domain="http://www.itworld.com/fuzzing">fuzzing</category>
 <category domain="http://www.itworld.com/security-0">security</category>
 <category domain="http://www.itworld.com/testing">testing</category>
 <category domain="http://www.itworld.com/voip">voip</category>
 <pubDate>Mon, 19 Jan 2009 09:18:25 -0500</pubDate>
 <dc:creator>Ari Takanen</dc:creator>
 <guid isPermaLink="false">61015 at http://www.itworld.com</guid>
</item>
<item>
 <title>VoIP Still Not Ready For Carrier-Grade Networks</title>
 <link>http://www.itworld.com/security/55563/voip-still-not-ready-carrier-grade-networks</link>
 <description>After a quick tour of some Really Talented Groups dedicated to fuzzing research, I noticed three things: 1) Most teams are focused on fuzzing VoIP 2) Most if not all VoIP devices still break with fuzzing 3) Most VoIP vendors still do not get it. The tour continues...
</description>
 <comments>http://www.itworld.com/security/55563/voip-still-not-ready-carrier-grade-networks#comments</comments>
 <category domain="http://www.itworld.com/development">Development</category>
 <category domain="http://www.itworld.com/internet">Internet</category>
 <category domain="http://www.itworld.com/mobile-wireless">Mobile &amp;amp; wireless</category>
 <category domain="http://www.itworld.com/networking">Networking</category>
 <category domain="http://www.itworld.com/security">Security</category>
 <category domain="http://www.itworld.com/data-center">Server and data center</category>
 <category domain="http://www.itworld.com/software">Software</category>
 <category domain="http://www.itworld.com/opinion">Opinion</category>
 <category domain="http://www.itworld.com/book">book</category>
 <category domain="http://www.itworld.com/fuzzing">fuzzing</category>
 <category domain="http://www.itworld.com/security-0">security</category>
 <category domain="http://www.itworld.com/testing">testing</category>
 <category domain="http://www.itworld.com/voip">voip</category>
 <pubDate>Thu, 02 Oct 2008 13:22:42 -0400</pubDate>
 <dc:creator>Ari Takanen</dc:creator>
 <guid isPermaLink="false">55563 at http://www.itworld.com</guid>
</item>
<item>
 <title>(Is There) Motivation for VoIP Fuzzing</title>
 <link>http://www.itworld.com/security/54688/there-motivation-voip-fuzzing</link>
 <description>What have we learned during these six or so years of proactive security work with VoIP fuzzing? Here is my top ten discoveries.
</description>
 <comments>http://www.itworld.com/security/54688/there-motivation-voip-fuzzing#comments</comments>
 <category domain="http://www.itworld.com/networking">Networking</category>
 <category domain="http://www.itworld.com/security">Security</category>
 <category domain="http://www.itworld.com/opinion">Opinion</category>
 <category domain="http://www.itworld.com/fuzzing">fuzzing</category>
 <category domain="http://www.itworld.com/security-0">security</category>
 <category domain="http://www.itworld.com/telecommunications-0">telecommunications</category>
 <category domain="http://www.itworld.com/testing">testing</category>
 <category domain="http://www.itworld.com/voip">voip</category>
 <pubDate>Thu, 04 Sep 2008 03:06:57 -0400</pubDate>
 <dc:creator>Ari Takanen</dc:creator>
 <guid isPermaLink="false">54688 at http://www.itworld.com</guid>
</item>
<item>
 <title>VoIP security auditing is becoming more and more complex ... Not!</title>
 <link>http://www.itworld.com/security/54291/voip-security-auditing-becoming-more-and-more-complex-not</link>
 <description>I am curious how people can conduct penetration tests of a complex VoIP system when they barely understand how VoIP infrastructure works. Today, security people are still stuck to auditing practices from 1990s. When asked to do a penetration test, a consultant often is only looking at past issues that can be detected using various vulnerability scanners. Very few of them know that vulnerability scanners have extremely bad coverage of vulnerabilities in VoIP solutions. And even if the tools did know VoIP, who really cares about past issues that might have been relevant several years ago. 
</description>
 <comments>http://www.itworld.com/security/54291/voip-security-auditing-becoming-more-and-more-complex-not#comments</comments>
 <category domain="http://www.itworld.com/networking">Networking</category>
 <category domain="http://www.itworld.com/security">Security</category>
 <category domain="http://www.itworld.com/opinion">Opinion</category>
 <category domain="http://www.itworld.com/fuzzing">fuzzing</category>
 <category domain="http://www.itworld.com/security-0">security</category>
 <category domain="http://www.itworld.com/testing">testing</category>
 <category domain="http://www.itworld.com/tool">tool</category>
 <category domain="http://www.itworld.com/voip">voip</category>
 <pubDate>Fri, 15 Aug 2008 07:14:58 -0400</pubDate>
 <dc:creator>Ari Takanen</dc:creator>
 <guid isPermaLink="false">54291 at http://www.itworld.com</guid>
</item>
</channel>
</rss>
