<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.itworld.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>security testing</title>
 <link>http://www.itworld.com/security-testing</link>
 <description></description>
 <language>xx</language>
<item>
 <title>Vulnerability Disclosure: Is it Blackmail, Whitemail or Bluemail</title>
 <link>http://www.itworld.com/security/72334/vulnerability-disclosure-it-blackmail-whitemail-or-bluemail</link>
 <description>Hackers (or security researchers) come with a range of rainbow colored hats. Some guys&#039;n&#039;gals are nice (the White Hats). They find and disclose problems in communication products using approved responsible disclosure models. Others are in the business for money, and are not satisfied by the fame they get for disclosing problems. The process can easily get close to what some would consider unethical, or even direct blackmailing.
</description>
 <comments>http://www.itworld.com/security/72334/vulnerability-disclosure-it-blackmail-whitemail-or-bluemail#comments</comments>
 <category domain="http://www.itworld.com/career">Career</category>
 <category domain="http://www.itworld.com/security">Security</category>
 <category domain="http://www.itworld.com/software">Software</category>
 <category domain="http://www.itworld.com/opinion">Opinion</category>
 <category domain="http://www.itworld.com/security-research">security research</category>
 <category domain="http://www.itworld.com/security-testing">security testing</category>
 <category domain="http://www.itworld.com/vulnerabilities">vulnerabilities</category>
 <pubDate>Thu, 23 Jul 2009 16:25:21 -0400</pubDate>
 <dc:creator>Ari Takanen</dc:creator>
 <guid isPermaLink="false">72334 at http://www.itworld.com</guid>
</item>
<item>
 <title>Fuzzing and Product Security</title>
 <link>http://www.itworld.com/security/64502/fuzzing-and-product-security</link>
 <description>Finally, some real data on the usage of fuzzing is emerging. Who is using fuzzing? How do people see fuzzing being used in the product security process? Forrester has included questions regarding use of fuzzing in to their questionnaire that they send to key industry CIOs, CSOs and CISOs. Security companies such as Cigital are publishing their findings. I have talked with these organizations and will be discussing my findings in this blog and the upcoming webinar.
</description>
 <comments>http://www.itworld.com/security/64502/fuzzing-and-product-security#comments</comments>
 <category domain="http://www.itworld.com/security">Security</category>
 <category domain="http://www.itworld.com/best-practice">Best practice</category>
 <category domain="http://www.itworld.com/analyst">analyst</category>
 <category domain="http://www.itworld.com/fuzzing">fuzzing</category>
 <category domain="http://www.itworld.com/penetration-testing">penetration testing</category>
 <category domain="http://www.itworld.com/qa">QA</category>
 <category domain="http://www.itworld.com/research">research</category>
 <category domain="http://www.itworld.com/security-testing">security testing</category>
 <pubDate>Wed, 18 Mar 2009 04:40:30 -0400</pubDate>
 <dc:creator>Ari Takanen</dc:creator>
 <guid isPermaLink="false">64502 at http://www.itworld.com</guid>
</item>
</channel>
</rss>
