Security certificates for Programming

krwell

Senior member
Feb 11, 2001
454
0
0
Hey guys I'm a programmer and with all the talk about security and all the jobs being shipped overseas I thought it would be best if I learned everything I could about security in code and programs. Any good places to start or anything good to learn?
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
First thing is to make sure you never buy the book "Writing Secure Code" by Microsoft Press...
 

Barnaby W. Füi

Elite Member
Aug 14, 2001
12,343
0
0
Zing!

I dunno about certificates, but there's lots of good info on the web, and at least one book I can remember hearing about.
 

Descartes

Lifer
Oct 10, 1999
13,968
2
0
I would start with The Sans Reading Room. There are countless other resources as BBWF said, but SANS should give you a starting point. "Security" is really a broad scope of knowledge, so it would be better if you picked a certain facet of particular interest and started there. For example, are you a developer or an administrator?

Originally posted by: Nothinman
First thing is to make sure you never buy the book "Writing Secure Code" by Microsoft Press...

Seriously, your myopic anti-MS drivel can be overwhelmingly annoying at times. Writing Secure Code is an absolutely fantastic book. Don't discount the works of excellent authors simply because it's published by MS Press.

 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
Seriously, your myopic anti-MS drivel can be overwhelmingly annoying at times. Writing Secure Code is an absolutely fantastic book. Don't discount the works of excellent authors simply because it's published by MS Press.

You need a better sense of humor then. It was a joke without the trailing I don't even know if the author works at MS other than as a writer, I just found it amusing that they published a book on secure programming that obviously noone in their company has read.
 

Descartes

Lifer
Oct 10, 1999
13,968
2
0
Originally posted by: Nothinman
Seriously, your myopic anti-MS drivel can be overwhelmingly annoying at times. Writing Secure Code is an absolutely fantastic book. Don't discount the works of excellent authors simply because it's published by MS Press.

You need a better sense of humor then. It was a joke without the trailing I don't even know if the author works at MS other than as a writer, I just found it amusing that they published a book on secure programming that obviously noone in their company has read.

The trailing changes the semantics of the whole sentence, so I just took it at face value (pun intended).

To author an MS Press book you need not be an MS employee. A lot of the authors are just outside consultants who are commissioned to write the books. Admonish MS all you want for their past security policies (or lack thereof), but there is a concerted effort to turn things around.
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
To author an MS Press book you need not be an MS employee. A lot of the authors are just outside consultants who are commissioned to write the books.

I figured as much, just like their hardware and pretty much everything but the software they produce. It's just got their name on it.

Admonish MS all you want for their past security policies (or lack thereof), but there is a concerted effort to turn things around.

I know, I've seen Win2K3 and I was surprised at how good a job they did setting almost everything up like I usually do. Instead of 20 minutes of fixing stupid defaults it was like 2. But I still think a big problem is the ease of use they push, it makes people think they're administrators when they're really not. For instance a friend of mine recently started playing with Win2K3 and AD at home, that in itself isn't a problem but I know he did nothing more security-wise than go through the add role wizards. Just for internal AD/DHCP/DNS this isn't a problem but he spoke of trying to setup Exchange next and running a personal mail server and that has a lot more potential to be a problem.

In addition to that his Cisco DSL router has the default telnet and enable password, when I told him I could get into his router from anywhere on the Internet he said "but that's not an issue because they don't know I have a Cisco router", after I ran nmap on his router and showed him that it even displayed the model number (the new nmap OS detection code is bad ass) he didn't reply because he just don't really care. And that's a problem with a lot of MS clients, they buy the software hoping to get a quick server setup for something and don't care to set it up right. That's not MS' fault, but they make it too easy for them to setup poorly secured boxes. Atleast with Linux if you don't have the dedication to read the documentation you don't have a chance of getting it setup at all =)
 

krwell

Senior member
Feb 11, 2001
454
0
0
I'm looking for more security in being a software developer, not a network admin.
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
I'm looking for more security in being a software developer, not a network admin.

I know, the book were were talking about originally was a programming book, I just got off on a tangent.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |