|
Sunday, August 13, 2006
Book Report: How to Break Software Security by James A. Whittaker and Herbert H. Thompson (2003) After I read How to Break Software (which a quick Google check indicates I have not reviewed, gentle reader, but most of you wouldn't have read it anyway), I bought the companion volumes. This book, which I bought off of Amazon.com at its retail price, disappointed me where How to Break Software did not. Both books run off of a quick list of fault-model testing (a term I learned from the first book). I had a ball with the first book, laughing at seeing some of my favorite dirty tricks encapsulated in someone definitive's book. This book, however, didn't hold the same glee for me. The first book dealt with a broad subject and offered some very concrete things to try to attack software. This second book deals with a similarly broad subject (security testing), but is more abstract. The attacks it discusses aren't as narrow and easy to recreate; they're more methods and abstract ideas to try rather than concrete shortcuts to finding issues. I know, there's something to be said for a broad, ranging methodology, but the first book wasn't that way, and I didn't expect this one to be that way. Additionally, the book is sized similarly to the first, which doesn't allow it to go into a lot of detail for each of the abstract things it talks about. Finally, I don't know that the book focuses enough on actual security attacks; rather, it focuses on attacks that could be construed as security breaches. However, in many cases, they're not specifically security attacks, but rather regular tests that could, if applied to applications needing security, be security attacks. Maybe that's all security testing is, but this book wasn't different enough from the first book to make me wonder if it wasn't really a sequel given a better title. On the other hand, it does come with a CD and a tool which looks to be pretty cool, if I could get some professional time to play with it. So buy the first book, How to Break Software, and apply its attacks to secure software. Buy this book if you're really into it or if the company is buying it for you. |
To say Noggle, one first must be able to say the "Nah."
"I will." Heather L. Igert, angelweave.mu.nu "Genuis." Neil Steinberg, Chicago Sun-Times "Some wanker." Kim du Toit, on the Noggle Library. "Brian J. Noggle apparently forgot that the proper design for a tin foil beanie calls for the shiny side out." Robb Allen, Sharp as a Marble. "I'm weeping openly right now. Thanks for hurting my feelings, pinhead." Bob Rybarcyzk, St. Louis Post-Dispatch
Visualize World Hegemony
Cog in the Machine
Tao Sharks
Humor not displayed
Beware of Conservative April 2003 May 2003 June 2003 July 2003 August 2003 September 2003 October 2003 November 2003 December 2003 January 2004 February 2004 March 2004 April 2004 May 2004 June 2004 July 2004 August 2004 September 2004 October 2004 November 2004 December 2004 January 2005 February 2005 March 2005 April 2005 May 2005 June 2005 July 2005 August 2005 September 2005 October 2005 November 2005 December 2005 January 2006 February 2006 March 2006 April 2006 May 2006 June 2006 July 2006 August 2006 September 2006 October 2006 November 2006 December 2006 January 2007 February 2007 March 2007 April 2007 May 2007 June 2007 July 2007 August 2007 September 2007 October 2007 November 2007 December 2007 January 2008 February 2008 March 2008 April 2008 May 2008 June 2008 July 2008 August 2008 September 2008 October 2008 November 2008 December 2008 January 2009 February 2009 March 2009 April 2009 May 2009 June 2009 July 2009 | ||