lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <AE7A8CA5427F43349FD2927AE721D8AC@gw1>
Date: Mon, 8 Sep 2008 22:43:17 +0300
From: "Valery Marchuk" <tecklord@...uritylab.ru>
To: <full-disclosure@...ts.grok.org.uk>
Subject: WASC Announcement: 2007 Web Application Security
	Statistics Published

The Web Application Security Consortium (WASC) is pleased to announce
the WASC Web Application Security Statistics Project 2007. This
initiative is a collaborative industry wide effort to pool together
sanitized website vulnerability data and to gain a better understanding
about the web application vulnerability landscape.


Goals
1. Identify the prevalence and probability of different vulnerability 
classes
2. Compare testing methodologies against what types of vulnerabilities they
   are likely to identify.


The statistics was compiled from web application security assessment 
projects
which were made by the following companies in 2007 (in alphabetic order):


- Booz Allen Hamilton
- BT
- Cenzic with Hailstorm and ClickToSecure
- dblogic.it
- HP Application Security Center with WebInspect
- Positive Technologies with MaxPatrol
- Veracode with Veracode Security Review
- WhiteHat Security with WhiteHat Sentinel


The overall statistics includes analysis results of 32,717 sites and
69,476 vulnerabilities of different degrees of severity. The detailed
information can be found here:


http://www.webappsec.org/projects/statistics/


If you represent an organization that performs vulnerability assessments
on websites, particular in those in custom web applications, through a
manual or automated process and would like to participate please let us
know. Please contact Sergey Gordeychik (statistics_at_webappsec.org).


Regards,
- statistics_at_webappsec.org
http://www.webappsec.org/ The Web Application Security Consortium




_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ