in

New Glossary Term: Vulnerability

Last post 09-02-2010 10:56 PM by mkp. 2 replies.
Page 1 of 1 (3 items)
Sort Posts: Previous Next
  • 05-10-2007 10:02 AM

    • mcurphey
    • Top 10 Contributor
    • Joined on 02-13-2007
    • Europe
    • Posts 199
    • Points 2,180

    New Glossary Term: Vulnerability

    Vulnerability: A flaw or weakness in system security procedures, design, implementation, or internal controls that could be exercised (accidentally triggered or intentionally exploited) and result in a security breach or a violation of the system's security policy.

    Example: A SQL Injection vulnerability exists in the PHP Nuke application

    Example; Mac's are also susceptible to vulnerabilities don't you know ;-)

    • Post Points: 20
  • 06-25-2007 9:37 PM In reply to

    • rybolov
    • Top 10 Contributor
    • Joined on 02-13-2007
    • Washington, DC
    • Posts 149
    • Points 1,025

    Re: New Glossary Term: Vulnerability

    I'm using this for the Practical Risk Assessment Methodology:

     

    Vulnerability: A flaw or weakness in system security procedures, design, implementation, or internal controls that could be exercised (accidentally triggered or intentionally exploited) and result in a security breach or a violation of the system's security policy.

    • Example: A SQL Injection vulnerability exists in the PHP Nuke application
    • Example: Lack of a viable backup solution means that we cannot restore a server
    "Those who do not understand Unix are condemned to reinvent it, poorly."
    --Henry Spencer
    Filed under:
    • Post Points: 40
  • 09-02-2010 10:56 PM In reply to

    • mkp
    • Top 25 Contributor
    • Joined on 08-16-2010
    • Posts 5
    • Points 125

    Re: New Glossary Term: Vulnerability

    I would like to point out that I found the blog pretty interesting. It has made me familiar with the term vulnerability. Clear examples are also given which really goes a long way in conveying the idea. I would like to add something more on the SQL Injection vulnerability. It occurs most of the time when user input is incorrectly filtered or when it is not strongly typed. I think the best way to avoid this is by using parameterized statements or by carefully filtering the user input.
    • Post Points: 25
Page 1 of 1 (3 items)
All Rights Reserved - The ISM-Community
Powered by Community Server (Commercial Edition), by Telligent Systems