Waraxe IT Security Portal
Login or Register
November 21, 2024
Menu
Home
Logout
Discussions
Forums
Members List
IRC chat
Tools
Base64 coder
MD5 hash
CRC32 checksum
ROT13 coder
SHA-1 hash
URL-decoder
Sql Char Encoder
Affiliates
y3dips ITsec
Md5 Cracker
User Manuals
AlbumNow
Content
Content
Sections
FAQ
Top
Info
Feedback
Recommend Us
Search
Journal
Your Account
User Info
Welcome, Anonymous
Nickname
Password
(Register)

Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144

People Online:
Visitors: 156
Members: 0
Total: 156
Full disclosure
SEC Consult SA-20241112-0 :: Multiple vulnerabilities in Siemens Energy Omnivise T3000 (CVE-2024-38876, CVE-2024-38877, CVE-2024-38878, CVE-2024-38879)
Security issue in the TX Text Control .NET Server for ASP.NET.
SEC Consult SA-20241107-0 :: Multiple Vulnerabilities in HASOMED Elefant and Elefant Software Updater
Unsafe eval() in TestRail CLI
4 vulnerabilities in ibmsecurity
32 vulnerabilities in IBM Security Verify Access
xlibre Xnest security advisory & bugfix releases
APPLE-SA-10-29-2024-1 Safari 18.1
SEC Consult SA-20241030-0 :: Query Filter Injection in Ping Identity PingIDM (formerly known as ForgeRock Identity Management) (CVE-2024-23600)
SEC Consult SA-20241023-0 :: Authenticated Remote Code Execution in Multiple Xerox printers (CVE-2024-6333)
APPLE-SA-10-28-2024-8 visionOS 2.1
APPLE-SA-10-28-2024-7 tvOS 18.1
APPLE-SA-10-28-2024-6 watchOS 11.1
APPLE-SA-10-28-2024-5 macOS Ventura 13.7.1
APPLE-SA-10-28-2024-4 macOS Sonoma 14.7.1
Log in Register Forum FAQ Memberlist Search
IT Security and Insecurity Portal

www.waraxe.us Forum Index -> Suggestions -> Why do not you give away hack proven certificates ?
Post new topicReply to topic View previous topic :: View next topic
Why do not you give away hack proven certificates ?
PostPosted: Mon May 26, 2008 8:34 pm Reply with quote
Snoop1990
Advanced user
Advanced user
Joined: May 22, 2008
Posts: 65




After testing my webspace, you remember here, I was just thinking if it is possible to get some certificate. You know it seems to be a trusted side if I have something to show of. Therefore I guess it would be easy for you to write a script that checks some basic stuff, like you told me. Then if everything is ok, you can give away a certificate, which contains a link to your page. You get more visitors and my visitors know that my page is secure. Sounds like a nice deal doesn't it ?

After reading some topics on this board I am quite convinced that you know a lot about security. And I guess it isn't too difficult to write such a script.

Or even better, you just write this php script. Then the customer place this file on the server and a link on his / her page and if all is configured right a waraxe icon appears and says the page is secure. And if the people click at the link they get the results on a special page and there is a link to your page so people can read more about security.

That's just an idea but as I explained I think it shouldn't be too difficult for you to do and having more traffic is what everybody likes Very Happy

Regrades Snoop1990

_________________
http://snoop1990.co.cc

"I don't hack, I only surf the web to search for security holes ! To prevent my clients and me from being hacked !"
View user's profile Send private message Visit poster's website
PostPosted: Mon May 26, 2008 8:54 pm Reply with quote
lenny
Valuable expert
Valuable expert
Joined: May 15, 2008
Posts: 275




Like to hackersafe logo? That is a pretty good idea, but really Waraxe is not reputable enough to be considered a safe source. The idea behind the certificates it to prove to customers that the site they are using is safe - If the customers don't consider Waraxe a reputable source (possibly they have never heard about Waraxe? Countless possibilities) then the logo become useless. Still a good idea though, and I would certainly want my site to be certified Smile
View user's profile Send private message
PostPosted: Mon May 26, 2008 9:00 pm Reply with quote
Snoop1990
Advanced user
Advanced user
Joined: May 22, 2008
Posts: 65




If I take a look at those web users I know there are some who really know about such stuff but a lot would be pleased to see a symbol that shows this side is hack proofed. And as I pointed out it is not that much work to do and the more popular waraxe gets the more people would like to get such a certificate. Just think about it, it's just an idea ! a Suggestion !

_________________
http://snoop1990.co.cc

"I don't hack, I only surf the web to search for security holes ! To prevent my clients and me from being hacked !"
View user's profile Send private message Visit poster's website
PostPosted: Mon May 26, 2008 9:14 pm Reply with quote
waraxe
Site admin
Site admin
Joined: May 11, 2004
Posts: 2407
Location: Estonia, Tartu




It can be something like "Waraxe was here" Smile
Because serious security audit is something very different from those "Hacker Safe" scannings and stuff:

http://www.wbshop.com/

Look the sign upper left - "Hacker Safe" Smile
By the way most of those "safe" websites actually contain esasy-to-spot security holes and that everyday scanner will not find anything unusual Smile
This is more like for customer assurance - buy from us, we are secure, your CC numbers will not get stolen Wink
View user's profile Send private message Send e-mail Visit poster's website
PostPosted: Mon May 26, 2008 9:18 pm Reply with quote
Snoop1990
Advanced user
Advanced user
Joined: May 22, 2008
Posts: 65




I know that a side can never be 100% secure but customers believe in things like this. So if you could write such a script, that does your general tests I would be very pleased to place it on my side.

_________________
http://snoop1990.co.cc

"I don't hack, I only surf the web to search for security holes ! To prevent my clients and me from being hacked !"
View user's profile Send private message Visit poster's website
PostPosted: Mon May 26, 2008 9:32 pm Reply with quote
waraxe
Site admin
Site admin
Joined: May 11, 2004
Posts: 2407
Location: Estonia, Tartu




Good security means dedicated server, this is first what's important. Then you need professional admin, who can manage, update, secure and configure server or servers 24/7, analyze logs, etc. Without such measures there will be not even 90% security ...
View user's profile Send private message Send e-mail Visit poster's website
PostPosted: Mon May 26, 2008 9:47 pm Reply with quote
Snoop1990
Advanced user
Advanced user
Joined: May 22, 2008
Posts: 65




for sure the certificate is nearly unnecessary but, look what I want to say there are a lot of people on the web who have no idea about security they may use a firewall but they haven't configured it, it is just like it came. Those people trust in such things.

For sure I can also place a link on my page to support you, but it would be much "cooler" to have a certificate that says "hack proved". And if I place such a thing on my side maybe some of my friends also want to place it on their side and you know it goes on and on and on.

The more people use your side the more popular you get and maybe you earn some money with some advertisement.

What I just want to say, it is worst trying it for somebody who knows that much about security like you do. That's what everybody does! It is a matter of fact that there is never total security or even high level security on a shared host. But it doesn't matter, it is just important to prove the security you have and to show that you have proved it.

You can also add a disclaimer explaining what tests your script does and that having your certificate only means the side is protected dude to php scripting or what so ever ...

At the moment it's Lenny and me who like to place such a certificate on their page but I guess others will follow. Just try !

_________________
http://snoop1990.co.cc

"I don't hack, I only surf the web to search for security holes ! To prevent my clients and me from being hacked !"
View user's profile Send private message Visit poster's website
PostPosted: Tue May 27, 2008 4:41 am Reply with quote
pexli
Valuable expert
Valuable expert
Joined: May 24, 2007
Posts: 665
Location: Bulgaria




waraxe wrote:
Good security means dedicated server, this is first what's important. Then you need professional admin, who can manage, update, secure and configure server or servers 24/7, analyze logs, etc. Without such measures there will be not even 90% security ...


A'm not agree for dedic server's.Sometime's (about 90%) hosting keep's in database critical info for dedicated server's(root,ftp,mysql ....etc),but if you have more money for hosting,buy server and store there.colocation.Then you just need good admin do everything you write. Laughing

P.S.This with "Waraxe was here" is very stupid.Only big LaMeRs do that. Laughing Laughing Laughing Laughing Laughing
View user's profile Send private message
PostPosted: Tue May 27, 2008 10:00 am Reply with quote
waraxe
Site admin
Site admin
Joined: May 11, 2004
Posts: 2407
Location: Estonia, Tartu




"Waraxe was here" is just ironical joke Smile
View user's profile Send private message Send e-mail Visit poster's website
PostPosted: Tue May 27, 2008 11:08 am Reply with quote
pexli
Valuable expert
Valuable expert
Joined: May 24, 2007
Posts: 665
Location: Bulgaria




waraxe wrote:
"Waraxe was here" is just ironical joke Smile


Я понял дружище.Smile
View user's profile Send private message
PostPosted: Sat May 31, 2008 11:39 am Reply with quote
Snoop1990
Advanced user
Advanced user
Joined: May 22, 2008
Posts: 65




Can you please speak english so we all understand it ? please !

_________________
http://snoop1990.co.cc

"I don't hack, I only surf the web to search for security holes ! To prevent my clients and me from being hacked !"
View user's profile Send private message Visit poster's website
Why do not you give away hack proven certificates ?
www.waraxe.us Forum Index -> Suggestions
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT
Page 1 of 1

Post new topicReply to topic


Powered by phpBB © 2001-2008 phpBB Group



Space Raider game for Android, free download - Space Raider gameplay video - Zone Raider mobile games
All logos and trademarks in this site are property of their respective owner. The comments and posts are property of their posters, all the rest (c) 2004-2024 Janek Vind "waraxe"
Page Generation: 0.039 Seconds