Attacking Is Easy, Defending Is Hard

No ratings

Presented at OWASP BeNelux 2010 by

An attacker has an easy job. They need only find one security hole, and they've broken the system. The system, application and network administrators :have a much harder task. They have to find not just one, but each and every one of the holes. Preferably before the bad guys do. And, these holes can be at several different layers. In the presentation, we will look at those layers (system level, application level, but also user :level) and observe what goes wrong and how to fix it. The observations come from the daily work at Madison Gurkha. Examples of problems are lack of patches, problems during the development phase, susceptibility to social engineering attacks and more.