4 ms·
Off your head, what is your recommendation / checklist for people running servers? He covers fail2ban as well
by simplehuman 10y ago
Off your head, what is your recommendation / checklist for people running servers? He covers fail2ban as well
- sillysaurus3 10y agoAn audit is only around $6k. If you can afford one, you should get one.
- simplehuman 10y agoYeah, I run things on my own. 6k is out of my league. I am surprised this costs so much. Can it not be automated?
- sillysaurus3 10y agoNope. It takes at least a couple months of doing daily pentests to become proficient at finding vulns. As to why it can't be automated, it takes a book to answer that. I'd recommend The Web Application Hacker's Handbook, along with The Tangled Web. There are things you can do, of course. But unless your app is basically read-only, there are almost always one or two noteworthy vulns.
- deleted 10y ago[deleted]
- dguido 10y ago$6k covers about 3 days of effort by a single security auditor, which barely scratches the surface for a large application like NextCloud. Sorry, security is expensive :-/. You can save yourself some headache by using best practices and clearing away all the low hanging fruit before contracting with an expert. For example, but deploying on HHVM, aggressively using static analysis tools and clearing up issues that lead to compiler warnings, and running external application vulnerability scans from things like local Burp Pro or the hosted Tinfoil Security.
- sillysaurus3 10y agoThe question was about people running their own webapps. $6k is a reasonable price for a smaller project.
- tptacek 10y agoThere aren't many non-brochure-ware applications I can imagine getting audited in 3 days. 2 person/weeks is a small app pentest project.