Search Engine News
  Home arrow Search Engine News arrow Page 3 - Get Fuzzy
SEO Chat Forums  
Choosing Keywords  
Google Optimization  
Link Trading  
MSN Optimization  
Search Engine News  
Search Engine Spiders  
Search Optimization  
Web Directories  
Website Marketing  
Website Promotion  
Website Submission  
Yahoo Optimization  
SEO Tools
Adsense Calculator
AdSense Preview
Advanced Meta-Tags
Alexa Rank Tool
Check Server Headers
Class C Checker
Code to Text Ratio
CPM Calculator
Domain Age Check
Domain Typos
Future PageRank
Google Dance
Google Keywords
Google Search
Google Suggest
Google vs Yahoo
Indexed Pages
Keyword Cloud
Keyword Density
Keyword Difficulty
Keyword Optimizer
Keyword Position
Keyword Typos
Link Popularity
Link Price Calculator
Meta Analyzer
Meta Tag Generator
Multiple Link Popularity
Page Comparison
Page Size
PageRank Lookup
PageRank Search
Robots.txt Generator
ROI Calculator 
S.E. Comparison 
S.E. Keyword Position 
Site Link Analyzer 
Spider Simulator 
URL Redirect Check 
URL Rewriting 
Mobile Linux 
APP Generation ROI 
IBM® developerWorks 
SEO Weekly Newsletter
 
Developer Updates  
Free Website Content 
 RSS  Articles
 RSS  Forums
 RSS  All Feeds
Write For Us Get Paid 
Request Media Kit
Contact Us 
Site Map 
Privacy Policy 
Support 
 USERNAME
 
 PASSWORD
 
 
  >>> SIGN UP!  
  Lost Password? 
SEARCH ENGINE NEWS

Get Fuzzy
By: Michael Lowry
  • Search For More Articles!
  • Disclaimer
  • Author Terms
  • Rating: 5 stars5 stars5 stars5 stars5 stars / 3
    2007-12-05

    Table of Contents:
  • Get Fuzzy
  • Basic Techniques
  • Happening Now
  • Conclusion

  • Rate this Article: Poor Best 
      ADD THIS ARTICLE TO:
      Del.ici.ous Digg
      Blink Simpy
      Google Spurl
      Y! MyWeb Furl
    Email Me Similar Content When Posted
    Add Developer Shed Article Feed To Your Site
    Email Article To Friend
    Print Version Of Article
    PDF Version Of Article
     
     
    ADVERTISEMENT


    Get Fuzzy - Happening Now


    (Page 3 of 4 )

    As you might expect, some of the most recent fuzz testing news has to do with the Internet, specifically web browsers. Not too long ago, HD Moore, a security researcher, along with a set of colleagues used fuzzing to test the major browsers, mostly notably Internet Explorer, and found several hundred ways to make it crash. All in all, there were at least 50 defects, some of which could allow someone to gain control of a website user's Windows system. Moore and Co. found it easier to check the user applications (i.e. web browsers) than test the server itself. This also helps protect the user from the malicious websites that I mentioned earlier.

    Of course, attackers have become more innovative when it comes to attacking a network's internal system through browsers. And apparently the internal systems are more vulnerable than the well-maintained external applications. Microsoft has done its part in fixing some of the most crucial vulnerabilities in Internet Explorer, but it would be interesting to see just how far they've come to this point.

    Earlier this year, the company SPI Dynamics released a web fuzz testing tool specifically for web applications called Web Fuzz. The simplicity and ferocity with which web applications are made makes fuzz testing the ideal choice for detecting vulnerabilities, especially since they account for half of all defects. This was good news for developers because the vendors aren't likely to have their back when bugs start coming up in their apps. SPI Dynamics employee Michael Sutton describes the way fuzzing finds the simple vulnerabilities through a process called FUGGLE (Fuzzing Using Google Gets Low-hanging-fruit Easily):

    ... you can Google for sites that are going to be vulnerable to attack. Then you make a request for them using Google fuzzing to see if they could find indicators of what vulnerabilities [are there].

    The new developments in fuzz testing grow by the day, it seems. The real innovations are in the field of customized tools designed to test specific software protocol. Some companies are providing libraries of reusable code that make customizing easier without having to start over. Yes, it's a fledgling industry now, but as the web grows and developers need ways to test their apps, so too will the fuzzing industry.

    More Search Engine News Articles
    More By Michael Lowry


       · Interesting article. Thank you! It would be great if you can write about the...
       · Thank you for reading this article on fuzz testing for your website. If you have...
       · Thanks for the comment. I will definitely look into writing about some fuzz testing...
     

    SEARCH ENGINE NEWS ARTICLES

    - Google`s Living Stories: the Final Nail in t...
    - Should You Be Clocked In?
    - Assessing DMOZ: A Quality Review
    - A Search Engine that Saves the Rain Forest?
    - Collecta: Real Time Search
    - Google Real-Time Search: a Review
    - Microsoft and OpenX Team Up
    - Google`s Influence on the Internet Through i...
    - Fast Flip, Google`s New News Reading Service
    - Masterseek: a Global Business Search Engine
    - Behavioral Advertising Bill Breaks New Ground
    - Microsoft-Yahoo Deal: Where Do We Go From He...
    - The History of Search and Search Technology
    - Yahoo Closes Geocities
    - Tokoni Takes Storytelling in New Direction



     



    © 2003-2010 by Developer Shed. All rights reserved. DS Cluster 9 Hosted by Hostway
    For more Enterprise Application Development news, visit eWeek