19.04.2013 Views

2KKUU7ita

2KKUU7ita

2KKUU7ita

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

304<br />

Part V: Hacking Applications<br />

CxDeveloper is pretty much all you need to analyze and report on vulnerabilities<br />

in your C#, Java, and mobile source code bundled into one simple<br />

package. Checkmarx, like Veracode, also offers a cloud-based source code<br />

analysis service. If you can get over any hurdles associated with uploading<br />

your source code to a third party in the cloud, these can offer a more efficient<br />

and mostly hands-free option for source code analysis.<br />

Source code analysis will often uncover different flaws than traditional web<br />

security testing. If you want the most comprehensive level of testing, do both.<br />

The extra level of checks offered by source analysis is becoming more and<br />

more important with mobile apps. These apps are often full of security holes<br />

that many newer software developers didn’t learn about in school. I cover<br />

additional mobile flaws in Chapter 10.<br />

The bottom line with web security is that if you can show your developers<br />

and quality assurance analysts that security begins with them, you can really<br />

make a difference in your organization’s overall information security.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!