WebApp Sec mailing list archives

Re: Web Application Penetration Testing Methodology Patent


From: "dreamwvr () dreamwvr com" <dreamwvr () dreamwvr com>
Date: Fri, 16 Jan 2004 09:38:54 -0700

1. The process to traverse a web application in order to discover and
actuate the links therein.  This is also called a web crawler.  Something
[...]
As you can see, this patent is very broad and covers everything from
security products to penetration testing.  Unless someone can develop
a way to perform web application security without violating one of the
four points mentioned above everyone is in violation of this patent.
 Obviously, such a patent gives Sanctum an unfair competitive advantage
within our market.  However, there is a way to challenge this patent.
 First and foremost is to find something that addresses all the above
points 1 year prior to when Sanctum submitted the patent.  Sanctum submitted
for the patent on March 3, 2000 so the material must be dated on or before
March 2, 1999.  If you know of something that has been made public (e.g.,
 article, posting, product, etc.) that contains all of the above elements
post your findings to the list.  A critical aspect is that is must contain
all 4 elements from above.  Anything less will not suffice.  
That's simple 'PERL' is often used for this type of application. 
This is nothing new here. PERL is the means and the method() :-)

-- 
/*  Security is a work in progress - dreamwvr                 */
#                               48 69 65 72 6F 70 68 61 6E 74 32
# Note: To begin Journey type man afterboot,man help,man hier[.]      
# 66 6F 72 20 48 69 72 65                              0000 0001
// "Who's Afraid of Schrodinger's Cat?" /var/(.)?mail/me \?  ;-]


Current thread: