[Owasp-testing] editorial changes to intro

Marco M. Morana marco.m.morana at gmail.com
Thu Jul 17 07:36:06 EDT 2008


Marco

 

As I read your comments I think you reviewed the introduction of vs 2. Did
you also review the new additions on the testing methodology of vs 3. If so
I will be happy to address changes. 

 

I saw comments related to vs 3 additions of the methodology from Rick

 

Under "Developers' Security Tests" the following sentence doesn't read
clearly but I'm not 100% sure what the author was trying to say so I haven't
edited it: "A security unit testing framework might consist on a place
holder for security test cases and used to wrap the functions, methods and
classes that need to be security tested." Rick.mitchell 11:06, 15 July 2008
(EDT)

 

I will change the text and simplify and elaborate.

 

Also for the other parts that you addressed:

Questions: 

*	Is there a format for citations/references? 
*	Threat modeling in Testing Techniques Explained refers to a detailed
threat modeling methodology in part 2. Does this really exist? 

Open: 

*	The part on automated tools being bad at finding vulnerabilities
should probably be clarified (Mindset paragraph in principles) 

I can provide changes to address threat modeling for testing and tools being
bad to find vulnerabilities.

I think this are in vs 2 so I did not commit to change this part of my
re-writing, just let me know.

 

Regards

 

Marco

 

-----Original Message-----
From: owasp-testing-bounces at lists.owasp.org
[mailto:owasp-testing-bounces at lists.owasp.org] On Behalf Of Marco Cova
Sent: Wednesday, July 16, 2008 2:03 PM
To: owasp-testing at lists.owasp.org
Subject: [Owasp-testing] editorial changes to intro

 

Hi all.

 

I've started to do a batch of editorial changes to the intro chapter

of the testing guide. My plan is to finish with the intro by tonight,

wait for reactions, and, depending on those, back off or go on with

other sections of the guide :-)

 

The changes are mostly editorial: they try to streamline, reorganize,

and clarify the text, (mostly) without adding new content.

I'm trying to document the changes in the talk section of the page:

https://www.owasp.org/index.php/Talk:Testing_Guide_Introduction

 

Of course, feel free to ask me if you have any

questions/comments/criticism, or to revert back to the previous

version.

 

Marco

_______________________________________________

Owasp-testing mailing list

Owasp-testing at lists.owasp.org

https://lists.owasp.org/mailman/listinfo/owasp-testing

-------------- next part --------------
An HTML attachment was scrubbed...
URL: https://lists.owasp.org/pipermail/owasp-testing/attachments/20080717/2f7845e6/attachment.html 


More information about the Owasp-testing mailing list