Poll
Should software vendors reward independent researchers for finding vulnerabilities in their software?
Projects
-
Proactive Security Challenge
Proactive Security Challenge is a project of testing Windows security products that implement application-based security – i.e. most of the Internet security suites, HIPS, personal firewalls, behavior blockers etc. Proactive Security Challenge combines the easy and fast testing approach with the depth of the detailed analyses. Proactive Security Challenge allows us to compare tens of products and still cover many of the most important features of this kind of software.
-
Security Software Testing Suite
Security Software Testing Suite is a set of tools used for testing products suitable for Proactive Security Challenge. Most of the tests performed in Proactive Security Challenge are included in Security Software Testing Suite. All tests of this suite are published with their full source codes, this makes the testing transparent as much as possible. A non-commercial personal use of this suite is free of charge.
-
BSODhook
BSODhook (aka Kernel hooks probing tool) helps finding improper validation bugs in drivers that implement kernel mode hooks. It consists of two parts, the native SSDT call checker (original BSODhook) and the GDI SSDT call checker (codenamed ShadowHook). The tool calls system services and attempts to produce a system crash (bugcheck), which it catches with its kernel driver and reports validation bug in the tested software.
-
Nmap Online
Nmap Online is a handy service for all people who are directly connected to the Internet and want to be sure that their inbound firewall rules are setup correctly. It can be also very useful for administrators of smaller servers who deal with configurations of their firewalls. Nmap Online allows you to perform a scan of your computer using the popular Nmap Security Scanner. The service is free and can be used immediately, no registration is required.