|
|
|
|
|
by endymi0n
1690 days ago
|
|
While you'll probably get a good overview on the question you asked from the other comments, don't overlook that non-audit measures might give you even better bang for the buck — and that going 80% on a mix of lots of different measures will usually give you better overall effectivity than going 99.8% on just auditing. For example, putting that external software in a hardened container with network policies, non-root user, capability drops, readonly filesystem (,...) will go a long way towards securing it, even if there's a cleverly disguised backdoor you didn't manage to find. Dumping your database is only half the fun if the app isn't able to send all the data to Alonistan... |
|
The only option is to flag them as either insecure or unchecked.