<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0"
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>PHP Security Blog - Standards</title>
    <link>http://blog.php-security.org/</link>
    <description></description>
    <dc:language>en</dc:language>
    <admin:errorReportsTo rdf:resource="mailto:" />
    <generator>Serendipity 3.1.4159 - http://www.s9y.org/</generator>
    
    <image>
        <url>http://blog.php-security.org/layout/default/img/s9y_banner_small.png</url>
        <title>RSS: PHP Security Blog - Standards - </title>
        <link>http://blog.php-security.org/</link>
        <width>100</width>
        <height>21</height>
    </image>
<item>
    <title>OWASP Risk Evaluation</title>
    <link>http://blog.php-security.org/archives/81-OWASP-Risk-Evaluation.html</link>
<category>PHP</category><category>Security</category><category>Standards</category>    <comments>http://blog.php-security.org/archives/81-OWASP-Risk-Evaluation.html#comments</comments>
    <wfw:comment>http://blog.php-security.org/wfwcomment.php?cid=81</wfw:comment>
    <slash:comments>5</slash:comments>
    <wfw:commentRss>http://blog.php-security.org/rss.php?version=2.0&amp;type=comments&amp;cid=81</wfw:commentRss>

    <author>blog-admin@nopiracy.de (Stefan Esser)</author>
    <content:encoded>
&lt;br /&gt;
When you read the &lt;a href=&quot;http://www.owasp.org/index.php/How_to_value_the_real_risk&quot;&gt;OWASP risk evaluation standard&lt;/a&gt; carefully you might get as confused as I got. They estimate the risk by first estimating the likelihood and then estimating the technical and business impact. The estimation is done by assigning the numbers 0..9 to a number of factors.&lt;p&gt;&lt;br /&gt;So far so good. Most of it makes perfect sense, but I was a little bit confused about the following factor:&lt;/p&gt;&lt;dl&gt;&lt;dt&gt;&lt;b&gt; Opportunity&lt;/b&gt;&lt;br /&gt;
&lt;/dt&gt;&lt;dd&gt; What resources and opportunity are required for this group of&lt;br /&gt;
attackers to find and exploit this vulnerability? No access or special&lt;br /&gt;
resources (0), limited access and resources (4), special access or&lt;br /&gt;
resources (7), full access or expensive resources (9)&lt;/dd&gt;&lt;/dl&gt;&lt;p&gt;&lt;br /&gt;
According to this factor the likelihood of an attack increases when more access to the application and more expensive resources are required on the attacker's side. I dare to doubt that &lt;img src=&quot;http://blog.php-security.org/layout/default/img/emoticons/smile.png&quot; alt=&quot;:-)&quot; style=&quot;display: inline; vertical-align: bottom;&quot; class=&quot;emoticon&quot; /&gt;&lt;/p&gt;    </content:encoded>
    <pubDate>Fri, 11 May 2007 14:00:00 +0000</pubDate>
    <guid isPermaLink="false">http://blog.php-security.org/archives/81-guid.html</guid>
    </item>
</channel>
</rss>
