الأربعاء، 3 أغسطس 2016

لقاء مع مع الخبير الأمني بنجامين كونز ميجري

في لقاء حصري مع الباحث الامني الالماني بينجامين كونز ميجري نظمه الباحث الامني لورانس عامر بالتعاون مع مجتمع الامن المعلوماتي كنا قد طرحنا جملة من الاسئلة تتعلق بالمختبر الأمني  Vulnerability Lab للتعامل مع الثغرات الامنية في المواقع والمؤسسات الحكوميه على مستوى العالم .
1. Who is the CEO Founder ?
The founder of the program is the ceo of the Evolution Security Gmbh
Benjamin Kunz Mejri.
1. من هو المسؤول الاول عن المشروع الجديد ؟
الفكرة والمشروع من بادارة بنجامين كونز ميجاري والذي يعتبر أيضا المدير التنفيذي لشركة الامن والحماية ايفالوشن سيكيورتي http://ift.tt/2aQLQ34

2. Description about purpose of Government Laboratory?
The government laboratory was build to successful track and identify
unknown vulnerabilities in government or military institute.
Thus was we safe important infrastructures and companies of different
governments independently. The gov lab represents the private sector of
the public industry.
ماهو الهدف من مشروع Gov Lab ؟
المشروع بالبناء الاساسي وجد لمعالجة ومتابعة تقارير الثغرات الامنية الغير معروفة مسبقا في المؤسسات الحكومية والعسكرية كما ان المختبر الامني يتابع الثغرات الامنية بشكل سري دون شرح تفاصيل الثغرة الامنية للعموم كما ان المختبر الامني يتابع الثغرات الامنيه بشكل سري دون شرح تفصيل الثغره الامنيه للعموم 

3. How can Hackers join the Government Laboratory?
Mainly by interaction via disclosure of vulnerabilities or own bug
reports. People with technical knowledge are allowed to participate in
the program.
We do only accept parent managers with a minimum age 18+ or 21+.
Everybody that can report own vulnerabilities is welcome to the
government laboratory.
كيف يستطيع الهاكرز الانظمام الى المختبر الامني  Gov Lab ؟
الباب مفتوح لجميع الهاكرز من خلال الالتزام بتقديم تقارير امنية صحيحة .
يشترط ان يكون الباحث الامني المشارك في تقديم الثغرة الامنية لايقل عن 18 سنة ومرحب بالجميع 

4. Do you think the arabian Governments are inlcluded in this program?
The community is not limited to report vulnerabilities to western
security agencies or cert teams. We do allow everybody to report any
government vulnerability that he is able to disclose. All governments
are included to the indepdent program

هل تعتقد ان مواقع الحكومات العربية ضمن لائحة القبول في المختبر الامني ؟ 
الامر ليس محدود فقط بالموسسات الحكومية في اوروبا او الغرب بشكل عام بل ايضا لكل العالم بشكل كلي فكل المؤسسات الحكومية حول العالم يشملها المشروع

5. We discovered that there is an official name under team section, can
you please clarify to us what's conditions?
Representatives of the community are listed in the team pages. These
managers are marked as trusted by several reports and interaction.
To become a representative you need to be a responsible and active
person to the government laboratory infrastructure.

من خلال تصفحنا بالموقع الرسمي للمختبر لاحظنا وجود قسم خاص بالفريق القائم ضمن الموقع ؟ هل تستطيع شرح لنا ماهي الشروط المطلوبة لاعضاء الفريق؟
كل من الباحثين الامنين الموجودين ضمن قسم الفريق يمثلون باحثين امنين موثوقين من خلال الاشتراك وتقديم العديد من التقارير الامنية . ولكي تصبح احد الاعضاء عليك ان تكون مسؤول بالدرجة الاولى وفعال ضمن المختبر الامني 

6. is there a private Community to discusse finding issue.? or only
through Email messgaing?
There is a private leader board community but as well internal teams
that communicate to each other during there tests, verification or
reproduces.
We do as well use rsa encrypted email communication via pgp to ensure
the conversations stay permanently private.

هل هنالك مجتمع خاص محدد للنقاش حول الثغرات الامنية او فقط من خلال البريد الالكتروني ؟
هناك لوحه خاصة للباحث الامني لتقديم التقارير بالاضافة الى ان هناك فريق داخلي لمعالجة الاختبارات وتوثيق الثغرات الامنية كما ان نحرص عن وجود تسفير جميع الرسائل البريدية الواردة والصادرة بتشفير RSA

7. How much time takes to handle a reported issue via Gov Lab ?
Depends on the manufacturers. We handle the reports, form advisories and
transfer them to the responsible contacts. After that it can take 1 week
up to some month since the issues are reproduced by the externals or
patched by manufacturers in-house developers.
ماهي المده لمعالجة الثغرات الامنية المكتشفة والمرسلة الى المختبر ؟
يعتمد هذا لامر على المؤسسة نحن نقوم بمتابعة التقارير من الباحث الامني ثم نقوم بارسالها الى جهات الاتصال الموثوقة ضمن المؤسسة بعد ذلك يتوقع ان تاخذ مدة اسبوع الى حد الشهر بعد توثيق الثغرة الامنية من الفريق الامني او طرح اصلاح للثغرة الامنية

9. what are the most important even Gov Lab occupies cross world wide ?
Government Laboratory is the first public prototype with transparent
model for independent security researchers. The goal for the community
is to become more aware of problems with the government cyber security,
disclosure own vulnerabilities by references to teach others and to
protect the public or industry.
 ماهو الحدث الاهم ضمن المختبر الامني Gov Lab ؟
يعتبر موقع  الاول عالميا في هذا المجال الهدف من ذلك هو طرح المشاكل الامنية ضمن مواقع الحكومات الالكترونية لحماية المؤسسة ولتعليم الاخرين عن ذلك.


Source مجتمع الأمن المعلوماتي : دليلك الأول نحو الحماية | Secomunity http://ift.tt/2aSfl4V

0 التعليقات:

إرسال تعليق

Twitter Delicious Facebook Digg Stumbleupon Favorites More