Friday, September 8, 2017

Why is port scanning useful?

“Ports are the point from where information goes in and out of any system. Scanning of the ports to find out any loop holes in the system are known as Port Scanning. There can be some weak points in the system to which hackers can attack and get the critical information. These points should be identified and prevented from any misuse. Following are the types of port scans:
  1. Strobe: Scanning of known services.
  2. UDP: Scanning of open UDP ports
  3. Vanilla: In this scanning, the scanner attempts to connect to all 65,535 ports.
  4. Sweep: The scanner connects to the same port on more than one machine.
  5. Fragmented packets: The scanner sends packet fragments that get through simple packet filters in a firewall
  6. Stealth scan: The scanner blocks the scanned computer from recording the port scan activities.
  7. FTP bounce: The scanner goes through an FTP server in order to disguise the source of the scan.” (Shinde, 2015)
---------
§  Why would attackers scan systems and networks?
The primary step in any successful attack is sniffing, used to see what type of traffic is being passed on a network and to look for things like passwords, credit card numbers, and so forth. Port scanning can find system vulnerabilities—but they take different approaches. Sniffing is used by an attacker already on the network who wants to gather more information about the network. Port scanning is used by someone who is interested in finding vulnerabilities on a system that is unknown. (Liska, 2003)
--------
§  Why would security analysts scan systems and networks?

Discovery holes before somebody else does at any given time, attackers are employing any number of automated tools and network attacks watching for ways to penetrate systems. Only a minority of those people will have access to 0-day exploits, most will be using well known (and hence preventable) attacks and exploits. Penetration testing provides IT management with a view of their network from a malevolent point of view. The objective is that the penetration tester will find ways into the network so that they can be fixed before someone with less than honorable intentions discovers the same holes. In a sense, think of a Penetration Test as an annual medical physical. Even if you believe you are healthy, your physician will run a series of tests (some old and some new) to detect dangers that have not yet developed symptoms. (Insitute, 2006)

§  Why is enumeration useful?

“Enumeration involves listing and identifying the specific services and resources that a target offers. You perform enumeration by starting with a set of parameters, such as an IP address range, or a specific domain name system (DNS) entry, and the open ports on the system. Your goal for enumeration is a list of services which are known and reachable from your source. From those services, you move further into the scanning process, including security scanning and testing, the core of penetration testing. Terms such as banner grabbing and fingerprinting fall under the category of enumeration.” (Faircloth, 2011)


§  Why would security analysts use password cracking tools?
To test if the current password from the firm analyzed is secure and following the right policy.


§  How would attackers cover their tracks?
§  “Covering Tracks in the previous phases penetration tester or attacker often made significant changes to the compromised systems to exploit the systems or to gain administrative rights. This is the final stage in penetration test in which an attack clears all the changes made by himself in the compromised systems and returns the system and all compromised hosts to the precise configurations as they are before conducting penetration test.” (Narwal & Gupta, 2015)

§  How is privilege escalation used?
Programming errors in privileged services can result in system compromise allowing an adversary to gain unauthorized privileges. Privilege separation is a concept that allows parts of an application to run without any privileges at all. Programming errors in the unprivileged part of the application cannot lead to privilege escalation. As a proof of concept, we implemented privilege separation in OpenSSH and show that past errors that allowed system compromise would have been contained with privilege separation. There is no performance penalty when running OpenSSH with privilege separation enabled.” (Provos, 2002)


§  How can an organization protect itself and when can it do so? When is it not possible?

Some firewalls use "adaptive behavior," which means they will block previously open and closed ports if a suspect IP address is probing them. They can also be configured to alert administrators if they detect connection requests across a broad range of ports from a single host. However, hackers can get around this protection by conducting the port scan in strobe or stealth mode. In strobe mode, hackers can only scan a small number of ports at a time, but in stealth mode, they can scan the ports over a much longer period, which reduces the chance that the firewall will activate an alert.
In order to decide whether your computer is at risk, you should find out what an attacker would see in a port scan of your router. You could do this using Nmap, a free port scanner that hackers often use. Once you find out what ports respond as being open on your computer, you can review whether it's actually necessary for those ports to be accessible from outside your network. If they're not necessary, you should shut them down or block them. If they are necessary, you can begin to research what sorts of vulnerabilities and exploits your network is open to and apply the appropriate patches to protect your network.” (Cobb, 2006)


Bibliography

Cobb, M. (2006, June). Retrieved from Tech Target: http://searchsecurity.techtarget.com/answer/How-to-protect-against-port-scans
Faircloth, J. (2011). Penetration Tester's Open Source Toolkit (Third Edition). Elsevier Inc.
Insitute, S. (2006, June). Retrieved from SANS Insitute: https://www.sans.org/reading-room/whitepapers/analyst/penetration-testing-assessing-security-attackers-34635
Liska, A. (2003, June). Retrieved from Network Security: Understanding Types of Attacks | Sniffing and Port Scanning: http://www.informit.com/articles/article.aspx?p=31964
Narwal, E. R., & Gupta, E. G. (2015). Tracks covering in Penetration Testing and Cyber Attack. IJASPM.
Provos, N. (2002, August 05). Preventing Privilege Escalation. Retrieved from UMICH.EDU: http://www.citi.umich.edu/techreports/reports/citi-tr-02-2.pdf
Shinde, V. (2015, May 23). Retrieved from Software Testing Help: www.softwaretestinghelp.com/interview-questions/security-testing-interview-questions-and-answers/



Thursday, September 7, 2017

O que é uma enumeração de arquivos?


Esse tipo de ataque usa uma busca vigorosa em relação à manipulação de URL. Os hackers podem manipular os parâmetros na string do URL e podem obter os dados críticos geralmente não abertos ao público, como dados do banco de dados, versão antiga ou dados em desenvolvimento.

Explique a "manipulação de URL"?
 A manipulação de URL é um tipo de ataque em que os hackers manipulam o URL do site para obter informações críticas. A informação é passada nos parâmetros na cadeia de consulta através do método HTTP GET entre o cliente e o servidor. Os hackers podem alterar a informação entre esses parâmetros e obter a autenticação nos servidores e roubar os dados críticos.

Para evitar esse tipo de ataque, os testes de segurança da manipulação de URL devem ser feitos. Os próprios testadores podem tentar manipular o URL e verificar possíveis ataques e, se achados, eles podem evitar esses tipos de ataques.

O que é varredura de portas?
Ans. As portas são o ponto de onde a informação entra e sai de qualquer sistema. A varredura das portas descobrer buracos no sistema. Pode haver alguns pontos fracos no sistema ao qual os hackers podem atacar e obter informações críticas. Esses pontos devem ser identificados e impedidos de qualquer uso indevido.

Seguem-se os tipos de varreduras de portas:

Strobe: digitalização de serviços conhecidos.
UDP: digitalização de portas UDP abertas
Vanilla: nessa digitalização, o scanner tenta se conectar a todas as 65.535 portas.
Varredura: o scanner se conecta à mesma porta em mais de uma máquina.
Pacotes fragmentados: o scanner envia fragmentos de pacotes que passam por filtros de pacotes simples em um firewall
Varredura furtiva: o scanner bloqueia o computador escaneado para gravar as atividades de varredura de portas.
Desligamento de FTP ou Bounce FTP: o scanner passa por um servidor FTP para disfarçar a origem da varredura.

Wednesday, September 6, 2017

Configuration Command Modes - Cisco Netacad


To configure the device, the user must enter Global Configuration Mode, which is commonly called global config mode.
From global config mode, CLI configuration changes are made that affect the operation of the device as a whole. Global configuration mode is identified by a prompt that ends with (config)# after the device name, such as Switch(config)#.
Global configuration mode is accessed before other specific configuration modes. From global config mode, the user can enter different sub-configuration modes. Each of these modes allows the configuration of a particular part or function of the IOS device. Two common sub-configuration modes include:
  • Line Configuration Mode - Used to configure console, SSH, Telnet, or AUX access.
  • Interface Configuration Mode - Used to configure a switch port or router network interface.
When using the CLI, the mode is identified by the command-line prompt that is unique to that mode. By default, every prompt begins with the device name. Following the name, the remainder of the prompt indicates the mode. For example, the default prompt for line configuration mode is Switch(config-line)# and the default prompt for interface configuration mode is Switch(config-if)#.

Monday, September 4, 2017

How Cybersecurity Became 2017’s Hot New Major


Everybody wants to teach, but nobody can decide what it is

by 

If recent headlines about attacks on our privacy make one thing clear, it’s that there is a lot of work to do in the world of cybersecurity. Whether it’s Verizon accidentally exposing the personal data of 14 million subscribers, thieves stealing details about the hacking tools used by the CIA, or a Russian computer whiz hacking into academic institutions around the world, the vulnerability of our digital world is in the news nearly every day. Even so, a close look at cyber security education at the university level reveals a gap between what students are learning and the kinds of skills employers are looking for in the workplace.
Nearly two-thirds of all Americans have been affected personally by some kind of data theft, according to a 2016 Pew Research Center survey, including fraudulent credit card charges, stolen sensitive information such as Social Security or financial account numbers, identity theft, and hijacked email accounts. U.S. companies and government agencies suffered 1,093 data breaches in 2016, according to the Identity Theft Resource Center, a nonprofit that helps identity theft victims resolve their cases. One out of four companies is expected to experience a breach in the next two years, research firm the Ponemon Institute said earlier this year. It’s no surprise that cybersecurity programs are popping up in colleges and universities around the country, filled with students interested in acquiring relevant and highly employable skills. At NYU’s Tandon School of Engineering, undergrads majoring in computer science or computer engineering have the option of minoring in cybersecurity. NYU, Columbia, and Pace all offer master’s programs in cybersecurity.
Yet it remains a relatively new field of academia, having arrived on campuses within the past five years. There still aren’t many schools offering specialized cybersecurity programs, and the majority of universities don’t require students to take security courses when enrolled in related programs, such as computer science, information systems, and engineering. For Columbia undergrads, none of the security courses — such as introduction to cryptography, security architecture and engineering, or secure software development — are core requirements. Similarly, students enrolled in computer science at CUNY’s City College study programming, operating systems, and databases. Computer security is offered as a theory and application elective. Without consistent accreditation or even agreement on what needs to be included in a cybersecurity curriculum, security experts warn, most of these programs are not doing nearly enough to prepare students to tackle the security challenges that await outside Academy walls.
There are currently 137 institutions that the National Security Agency has designated as “Centers for Excellence in Cybersecurity Education and Research,” but only a quarter of these offer specialized cybersecurity programs at the undergraduate level. NYU has the NSA designation and offers a security minor and that master’s program; the New York Institute of Technology offers a network security concentration for undergraduates and a master of science in information, network, and computer security. Pace doesn’t offer a security concentration for undergraduate computer science and information science students but offers it for information technology majors and master’s candidates.
CyberSeek, an interactive online career information tool run by the National Institute of Standards and Technology, estimates that there are currently about 300,000 unfilled security jobs in the United States. That number is expected to skyrocket to 3.5 million by 2021, according to cyber seek's estimates. If each NSA-accredited program graduates about 90 students each year, that’s about 12,300 newly minted cyber-defenders. To fill the expected number of job openings, these programs would need to graduate some 26,000 students annually, or more than double the current number.
“If we assumed — and I think it’s right to assume — that universities are a large source of computer security education employees, we’re currently able to produce around 50 percent of the requirement for what organizations really need and want,” said Chaim Sanders, an adjunct professor at the Rochester Institute of Technology and researcher at security company ZeroFox.
More worryingly, academic departments can’t seem to agree on what exactly these students should be studying. The field is still evolving and includes not just learning cryptography, but also writing software that is safe to use, protecting networks and computers (and mobile devices) from attackers, and addressing hardware vulnerabilities. While there is nothing wrong with specializing — after all, the skills to protect networks are different from those to write secure code or design secure devices — everyone is coming out with a different type of security foundation.
Because cybersecurity is intrinsically linked to computer science, engineering, and information systems, many institutions use these fields to establish the baseline curriculum. There is a problem with that approach, though. Accredited computer science degree programs follow Association for Computing Machinery curriculum guidelines, which require only three to nine lecture hours on security for a four-year computer science degree. A 2016 analysis by security company CloudPassage found that none of the top ten undergraduate computer science and engineering programs at American universities (as ranked by the U.S. News & World Report) required its students to take a cybersecurity course in order to graduate. The University of Michigan, ranked twelfth, was the only of the top thirty-six programs with a security requirement. The University of Alabama, unranked on this list, was the exception, as it requires students to complete three security classes as part of the information systems degree and four security classes for the computer science degree.
Locally, Pace University offers eight security electives. While Columbia University offers a computer security track within its graduate computer science degree, the only security electives offered to undergraduates are cryptography-related. “The curriculum guidelines that are there say these programs are supposed to teach security, but they’re not actually assessing the security knowledge that students are getting all that much,” said Rob Olson, a Rochester Institute lecturer who teaches programming, mobile security, and web app security and who presented with Sanders at this May’s Black Hat Briefings, a computer security conference.
Given that many schools rely on the NSA designation as a form of accreditation — that imprimatur qualifies schools to receive grants from the government for cybersecurity improvements — it’s not surprising that their programs are geared toward what the NSA requires of its workforce, which might not be applicable to the private sector. One of the NSA designations focuses on offensive capabilities, which would be useful for future NSA employees dealing with nation-state attacks, but not so much for private enterprise; if the school has the CAE Cyber Offense designation, those students will not have the kind of defensive skills employers are looking for. And while the Cyber Defense designation covers those skills, it requires students evaluating different programs to know, first, to look for those with the NSA stamp of approval, and second, to know the details of each designation. Students have to look at the coursework to see whether the program’s emphasis is on defensive security, offensive research, or policy, and to know the difference.
“There is no harm in knowing these things, but a typical consulting firm or security team may not need to know them for their daily jobs,” Sanders said, noting that more practical topics, such as cloud security, virtualization, and secure software development are all relegated to optional coursework. A well-grounded computer security program should cover fundamentals in security assurance, introductory cryptography, and system administration, Sanders said.
Unfortunately, there is negligible support from the industry to change the accreditation because of the impression that if it’s good enough for the NSA, it should be good enough for the basic enterprise. Universities don’t want to lead the way because it costs money and takes a lot of work to be accredited. As long as prospective employers and students don’t demand changes, there’s little incentive for schools to create guidelines that everyone can follow.
The other reason security education is so inconsistent across different institutions is that the curricula are designed to fit within the originating department, and a security track within an existing department will reflect the department’s original focus, Sanders said. If cybersecurity is being taught as part of an overall computer science program, it may include cryptography and application security, but an information technology program will emphasize network security and virtualization. If it is part of an engineering program, the focus will be on embedded systems, and an information science program will be policy-driven and emphasize compliance, risk analysis, and supply chain. When evaluating programs, students are left to navigate this maze on their own, to figure out what kind of training they will receive. The underlying foundation will determine the kind of instruction they will receive in software security, penetration testing, anomaly detection, or security economics and metrics.
“Some of the students who are coming out with these more historic versions of the accreditations and designations are maybe not as well prepared as some others,” Sanders added. “And it’s very difficult to determine which is which.”
As a result, even the best security programs tend to focus more on theory and less on practice. While some on-the-job training is to be expected, employers need a way to understand how effective the coursework was in preparing the student for real-world security challenges. One way universities can keep their curricula relevant is to work with alumni in the industry or develop deep industry partnerships with different companies to act as visiting lecturers, provide internships and mentoring, and get guidance on what kind of courses and skills are needed. Tech giant Intel, for example, worked with Cal Poly Pomona to build the PolySec Cyber Security Lab, where students can learn how to protect critical infrastructure such as smart grids and industrial control systems. Intel security experts also work with university professors around the country as part of the Intel Security Curriculum Program to develop security content. NYU has its Hacker in Residence, a security expert from the industry who curates some of the classes in the School of Engineering’s Department of Information Systems and Internet Security.
All of which is to say: Somewhat ironically, in order to bridge the gap between what gets taught in the classroom and what kind of skills employers are looking for, the rapidly expanding field of cybersecurity needs to break down barriers, not put them up. As Sanders put it, “There needs to be communication between academia and industry to better prepare students for the real world.”

CSI Cyber code editor


I will not illegally download this movie. Bart being Bart.


Lego's New Kit Teaches Young Kids about Code


Saturday, September 2, 2017

COMO EVITAR ATAQUES DE Engenharia Social


Desconfie de e-mails, mensagens instantâneas e chamadas telefônicas para pessoas não solicitadas, como prestadores de serviços. Verifique a origem de uma mensagem antes de enviar qualquer informação.

Nunca deixe a urgência na mensagem do atacante esconder seu julgamento.

Eduque-se. A informação é a ferramenta mais poderosa na prevenção de ataques de engenharia 
social. Pesquise sobre os fatos e como identificar e evitar criminosos on-line.

Nunca clique em links incorporados em e-mails de remetentes desconhecidos. Se necessário, use o mecanismo de pesquisa para procurar um site sugerido ou digite manualmente o URL do site.

Nunca baixe o anexo de email de remetentes desconhecidos. Se necessário, abra o anexo na visualização protegida que é habilitada por padrão em muitos sistemas operacionais.

Rejeitar pedidos de suporte técnico on-line de estranhos, não importa quão legítimos possam aparecer.

Proteja seu espaço de computador com um firewall forte, um software antivírus atualizado e defina seus filtros de spam muito alto.

Patch de software e sistemas operacionais para vulnerabilidades do dia zero ou zero day. Acompanhe as versões de patch de seus provedores de software e patch-up assim que possível.

Preste atenção ao URL do site. Às vezes, fraudadores online fazem pequenas mudanças nos URLs para direcionar o tráfego para seus próprios sites falsificados.


Information Gathering

What is information about University systems sensitive?
a.  University has a lot of vital information within their systems. Their systems have information about users, students, and vendors which could be sold for money. There can also be special projects that are a top secret which if stolen, could cost the University millions. Information on future prospects and where they are going to expand can cause problems also. As if the information falls into competitor’s hands, they can jump and gain the upper hand.
What data would be useful to aggressors?
a.      Data that aggressors could use as leverage is information about the infrastructure that the university offers. This could include server, hardware, and user information. As this information can be used to penetrate the infrastructure and assist in siphoning information from the university. The information will assist the hacker to see possible vulnerabilities. They can use this to create backdoors that they can later use to access systems when needed.
Of that data, what data can be protected?
a.      All data can be protected if the business is able to budget to cover that vulnerability. Having sensitive data floating around the network it should be encrypted to keep it protected. It should be recommended to the company to have a system in place. This will help if the network were to be penetrated as hackers might not be able to crack the encryption as easily and give up. This is one stage to make sure the data stays private and internal. The next items are to make sure all systems are up to date so there is not much vulnerability that could be easily exploited. This will help to build a barrier around the network. The University wants to protect data such as employee, student, and special project information.   
How can you prevent social engineering?
a.      The best way to prevent social engineering is by offering training regularly to users. The reason why training is important is it offers employees a better understanding as to they have to be careful when they have conversations with other people. The next item that should be discussed is how hackers can try to steal information via email. Show them examples of phishing emails and how to examine if they are fake or authentic.    

Consider the following questions:
1.        What is information about University systems sensitive?
2.       What data would be useful to aggressors?
3.       Of that data, what data can be protected?
4.      How can you prevent social engineering?
As has many organizations learned how to respond to security incidents only after suffering attacks. By this time, incidents often become much more costly than needed. The Proper incident response should be an integral part of any overall security policy and risk mitigation strategy.

There are clearly direct benefits in responding to security incidents. The value of forming a security incident response team with explicit team member roles is a must do, as well as how to define a security incident response plan.
To successfully respond to incidents, you need to:
·         Minimize the number and severity of security incidents.
·         Assemble the core Computer Security Incident Response Team (CSIRT).
·         Define an incident response plan.
·         Contain the damage and minimize risks.

Minimizing the Number and Severity of Security Incidents
  • Clearly, establish and enforce all policies and procedures.
  • Gain management support for security policies and incident handling.
  • Routinely assess vulnerabilities in your environment. Assessments should be done by a security specialist with the appropriate clearance to perform these actions.
  • Routinely check all computer systems and network devices to ensure that they have all of the latest patches installed.
  • Establish security training programs for both IT staff and end users. Knowing that the largest vulnerability in any system is the inexperienced user.
  • Post security banners that remind users of their responsibilities and restrictions, along with a warning of potential prosecution for violation. These banners make it easier to collect evidence and prosecute attackers.
  • Develop, implement, and enforce a policy requiring strong passwords.
  • Routinely monitor and analyze network traffic and system performance.
  • Routinely check all logs and logging mechanisms, including operating system event logs, application specific logs and intrusion detection system logs.
  • Verify the back-up and restore procedures. The administrator should be aware of where backups are maintained, who can access them, and your procedures for data restoration and system recovery. Create a Computer Security Incident Response Team (CSIRT) to deal with security incidents.
Assembling the Core Computer Security Incident Response Team
Assembling a team before an incident occurs is very important to your organization and will positively influence how incidents are handled. A successful team will:
  • Monitor systems for security breaches.
  • Serve as a central communication point, both to receive reports of security incidents and to disseminate vital information to appropriate entities about the incident.
  • Document and catalog security incidents.
  • Promote security awareness within the company to help prevent incidents from occurring in your organization.
  • Support system and network auditing through processes such as vulnerability assessment and penetration testing.
  • Learn about new vulnerabilities and attack strategies employed by attackers.
  • Research new software patches.
  • Analyze and develop new technologies for minimizing security vulnerabilities and risks.
  • Continually hone and update current systems and procedures.
Defining an Incident Response Plan
All members of your IT environment should be aware of what to do in the event of an incident. The CSIRT will perform most actions in response to an incident, but all levels of the IT staff should be aware of how to report incidents internally. End users should report suspicious activity to the IT staff directly or through a help desk rather than directly to the CSIRT.
To instigate a successful incident response plan, you should:
  • Make an initial assessment.
  • Communicate the incident.
  • Contain the damage and minimize the risk.
  • Identify the type and severity of the compromise.
  • Protect evidence.
  • Notify external agencies if appropriate.
  • Recover systems.
  • Compile and organize incident documentation.
  • Assess incident damage and cost.
  • Review the response and update policies.
These steps are not purely sequential. But, they happen throughout the incident. Just like, documentation starts at the very beginning and continues throughout the entire life cycle of the incident; communication also happens throughout the entire incident.
Containing the Damage and Minimizing the Risks
By acting quickly to reduce the actual and potential effects of an attack, you can make the difference between a minor and a major one. The exact response will depend on your organization and the nature of the attack that you face. However, the following priorities are suggested as a starting point:
  1. Protect human life and people's safety. This should, of course, always be your first priority.
  2. Protect classified and sensitive data. As part of your planning for incident response, you should clearly define which data is classified and which is sensitive. This will enable you to prioritize your responses in protecting the data.
  3. Protect other data, including proprietary, scientific, and managerial data. Other data in your environment might still be of great value. You should act to protect the most valuable data first before moving on to other, less useful, data.
  4. Protect hardware and software against attack. This includes protecting against loss or alteration of system files and physical damage to hardware. Damage to systems can result in costly downtime.
  5. Minimize disruption of computing resources (including processes). Although uptime is very important in most environments, keeping systems up during an attack might result in greater problems later on. For this reason, minimizing disruption of computing resources should generally be a relatively low priority.
There are a number of measures that the administrator can take to contain the damage and minimize the risk to your environment. At a minimum, you should:



O Valor da Footprint


Quão importante é a pegada? De acordo com o Fórum de Segurança da Informação (ISF), os ataques com enfâse lucrativa substituíram em grande parte os de hacker lobo solitário. Esses novos atacantes dependem de uma pegada cuidadosa para determinar e selecionar alvos adequados. Grupos de crimonosos hackers ficaram conhecidos por colocar funcionários falsos dentro das organizações para fornecer conhecimento interno, que consequentemente pode ser usado para realizar um ataque.

Este novo modo de ataque foi projetado para roubar informações valiosas e sensíveis ou dados do cliente para obter lucro. Embora não sejam inéditos, tais crimes raramente são realizados por uma pessoa; Esses ataques são tipicamente o trabalho de redes criminosas que reúnem habilidades especializadas.
 (Oriyano 114)
Tradução livre de Afonso H. R. Alves

Oriyano, Sean-Philip. Hacker Techniques, Tools e Incident Handling, 2nd Edition. Jones & Bartlett Learning, 08/2013. Arquivo do VitalBook.

Friday, September 1, 2017

Problemas e soluções para Projetos de Desenvolvimento da Web

Problema 1: Todo mundo quer saber o quanto vai custar o site

Pontos a considerar: De início, você nunca saberá  o custo real para produzir e manter um website
Os clientes tendem a mudar suas expectativas e requisitos constantemente. Os profissionais tendem a dizer que só podem definir o preço real do projeto tendo em vista um plano bem construído e sem grandes mudanças com o tempo. Essa incerteza sempre prejudica a qualidade do projeto - ou o orçamento.
Uma possível solução: você deve trabalhar em conjunto e decidir quais são suas prioridades. O preço mínimo, definido pelos desenvolvedores web, varia muito da experiencia do desenvolvedor e um contrato estabelecendo isto seria bem vindo. Dessa forma, os desenvolvedores da web serão capazes de cumprir os requisitos básicos, definidos pelo cliente, e haverá dinheiro suficiente para pagar despesas por detalhes adicionais.

Problema 2: confusão com os requisitos

Os requisitos do cliente são sempre uma dor no “pescoço”. Primeiro, alguns clientes não tem idéia do que querem ou - o que é ainda mais horrível - têm idéias que simplesmente não podem se traduzir em realidade. Em segundo lugar, às vezes os requisitos mudam porque o cliente percebeu que precisa mudar o público-alvo ou por outros motivos comerciais. Em terceiro lugar, às vezes os desenvolvedores da web percebem que podem oferecer uma solução melhor e todos os requisitos anteriores impedem que o façam. No terceiro caso, se os clientes souberem que voce poderia ter oferecido uma solução assim no início e oferece novas ideias fora do contrato pode ser não benéfico para ambos.
Solução: Defina os elementos de design. O cliente só precisa definir o básico - todo o resto deve ser discutido e implementado durante o processo de desenvolvimento do site.

Problema 3: você não pode simplesmente iniciar um site


Se você é um desenvolvedor web - diga olá para requisitos inesperados e correções intermináveis. E mesmo quando se lança um site, isso não significa que o trabalho esteja terminado, nós temos os "bugs", e alguém diz que a funcionalidade poderia ter sido melhor.
Solução: faça uma versão básica do site e deixe os visitantes chegarem até a versão principal estar completa. É melhor começar com um site de qualidade inferior ao padrão, em vez de perder tempo sem nenhum. O desenvolvimento do site é um processo difícil, então, se você decidir esperar até que tudo esteja em ordem, afinal, você pode se familiarizar com seus clientes, aprender suas necessidades e descobrir seus desejos tendo uma versão razoável do projeto, com a idéia principal num bom display.

1)  Abaixo eu cito alguns problemas a se ter em mente e que podem ser ponderados em relação à discussão do projeto com o Cliente.

Os requisitos não estão claramente definidos. Rescreva!
Comece a partir de uma instalação pré-configurada, em uma plataforma fácil de modificar
O site nunca está realmente pronto quando é lançado.
Meu sistema de gerenciamento de conteúdo / site de comércio eletrônico foi pirateado!  Certifique-se de que o site está bem respaldado e as medidas de segurança estão atualizadas.
Se seu site falhou após uma atualização. Tenha um contrato de suporte e backup, sempre!


Automação de Tarefas
Muitas vezes realizamos tarefas pequenas e repetitivas todos os dias. Isso pode variar desde a implantação de um novo ambiente de desenvolvimento até a compilação de nossas folhas de estilo. Por sorte, existem ferramentas como grunhir e webpack que fazem muito por nós. Verifiquem e me falem o que acharam!

Agora, alguns alunos me perguntaram sobre projetos e o que se pode fazer depois que finalizar o curso Web Desenvolvimento 2.0. Venho, por exemplo, aprendendo mais sobre Bootstrap 4.0 e verifico que todo momento é um desafio de integração do código com o projeto que estou trabalhando, portando é muito difícil de prever ganhos financeiros em relação a projetos futuros. A grande questão é começar e ir adquirindo experiências, fazendo amizades com profissionais, lendo constantemente stack overflow, livros, videos e o principal, tendo um projeto em mente para concretizar e instigar a pesquisa. Uma coisa digo com absoluta razão, devemos ler e buscar soluções diárias para os projetos que temos em mente e isto, leva algum tempo para se concretizar.

Afonso H. R. Alves


01 de Setembro de 2017