What is Toe?, There is not explanation

Goodnight, what happens is that I have searched all over the forum even on the Internet and I still do not understand what is Toe and Vbd since there is no clear explanation. In this url: https://fluidattacks.com/web/careers/technical-challenges/#keywords, there is a link to the explanation of Toe but it is only about how to configure Marklogic Server and there’s no url with the explanation about Vbd, that complicates things for me. The little I understood is that I’m most likely wrong, is that a vulnerability by design means that in a software development by not having good security practices in developing the code and database generate vulnerabilities. That is my conclusion.

I´m sorry with my english.

Target of Evaluation. Is a term commonly used in Common Criteria related standards, to referring to the system subject to security testing. Is the system to be attacked.

https://docs.marklogic.com/6.0/guide/cc/toe

https://en.wikipedia.org/wiki/Common_Criteria

thank you brother and my conclusion about VBD “means that in a software development by not having good security practices in developing the code and database generate vulnerabilities” is it correct or am I wrong?

Yes, you are right. There is an existing post related to VbD that may provide you more insight about this topic:

As a suggestion, double check the existing threads and posts, you can find useful information, and even solve your questions beforehand :wink:

thank you very much, I had not seen that publication sorry.

hey @clean-camera

If this topic is solved, please mark it as such by checking the solution chart at the bottom of the post you consider that properly answers your question (go to the answer, click on the ellipsis and then the solved button).