logo       


Re: "Build Security In" portal: msg#00014

Subject: Re: "Build Security In" portal
Thanks for the links Javier, in case your interested I've been working
on a lecture recently on the subject of C Source Code Auditing. It
should be done sometime this month. I'll be covering some of the tools
I use like cscope and ctags along with how to spot some of the
vulnerable code and some of the finer points of what makes code
vulnerable in the first place. All this will be going on on the irc
server at pulltheplug.org where I'll be giving some live demos via
screen and ttyrec of a auditing session. However if you can't make it
I'm publishing a paper covering all of the topics discussed in the
lecture which I'll gladly post a link to here when its finished.


Thanks,
David D. Rude
bannedit@xxxxxxxxxxxxxxx

Quoting Javier Fernández-Sanguino Peña <jfs@xxxxxxxxxx>:


I'm not sure if you guys were aware of the "Build Security In" portal
dedicated to code security and quality,  that has just been launched. It is
available at https://buildsecurityin.us-cert.gov/

The "Source Code Analysis Tools" section at
https://buildsecurityin.us-cert.gov/portal/article/tools/code_analysis/overview.xml
is worth reviewing. The code samples are missing, though.

People contributing to the portal include Gary McGraw and Ken van Wyk.
Definitely worth a look.

Regards

Javier




Ruby Jobs
Java Jobs
Jobs in California
more...
what
job title, keywords
where
city, state, zip
jobs by job search
Search:
Java, servers, webhosting, windows, cisco ...
more...
<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

Recently Viewed:
encryption.gpg....    ietf.rfc822/199...    freebsd.devel.i...    lang.haskell.li...    mail.squirrelma...    web.zope.plone....    yellowdog.gener...    text.xml.xalan....    recreation.phot...    kde.devel.educa...    hardware.bus.ca...    printing.ghosts...    voip.peering/20...    assembly/2006-0...    org.user-groups...    culture.interne...    network.i2p/200...    boot-loaders.ya...    xfree86.render/...    qnx.openqnx.dev...    jakarta.velocit...    user-groups.pal...   
Home | blog view | USPTO Patent Archive | advertise | OSDir is an inevitable website. super tiny logo

Free Magazines

Cisco News
Receive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business.
subscribe

Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field.
subscribe

The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business.
subscribe

Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company.
subscribe

Total Telecom Total Telecom is "The Economist of the communications industry".
subscribe