RE: Code Assessment

"Mike Randall" <[email protected]>
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
For ColdFusion, I use a tool from http://www.cfdev.com (CF Source Code
Review Tool).  It is a simple rule-based source code reviewer that comes
with 30 built-in rules, some of which deal with security.  It allows
additional rules to be created fairly easily (especially with regular
expressions) and I have created several more.  I would be happy to share
my rules with anyone who uses the tool.

Mike Randall
APA IV, Web Developer
AJLA-TS, KDHR
Phone: 785-296-3650
Fax: 785-296-2119
Email: [email protected]

-----Original Message-----
From: Bobby, Paul [mailto:[email protected]] 
Sent: Wednesday, April 14, 2004 9:03 AM
To: [email protected]
Subject: Code Assessment

I appreciate the discussions on various coding methodologies, however
I've been asked to approach application testing from a penetration point
of view.

I'm just beginning my research in to this topic, and wanted to ask
within this list early on. 

I am looking to assess the integrity of an application either by
scanning the source code for potential problems (like a security lint
for example), and secondly, various tools that test the application in
runtime.

The majority of applications to be assessed are written in cold fusion,
java, c/c++ and some .asp.

Thank you

Paul Bobby
Lockheed Martin Systems Integration
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.