RE: Code Assessment
"Mike Randall" <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
For ColdFusion, I use a tool from http://www.cfdev.com (CF Source Code Review Tool). It is a simple rule-based source code reviewer that comes with 30 built-in rules, some of which deal with security. It allows additional rules to be created fairly easily (especially with regular expressions) and I have created several more. I would be happy to share my rules with anyone who uses the tool. Mike Randall APA IV, Web Developer AJLA-TS, KDHR Phone: 785-296-3650 Fax: 785-296-2119 Email: [email protected] -----Original Message----- From: Bobby, Paul [mailto:[email protected]] Sent: Wednesday, April 14, 2004 9:03 AM To: [email protected] Subject: Code Assessment I appreciate the discussions on various coding methodologies, however I've been asked to approach application testing from a penetration point of view. I'm just beginning my research in to this topic, and wanted to ask within this list early on. I am looking to assess the integrity of an application either by scanning the source code for potential problems (like a security lint for example), and secondly, various tools that test the application in runtime. The majority of applications to be assessed are written in cold fusion, java, c/c++ and some .asp. Thank you Paul Bobby Lockheed Martin Systems Integration