Re: Your opinion on a valuable and feasible goal for a new source code auditing tool

[email protected]
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
On Tue, 11 May 2004 08:51:52 +0200, Holger Peine said:

> Buffer overflow detection in C programs is the first thing that
> comes to mind, but there are already various efforts in this
> direction (source code scanners and other things like compiler
> support).   Another idea we have come up with is building an input 
> validation checker similar to Perl's taint mode other languages 
> (most probably Java, C++, or C). Do you think that taint checking
> would cover a noteworthy share of _pratical_ software security bugs?
> Or what else would you suggest instead?
> 
> We are aware of tools like flawfinder, ITS4, RATS, MOPS, Splint.

Linus Torvalds has a tool called 'sparse' that has already caught a number of
things in the Linux kernel code.  He however freely admits it's not a fully
completed tool - you might want to touch base with him and see if improving
that tool would be a worthwhile project....
signature.asc (application/pgp-signature, 226 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQFAoPZrcC3lWbTT17ARAhyyAJ9Ev8ag5A6fKGe8WYh0/d/P3ihE7QCg+Zbb
qpgh7smLZ9Ip6/wWvlNI0D0=
=rgEC
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.