Re: Your opinion on a valuable and feasible goal for a new source code auditing tool
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 11 May 2004 08:51:52 +0200, Holger Peine said: > Buffer overflow detection in C programs is the first thing that > comes to mind, but there are already various efforts in this > direction (source code scanners and other things like compiler > support). Another idea we have come up with is building an input > validation checker similar to Perl's taint mode other languages > (most probably Java, C++, or C). Do you think that taint checking > would cover a noteworthy share of _pratical_ software security bugs? > Or what else would you suggest instead? > > We are aware of tools like flawfinder, ITS4, RATS, MOPS, Splint. Linus Torvalds has a tool called 'sparse' that has already caught a number of things in the Linux kernel code. He however freely admits it's not a fully completed tool - you might want to touch base with him and see if improving that tool would be a worthwhile project....
signature.asc
(application/pgp-signature, 226 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) Comment: Exmh version 2.5 07/13/2001 iD8DBQFAoPZrcC3lWbTT17ARAhyyAJ9Ev8ag5A6fKGe8WYh0/d/P3ihE7QCg+Zbb qpgh7smLZ9Ip6/wWvlNI0D0= =rgEC -----END PGP SIGNATURE-----