[SC-L] Off-by-one errors: a brief explanation

2004-05-05 Thread Steven M. Christey
Mads Rasmussen <[EMAIL PROTECTED]> said: >I for one have difficulties understanding the "off-by-one" >vulnerability. Maybe a kind soul would step in? I'll try to tackle this. Corrections or additions are most welcome :) In general, off-by-one bugs involve small errors in which an array of siz

[SC-L] SD Magazine conversation with Bruce Schneier

2004-05-05 Thread Benjamin Pick
Hi, I'm a software engineer with a strong interest in computer security, and I would like to follow the conversation between SD Magazine and Bruce Schneier, but because it looks like it'll be a video-conference, and doesn't seem to be text based, I would really appreciate it if someone here could

[SC-L] Washington DC area talk on Exploiting Software

2004-05-05 Thread Gary McGraw
FYI. Hope to see some of you there. gem > -Original Message- > From: Landwehr, Carl E. [mailto:[EMAIL PROTECTED] > Sent: Wednesday, May 05, 2004 8:29 AM > To: Washington Area Trustworthy Systems Hour > Subject: May WATSH coming next Tuesday: Gary McGraw, Cigital, > on How to Break Code

[SC-L] Re: Vulnerability Auditing Checklist

2004-05-05 Thread Alfonso Alba GarcĂ­a
Thanks a lot for publishing this checklist!! I have a few "friends of mine" who desperatelly need to read it ;-) As Eric said, a beer is waiting for you in Madrid if you happen to be there sometime. Regards Alfonso

Re: [SC-L] auditing

2004-05-05 Thread jnf
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Just wanted to say thanks to everyone who had suggestions, i havent had much time to try everything out yet, but ive tried ctags and cscope and between the two of them i think the auditing process can be made to be a little more sane for me- as for