[SC-L] (no subject)

2006-10-05 Thread Gadi Evron
playing with Google Code Search, as Lev Toger just wrote:

Google released a code search engine to catch up with Krugle, Koders, and
Codease.

Like most of the other Google?s tools it can be easily abused for hacking
:)

To find undisclosed vulnerabilities pass over this code:

http://www.google.com/codesearch?q=ugly%7Chack%7Cfixme

Or some other interesting combination (Use your favorite ugly code
comment). 
-

http://blogs.securiteam.com/index.php/archives/659

SO... ugly? dirty hack?

Gadi.

___
Secure Coding mailing list (SC-L)
SC-L@securecoding.org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php


Re: [SC-L] (no subject)

2006-07-17 Thread SC-L Subscriber Dave Aronson
Jeremy Epstein [mailto:[EMAIL PROTECTED] writes:

 > "Software Security Keeps the Bad Guys Out"

That's certainly one important aspect, but this slogan doesn't address issues 
such as staying up, producing correct output, etc.  It also can blur the 
already much too fuzzy (in the public mind) line between "software security" 
and "security software".

-Dave



___
Secure Coding mailing list (SC-L)
SC-L@securecoding.org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php


Re: [SC-L] (no subject)

2006-07-17 Thread SC-L Subscriber Dave Aronson
Gary McGraw [mailto:[EMAIL PROTECTED] wrote:

 > I wrote a book with viega a few years ago called "building secure
 > software"...

Yes, John gave us all copies.  Didn't bother to get it autographed though.  :-)

 > it was not about that company (at all).

It certainly was not about the horribly broken software I spent months banging 
my head against a wall trying to fix  :-(

 > P.s. I actually like ivan's quip as reported by crispy.

Me too.  It contains the ideas I was trying to convey, more clearly, but it's 
still too long to fit on a bumper sticker.  :-)

-Dave



___
Secure Coding mailing list (SC-L)
SC-L@securecoding.org
List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l
List charter available at - http://www.securecoding.org/list/charter.php