Re: Article on writing secure software

From: Jim Dennis (jimdat_private)
Date: Tue Apr 07 1998 - 03:06:40 PDT

  • Next message: Theo Schlossnagle: "APC UPS PowerChute PLUS exploit..."

    >>>>> Adam == Adam Shostack <adamat_private> writes:
    >>>>> TF == Trane Francks
    TF> Perhaps I'm preaching to the converted here, but I found an
    TF> interesting article in SunWorld Online regarding security and
    TF> the software we write. It might be considered mandatory reading
    TF> for new programmers....
    TF>
    TF> Take a look at:
    TF>
    TF> http://www.sun.com/sunworldonline/swol-04-1998\
    TF>   /swol-04-security.html?040198i
    
    Adam> If Aleph oks it, I'll plug a set of code review guidelines I
    Adam> wrote about a year ago:
    Adam> http://www.homeport.org/~adam/review.html
    
     I hope everyone here has also read one of the extent classics in
     this rarefied field:
    
            Matt Bishop's Writing Secure SUID Programs
            http://olympus.cs.ucdavis.edu/~bishop/secprog.html
    
    --
    Jim Dennis  (800) 938-4078              consultingat_private
    Proprietor, Starshine Technical Services:  http://www.starshine.org
            PGP  1024/2ABF03B1 Jim Dennis <jimat_private>
            Key fingerprint =  2524E3FEF0922A84  A27BDEDB38EBB95A
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:48:59 PDT