Re: Research on Source Code Review -C

From: Nicole Nicholson (nanicholsonat_private)
Date: Wed Jun 11 2003 - 06:41:42 PDT

  • Next message: dong-h0un U: "[Full-Disclosure] Re: Small buffer format string attack"

    Dwar-
    
    I don't know if you have looked at any of these sites.  They actually 
    contain tools & publications for source code analysis and review.  You may 
    be able to use some of their literature and/or documentation to develop a 
    set of guidelines.
    
    http://www.cenzic.com/
    http://www.cigital.com/
    http://www.dwheeler.com/flawfinder/
    http://www.securesoftware.com/
    
    Cheers.
    
    -Nicole
    
    
    <snip>
    
    Am looking to develop source code review guidelines for code written in
    c/c++. I have found a few documents on the net but nothing that could be
    really followed along to do source code review. I also wanted to know what
    people in the field are actually doing and also if they could provide
    first hand experience as to what all they look for and how.
    
    _________________________________________________________________
    The new MSN 8: advanced junk mail protection and 2 months FREE*  
    http://join.msn.com/?page=features/junkmail
    



    This archive was generated by hypermail 2b30 : Wed Jun 11 2003 - 12:11:38 PDT