<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; code-audit</title>
	<atom:link href="http://www.darknet.org.uk/tag/code-audit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>OWASP CodeCrawler &#8211; Static Code Review Tool</title>
		<link>http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/</link>
		<comments>http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 11:07:33 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[.net code review]]></category>
		<category><![CDATA[.net security]]></category>
		<category><![CDATA[code scanning tool]]></category>
		<category><![CDATA[code security]]></category>
		<category><![CDATA[code testing]]></category>
		<category><![CDATA[code-audit]]></category>
		<category><![CDATA[codecrawler]]></category>
		<category><![CDATA[development security]]></category>
		<category><![CDATA[J2EE-security]]></category>
		<category><![CDATA[JAVA-security]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[owasp codecrawler]]></category>
		<category><![CDATA[static analysis]]></category>
		<category><![CDATA[static code analysis tool]]></category>
		<category><![CDATA[static code review]]></category>
		<category><![CDATA[static code review tool]]></category>
		<category><![CDATA[static code security tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2510</guid>
		<description><![CDATA[CodeCrawler is a tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. It&#8217;s a Microsoft .NET 3.5 Windows Form application which supports the OWASP Code Review Project. It provides automatic STRIDE classification a very simple DREAD calculator and few minor [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>CodeCrawler is a tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. It&#8217;s a Microsoft .NET 3.5 Windows Form application which supports the OWASP Code Review Project.</p>
<p>It provides automatic STRIDE classification a very simple DREAD calculator and few minor utilities. Direct links to WAST 2.0 Threat Classification, Secure Java Development Guidelines and OWASP Tools are also part of the package. </p>
<p><strong>Requirements</strong></p>
<ul>
<li>.NET Framework 3.5 (Service Pack 1)</li>
<li>Visual Studio 2008</li>
<li>Windows Platform</li>
</ul>
<p>You can download CodeCrawler here:</p>
<p><a href="http://codecrawler.codeplex.com/releases/view/39345#DownloadId=102703">CODECRAWLER_2.5_RELEASE.zip</a></p>
<p></p>
<p>Or read more <a href="http://codecrawler.codeplex.com/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2510+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;t=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;title=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;title=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;title=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;title=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F03%2Fowasp-codecrawler-static-code-review-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>NSA Together With Mitre CWE and SANS Identifies Top 25 Programming Errors</title>
		<link>http://www.darknet.org.uk/2009/02/nsa-together-with-mitre-cwe-and-sans-identifies-top-25-programming-errors/</link>
		<comments>http://www.darknet.org.uk/2009/02/nsa-together-with-mitre-cwe-and-sans-identifies-top-25-programming-errors/#comments</comments>
		<pubDate>Tue, 17 Feb 2009 09:46:08 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[application-security]]></category>
		<category><![CDATA[code-audit]]></category>
		<category><![CDATA[hacking-software]]></category>
		<category><![CDATA[mitre]]></category>
		<category><![CDATA[mitre cwe]]></category>
		<category><![CDATA[NSA]]></category>
		<category><![CDATA[pen-testing]]></category>
		<category><![CDATA[penetration-testing]]></category>
		<category><![CDATA[programming errors]]></category>
		<category><![CDATA[sans]]></category>
		<category><![CDATA[software-hacking]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[web-application-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1484</guid>
		<description><![CDATA[Secure programming is a huge issue and it&#8217;s the lack of it that causes all the problems we have with vulnerabilities and the exploits associated with them. If everywhere developers followed secure programming practices we wouldn&#8217;t have buffer overflow issues or unsanitized parameters leading to SQL Injection. The NSA (National Security Agency), working with MITRE, [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Secure programming is a huge issue and it&#8217;s the lack of it that causes all the problems we have with vulnerabilities and the exploits associated with them. If everywhere developers followed secure programming practices we wouldn&#8217;t have buffer overflow issues or unsanitized parameters leading to SQL Injection.</p>
<p>The NSA (National Security Agency), working with MITRE, SANS, and dozens of industry experts from many other organizations, has published a valuable list of the top 25 most dangerous programming errors.</p>
<p>I hope more companies take notice of this and train their developers properly, rather than squeezing maximum efficiency and LOC out of them &#8211; teach them to code properly and securely too!</p>
<blockquote><p> The 2009 CWE/SANS Top 25 Most Dangerous Programming Errors is a list of the most significant programming errors that can lead to serious software vulnerabilities. They occur frequently, are often easy to find, and easy to exploit. They are dangerous because they will frequently allow attackers to completely take over the software, steal data, or prevent the software from working at all.</p>
<p>The list is the result of collaboration between the SANS Institute, MITRE, and many top software security experts in the US and Europe. It leverages experiences in the development of the SANS Top 20 attack vectors (<a href="http://www.sans.org/top20/">http://www.sans.org/top20/</a>) and MITRE&#8217;s Common Weakness Enumeration (CWE) (<a href="http://cwe.mitre.org/">http://cwe.mitre.org/</a>). MITRE maintains the CWE web site, with the support of the US Department of Homeland Security&#8217;s National Cyber Security Division, presenting detailed descriptions of the top 25 programming errors along with authoritative guidance for mitigating and avoiding them. The CWE site also contains data on more than 700 additional programming errors, design errors, and architecture errors that can lead to exploitable vulnerabilities.</p>
<p>The main goal for the Top 25 list is to stop vulnerabilities at the source by educating programmers on how to eliminate all-too-common mistakes before software is even shipped. The list will be a tool for education and awareness that will help programmers to prevent the kinds of vulnerabilities that plague the software industry. Software consumers could use the same list to help them to ask for more secure software. Finally, software managers and CIOs can use the Top 25 list as a measuring stick of progress in their efforts to secure their software. </p></blockquote>
<p>It&#8217;s good to see such a comprehensive project being published on the Internet for free, the aim behind this is just to make more secure code. There&#8217;s no hidden commercial agenda or aim to sell services or software packages on the back of this.</p>
<p>If you know anyone in the development field I suggest you forward the list to them and tell them to send it to anyone involved in software development (same goes for commercial and non-commercial projects).</p>
<p>There&#8217;s no excuse for insecure code!</p>
<blockquote><p>The Top 25 list was developed at the end of 2008. Approximately 40 software security experts provided feedback, including software developers, scanning tool vendors, security consultants, government representatives, and university professors. Representation was international. Several intermediate versions were created and resubmitted to the reviewers before the list was finalized. More details are provided in the Top 25 Process page</p>
<p>To help characterize and prioritize entries on the Top 25, a threat model was developed that identifies an attacker who has solid technical skills and is determined enough to invest some time into attacking an organization. More details are provided in Appendix B.</p>
<p>Weaknesses in the Top 25 were selected using two primary criteria:</p>
<ul>
<li>Weakness Prevalence: how often the weakness appears in software that was not developed with security integrated into the software development life cycle (SDLC).</li>
<li>Consequences: the typical consequences of exploiting a weakness if it is present, such as unexpected code execution, data loss, or denial of service. </li>
</ul>
<p>Prevalence was determined based on estimates from multiple contributors to the Top 25 list, since appropriate statistics are not readily available. </p></blockquote>
<p>It&#8217;s assumed the attacker has some strong technical skills, is intent on data theft or theft of resources and is willing to spend an estimate 20 hours per software module. This is not realistic and in a blackhat situation you could bet they would be willing to spend much more than 20 hours.</p>
<p>Even if you aren&#8217;t directly involved in software development, it&#8217;s an interesting study and for people doing pen-tests/code audits and web application assessments it&#8217;s a goldmine of information to research further on.</p>
<p>If you get your techniques down on each of these 25 vulnerabilities you should be able to pretty much break anything open.</p>
<p></p>
<p>Source: <a href="http://cwe.mitre.org/top25/index.html">CWE</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=NSA+Together+With+Mitre+CWE+and+SANS+Identifies+Top+25+Programming+Errors+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1484+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/02/nsa-together-with-mitre-cwe-and-sans-identifies-top-25-programming-errors/&amp;t=NSA+Together+With+Mitre+CWE+and+SANS+Identifies+Top+25+Programming+Errors" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/02/nsa-together-with-mitre-cwe-and-sans-identifies-top-25-programming-errors/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/02/nsa-together-with-mitre-cwe-and-sans-identifies-top-25-programming-errors/&amp;title=NSA+Together+With+Mitre+CWE+and+SANS+Identifies+Top+25+Programming+Errors" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/02/nsa-together-with-mitre-cwe-and-sans-identifies-top-25-programming-errors/&amp;title=NSA+Together+With+Mitre+CWE+and+SANS+Identifies+Top+25+Programming+Errors" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/02/nsa-together-with-mitre-cwe-and-sans-identifies-top-25-programming-errors/&amp;title=NSA+Together+With+Mitre+CWE+and+SANS+Identifies+Top+25+Programming+Errors" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/02/nsa-together-with-mitre-cwe-and-sans-identifies-top-25-programming-errors/&amp;title=NSA+Together+With+Mitre+CWE+and+SANS+Identifies+Top+25+Programming+Errors" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F02%2Fnsa-together-with-mitre-cwe-and-sans-identifies-top-25-programming-errors%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/02/nsa-together-with-mitre-cwe-and-sans-identifies-top-25-programming-errors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SpikeSource Spike PHP Security Audit Tool</title>
		<link>http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/</link>
		<comments>http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/#comments</comments>
		<pubDate>Tue, 01 Aug 2006 03:13:49 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[code auditing tool]]></category>
		<category><![CDATA[code-audit]]></category>
		<category><![CDATA[code-auditing]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[php-audit-tool]]></category>
		<category><![CDATA[php-security]]></category>
		<category><![CDATA[source code auditing]]></category>
		<category><![CDATA[spike]]></category>
		<category><![CDATA[spikesource]]></category>
		<category><![CDATA[static analysis]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/</guid>
		<description><![CDATA[Spike is an Open Source tool based on the popular RATS C based auditing tool implemented for PHP. The tool Spike basically does static analysis of php code for security exploits, PHP5 and call-time pass-by-reference are currently required, but a PHP4 version is coming out this week. This tool is especially welcomed by Darknet as [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Spike is an Open Source tool based on the popular <a href="http://www.darknet.org.uk/2009/11/rats-rough-auditing-tool-for-security/">RATS</a> C based auditing tool implemented for PHP.</p>
<p>The tool Spike basically does static analysis of php code for security exploits, PHP5 and call-time pass-by-reference are currently required, but a PHP4 version is coming out this week.</p>
<p>This tool is especially welcomed by Darknet as there aren&#8217;t many static analysis tools out there that are free, and there are very few tools for auditing PHP code..which as we all known tends to be coded quite insecurely at times (just look at phpBB and PhpNUKE).</p>
<p>You can find the latest version here:</p>
<p></p>
<p><a href="http://developer.spikesource.com/projects/phpsecaudit">Spike PHP Audit Tool</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=SpikeSource+Spike+PHP+Security+Audit+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D307+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;t=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;title=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;title=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;title=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;title=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F08%2Fspikesource-spike-php-security-audit-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

