<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; source code auditing tool</title>
	<atom:link href="http://www.darknet.org.uk/tag/source-code-auditing-tool/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Microsoft CAT.NET v1.1.1.9 &#8211; Binary Code Analysis Tool .NET</title>
		<link>http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/</link>
		<comments>http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 09:39:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[.net auditing tool]]></category>
		<category><![CDATA[.net security]]></category>
		<category><![CDATA[application-security]]></category>
		<category><![CDATA[binary code analysis]]></category>
		<category><![CDATA[binary-analysis]]></category>
		<category><![CDATA[cat.net]]></category>
		<category><![CDATA[code-auditing]]></category>
		<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[cross-site-scripting]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[software-security]]></category>
		<category><![CDATA[source code auditing tool]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[static analysis]]></category>
		<category><![CDATA[visual studio ide]]></category>
		<category><![CDATA[Visual-Studio]]></category>
		<category><![CDATA[windows-security]]></category>
		<category><![CDATA[xpath injection]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2321</guid>
		<description><![CDATA[CAT.NET is a binary code analysis tool that helps identify common variants of certain prevailing vulnerabilities that can give rise to common attack vectors such as Cross-Site Scripting (XSS), SQL Injection and XPath Injection. CAT.NET is a snap-in to the Visual Studio IDE that helps you identify security flaws within a managed code (C#, Visual [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>CAT.NET is a binary code analysis tool that helps identify common variants of certain prevailing vulnerabilities that can give rise to common attack vectors such as Cross-Site Scripting (XSS), SQL Injection and XPath Injection.</p>
<p>CAT.NET is a snap-in to the Visual Studio IDE that helps you identify security flaws within a managed code (C#, Visual Basic .NET, J#) application you are developing. It does so by scanning the binary and/or assembly of the application, and tracing the data flow among its statements, methods, and assemblies.</p>
<p>This includes indirect data types such as property assignments and instance tainting operations. The engine works by reading the target assembly and all reference assemblies used in the application — module-by-module — and then analyzing all of the methods contained within each. It finally displays the issues its finds in a list that you can use to jump directly to the places in your application’s source code where those issues were found.</p>
<p>The following rules are currently support by this version of the tool</p>
<ul>
<li>Cross Site Scripting</li>
<li>SQL Injection</li>
<li>Process Command Injection</li>
<li>File Canonicalization</li>
<li>Exception Information</li>
<li>LDAP Injection</li>
<li>XPATH Injection</li>
<li>Redirection to User Controlled Site</li>
</ul>
<p><strong>System Requirements</strong></p>
<p>Supported Operating Systems: Windows Vista; Windows XP</p>
<p>OS: XP, Vista Software: .NET Framework 2.0, Visual Studio 2005 or 2008. </p>
<p>You can download CAT.NET here:</p>
<p><a href="http://www.microsoft.com/downloads/info.aspx?na=90&#038;p=&#038;SrcDisplayLang=en&#038;SrcCategoryId=&#038;SrcFamilyId=0178e2ef-9da8-445e-9348-c93f24cc9f9d&#038;u=http%3a%2f%2fdownload.microsoft.com%2fdownload%2f3%2f3%2f4%2f334E8A84-0F1B-4E3C-AF5F-99DA8AE0601F%2fCATNETx32.msi">CATNETx32.msi</a></p>
<p></p>
<p>Or read more <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=0178e2ef-9da8-445e-9348-c93f24cc9f9d&#038;displaylang=en">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2321+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;t=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F12%2Fmicrosoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Flawfinder &#8211; Source Code Auditing Tool</title>
		<link>http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/</link>
		<comments>http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/#comments</comments>
		<pubDate>Wed, 16 Sep 2009 09:46:04 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[code auditing tool]]></category>
		<category><![CDATA[code-auditing]]></category>
		<category><![CDATA[flaw finder]]></category>
		<category><![CDATA[flawfinder]]></category>
		<category><![CDATA[source code auditing]]></category>
		<category><![CDATA[source code auditing tool]]></category>
		<category><![CDATA[static analysis]]></category>
		<category><![CDATA[static analysis tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2065</guid>
		<description><![CDATA[Flawfinder is a program that examines source code and reports possible security weaknesses (flaws) sorted by risk level. It&#8217;s very useful for quickly finding and removing at least some potential security problems before a program is widely released to the public. It&#8217;s a static analysis source code auditing tool. Flawfinder is specifically designed to be [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Flawfinder is a program that examines source code and reports possible security weaknesses (flaws) sorted by risk level. It&#8217;s very useful for quickly finding and removing at least some potential security problems before a program is widely released to the public. It&#8217;s a static analysis <a href="http://www.darknet.org.uk/tag/source-code-auditing/">source code auditing</a> tool.</p>
<p>Flawfinder is specifically designed to be easy to install and use. After installing it, at a command line just type:</p>
<pre><code>flawfinder directory_with_source_code</code></pre>
<p>Flawfinder works on Unix-like systems today (it&#8217;s been tested on GNU/Linux), and it should be easy to port to Windows systems. It requires Python 1.5 or greater to run (Python 1.3 or earlier won&#8217;t work).</p>
<p><strong>Speed</strong></p>
<p>Flawfinder is written in Python, to simplify the task of writing and extending it. Python code is not as fast as C code, but for the task I believe it&#8217;s just fine. Flawfinder version 0.12 on a 400Mhz Pentium II system analyzed 51055 lines in 39.7 seconds, resulting in an average of 1285 analyzed lines/second. Flawfinder 1.20 and later will report their speed (in analyzed lines/second) if you&#8217;re curious. </p>
<p><strong>How it works</strong></p>
<p>Flawfinder works by using a built-in database of C/C++ functions with well-known problems, such as buffer overflow risks (e.g., strcpy(), strcat(), gets(), sprintf(), and the scanf() family), format string problems ([v][f]printf(), [v]snprintf(), and syslog()), race conditions (such as access(), chown(), chgrp(), chmod(), tmpfile(), tmpnam(), tempnam(), and mktemp()), potential shell metacharacter dangers (most of the exec() family, system(), popen()), and poor random number acquisition (such as random()). The good thing is that you don&#8217;t have to create this database &#8211; it comes with the tool.</p>
<p>Flawfinder then takes the source code text, and matches the source code text against those names, while ignoring text inside comments and strings (except for flawfinder directives). Flawfinder also knows about gettext (a common library for internationalized programs), and will treat constant strings passed through gettext as though they were constant strings; this reduces the number of false hits in internationalized programs. </p>
<p>You can download Flawfinder here:</p>
<p><a href="http://www.dwheeler.com/flawfinder/flawfinder-1.27.tar.gz">flawfinder-1.27.tar.gz</a></p>
<p></p>
<p>Or read more <a href="http://www.dwheeler.com/flawfinder/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Flawfinder+%E2%80%93+Source+Code+Auditing+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2065+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/&amp;t=Flawfinder+%E2%80%93+Source+Code+Auditing+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/&amp;title=Flawfinder+%E2%80%93+Source+Code+Auditing+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/&amp;title=Flawfinder+%E2%80%93+Source+Code+Auditing+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/&amp;title=Flawfinder+%E2%80%93+Source+Code+Auditing+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/&amp;title=Flawfinder+%E2%80%93+Source+Code+Auditing+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F09%2Fflawfinder-source-code-auditing-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Skavenger &#8211; source code auditing tool!</title>
		<link>http://www.darknet.org.uk/2007/11/skavenger-source-code-auditing-tool/</link>
		<comments>http://www.darknet.org.uk/2007/11/skavenger-source-code-auditing-tool/#comments</comments>
		<pubDate>Sat, 10 Nov 2007 03:34:20 +0000</pubDate>
		<dc:creator>backbone</dc:creator>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[code auditing tool]]></category>
		<category><![CDATA[code-auditing]]></category>
		<category><![CDATA[console]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[php auditing tool]]></category>
		<category><![CDATA[php code auditing]]></category>
		<category><![CDATA[php source code auditing]]></category>
		<category><![CDATA[skavenger]]></category>
		<category><![CDATA[source]]></category>
		<category><![CDATA[source code auditing]]></category>
		<category><![CDATA[source code auditing tool]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2007/11/skavenger-source-code-auditing-tool/</guid>
		<description><![CDATA[Skavenger? Yes, because scavenger is already used?!? What is skavenger? Skavenger is a source code auditing tool, firstly though for php, but also used for any kind of source code file; as long as you know what to look for&#8230; Yes I thought is as a replacement tool for egrep/sed under Windows! because not everybody [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Skavenger? Yes, because scavenger is already used?!?</p>
<p>What is skavenger? Skavenger is a source code auditing tool, firstly though for php, but also used for any kind of source code file; as long as you know what to look for&#8230;</p>
<p>Yes I thought is as a replacement tool for egrep/sed under Windows! because not everybody installs cygwin (for example) under there windows boxes to perform source code auditing. I&#8217;ve seen people who most of the time used notepad to audit source code!</p>
<p>And more&#8230;<br />
Skavenger is more than a replacement for egrep/sed because it has the ability to parse conforming to a regular expression or a series of regular expressions more than one file; even a directory; and prints out line number&#8230; isn&#8217;t that sup4 l33t?</p>
<p>Anyway&#8230; for download and more info check out <a href="http://code.google.com/p/skavenger/">http://code.google.com/p/skavenger/</a>, because you can have a lot of fun with it; did I mention it was a console application?</p>
<p>P.S. You need php in order to use this script. Default values in regex.def check for primordial sql injection and XSS&#8230;.<br />
P.P.S. For more things to search for under php, check my article at <a href="http://insanesecurity.wordpress.com/2007/10/30/source-code-audit-php/">http://insanesecurity.wordpress.com/2007/10/30/source-code-audit-php/</a></p>
<p></p>
<p>Happy auditing! </p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Skavenger+%E2%80%93+source+code+auditing+tool%21+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D738+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2007/11/skavenger-source-code-auditing-tool/&amp;t=Skavenger+%E2%80%93+source+code+auditing+tool%21" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2007/11/skavenger-source-code-auditing-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2007/11/skavenger-source-code-auditing-tool/&amp;title=Skavenger+%E2%80%93+source+code+auditing+tool%21" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2007/11/skavenger-source-code-auditing-tool/&amp;title=Skavenger+%E2%80%93+source+code+auditing+tool%21" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2007/11/skavenger-source-code-auditing-tool/&amp;title=Skavenger+%E2%80%93+source+code+auditing+tool%21" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2007/11/skavenger-source-code-auditing-tool/&amp;title=Skavenger+%E2%80%93+source+code+auditing+tool%21" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2007%2F11%2Fskavenger-source-code-auditing-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2007/11/skavenger-source-code-auditing-tool/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

