<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; static analysis</title>
	<atom:link href="http://www.darknet.org.uk/tag/static-analysis/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>OWASP CodeCrawler &#8211; Static Code Review Tool</title>
		<link>http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/</link>
		<comments>http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 11:07:33 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[.net code review]]></category>
		<category><![CDATA[.net security]]></category>
		<category><![CDATA[code scanning tool]]></category>
		<category><![CDATA[code security]]></category>
		<category><![CDATA[code testing]]></category>
		<category><![CDATA[code-audit]]></category>
		<category><![CDATA[codecrawler]]></category>
		<category><![CDATA[development security]]></category>
		<category><![CDATA[J2EE-security]]></category>
		<category><![CDATA[JAVA-security]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[owasp codecrawler]]></category>
		<category><![CDATA[static analysis]]></category>
		<category><![CDATA[static code analysis tool]]></category>
		<category><![CDATA[static code review]]></category>
		<category><![CDATA[static code review tool]]></category>
		<category><![CDATA[static code security tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2510</guid>
		<description><![CDATA[CodeCrawler is a tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. It&#8217;s a Microsoft .NET 3.5 Windows Form application which supports the OWASP Code Review Project. It provides automatic STRIDE classification a very simple DREAD calculator and few minor [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>CodeCrawler is a tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. It&#8217;s a Microsoft .NET 3.5 Windows Form application which supports the OWASP Code Review Project.</p>
<p>It provides automatic STRIDE classification a very simple DREAD calculator and few minor utilities. Direct links to WAST 2.0 Threat Classification, Secure Java Development Guidelines and OWASP Tools are also part of the package. </p>
<p><strong>Requirements</strong></p>
<ul>
<li>.NET Framework 3.5 (Service Pack 1)</li>
<li>Visual Studio 2008</li>
<li>Windows Platform</li>
</ul>
<p>You can download CodeCrawler here:</p>
<p><a href="http://codecrawler.codeplex.com/releases/view/39345#DownloadId=102703">CODECRAWLER_2.5_RELEASE.zip</a></p>
<p></p>
<p>Or read more <a href="http://codecrawler.codeplex.com/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2510+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;t=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;title=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;title=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;title=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;title=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F03%2Fowasp-codecrawler-static-code-review-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Microsoft CAT.NET v1.1.1.9 &#8211; Binary Code Analysis Tool .NET</title>
		<link>http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/</link>
		<comments>http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 09:39:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[.net auditing tool]]></category>
		<category><![CDATA[.net security]]></category>
		<category><![CDATA[application-security]]></category>
		<category><![CDATA[binary code analysis]]></category>
		<category><![CDATA[binary-analysis]]></category>
		<category><![CDATA[cat.net]]></category>
		<category><![CDATA[code-auditing]]></category>
		<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[cross-site-scripting]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[software-security]]></category>
		<category><![CDATA[source code auditing tool]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[static analysis]]></category>
		<category><![CDATA[visual studio ide]]></category>
		<category><![CDATA[Visual-Studio]]></category>
		<category><![CDATA[windows-security]]></category>
		<category><![CDATA[xpath injection]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2321</guid>
		<description><![CDATA[CAT.NET is a binary code analysis tool that helps identify common variants of certain prevailing vulnerabilities that can give rise to common attack vectors such as Cross-Site Scripting (XSS), SQL Injection and XPath Injection. CAT.NET is a snap-in to the Visual Studio IDE that helps you identify security flaws within a managed code (C#, Visual [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>CAT.NET is a binary code analysis tool that helps identify common variants of certain prevailing vulnerabilities that can give rise to common attack vectors such as Cross-Site Scripting (XSS), SQL Injection and XPath Injection.</p>
<p>CAT.NET is a snap-in to the Visual Studio IDE that helps you identify security flaws within a managed code (C#, Visual Basic .NET, J#) application you are developing. It does so by scanning the binary and/or assembly of the application, and tracing the data flow among its statements, methods, and assemblies.</p>
<p>This includes indirect data types such as property assignments and instance tainting operations. The engine works by reading the target assembly and all reference assemblies used in the application — module-by-module — and then analyzing all of the methods contained within each. It finally displays the issues its finds in a list that you can use to jump directly to the places in your application’s source code where those issues were found.</p>
<p>The following rules are currently support by this version of the tool</p>
<ul>
<li>Cross Site Scripting</li>
<li>SQL Injection</li>
<li>Process Command Injection</li>
<li>File Canonicalization</li>
<li>Exception Information</li>
<li>LDAP Injection</li>
<li>XPATH Injection</li>
<li>Redirection to User Controlled Site</li>
</ul>
<p><strong>System Requirements</strong></p>
<p>Supported Operating Systems: Windows Vista; Windows XP</p>
<p>OS: XP, Vista Software: .NET Framework 2.0, Visual Studio 2005 or 2008. </p>
<p>You can download CAT.NET here:</p>
<p><a href="http://www.microsoft.com/downloads/info.aspx?na=90&#038;p=&#038;SrcDisplayLang=en&#038;SrcCategoryId=&#038;SrcFamilyId=0178e2ef-9da8-445e-9348-c93f24cc9f9d&#038;u=http%3a%2f%2fdownload.microsoft.com%2fdownload%2f3%2f3%2f4%2f334E8A84-0F1B-4E3C-AF5F-99DA8AE0601F%2fCATNETx32.msi">CATNETx32.msi</a></p>
<p></p>
<p>Or read more <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=0178e2ef-9da8-445e-9348-c93f24cc9f9d&#038;displaylang=en">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2321+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;t=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F12%2Fmicrosoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Flawfinder &#8211; Source Code Auditing Tool</title>
		<link>http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/</link>
		<comments>http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/#comments</comments>
		<pubDate>Wed, 16 Sep 2009 09:46:04 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[code auditing tool]]></category>
		<category><![CDATA[code-auditing]]></category>
		<category><![CDATA[flaw finder]]></category>
		<category><![CDATA[flawfinder]]></category>
		<category><![CDATA[source code auditing]]></category>
		<category><![CDATA[source code auditing tool]]></category>
		<category><![CDATA[static analysis]]></category>
		<category><![CDATA[static analysis tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2065</guid>
		<description><![CDATA[Flawfinder is a program that examines source code and reports possible security weaknesses (flaws) sorted by risk level. It&#8217;s very useful for quickly finding and removing at least some potential security problems before a program is widely released to the public. It&#8217;s a static analysis source code auditing tool. Flawfinder is specifically designed to be [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Flawfinder is a program that examines source code and reports possible security weaknesses (flaws) sorted by risk level. It&#8217;s very useful for quickly finding and removing at least some potential security problems before a program is widely released to the public. It&#8217;s a static analysis <a href="http://www.darknet.org.uk/tag/source-code-auditing/">source code auditing</a> tool.</p>
<p>Flawfinder is specifically designed to be easy to install and use. After installing it, at a command line just type:</p>
<pre><code>flawfinder directory_with_source_code</code></pre>
<p>Flawfinder works on Unix-like systems today (it&#8217;s been tested on GNU/Linux), and it should be easy to port to Windows systems. It requires Python 1.5 or greater to run (Python 1.3 or earlier won&#8217;t work).</p>
<p><strong>Speed</strong></p>
<p>Flawfinder is written in Python, to simplify the task of writing and extending it. Python code is not as fast as C code, but for the task I believe it&#8217;s just fine. Flawfinder version 0.12 on a 400Mhz Pentium II system analyzed 51055 lines in 39.7 seconds, resulting in an average of 1285 analyzed lines/second. Flawfinder 1.20 and later will report their speed (in analyzed lines/second) if you&#8217;re curious. </p>
<p><strong>How it works</strong></p>
<p>Flawfinder works by using a built-in database of C/C++ functions with well-known problems, such as buffer overflow risks (e.g., strcpy(), strcat(), gets(), sprintf(), and the scanf() family), format string problems ([v][f]printf(), [v]snprintf(), and syslog()), race conditions (such as access(), chown(), chgrp(), chmod(), tmpfile(), tmpnam(), tempnam(), and mktemp()), potential shell metacharacter dangers (most of the exec() family, system(), popen()), and poor random number acquisition (such as random()). The good thing is that you don&#8217;t have to create this database &#8211; it comes with the tool.</p>
<p>Flawfinder then takes the source code text, and matches the source code text against those names, while ignoring text inside comments and strings (except for flawfinder directives). Flawfinder also knows about gettext (a common library for internationalized programs), and will treat constant strings passed through gettext as though they were constant strings; this reduces the number of false hits in internationalized programs. </p>
<p>You can download Flawfinder here:</p>
<p><a href="http://www.dwheeler.com/flawfinder/flawfinder-1.27.tar.gz">flawfinder-1.27.tar.gz</a></p>
<p></p>
<p>Or read more <a href="http://www.dwheeler.com/flawfinder/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Flawfinder+%E2%80%93+Source+Code+Auditing+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2065+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/&amp;t=Flawfinder+%E2%80%93+Source+Code+Auditing+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/&amp;title=Flawfinder+%E2%80%93+Source+Code+Auditing+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/&amp;title=Flawfinder+%E2%80%93+Source+Code+Auditing+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/&amp;title=Flawfinder+%E2%80%93+Source+Code+Auditing+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/&amp;title=Flawfinder+%E2%80%93+Source+Code+Auditing+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F09%2Fflawfinder-source-code-auditing-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/09/flawfinder-source-code-auditing-tool/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>SpikeSource Spike PHP Security Audit Tool</title>
		<link>http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/</link>
		<comments>http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/#comments</comments>
		<pubDate>Tue, 01 Aug 2006 03:13:49 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[code auditing tool]]></category>
		<category><![CDATA[code-audit]]></category>
		<category><![CDATA[code-auditing]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[php-audit-tool]]></category>
		<category><![CDATA[php-security]]></category>
		<category><![CDATA[source code auditing]]></category>
		<category><![CDATA[spike]]></category>
		<category><![CDATA[spikesource]]></category>
		<category><![CDATA[static analysis]]></category>
		<category><![CDATA[web-application-security]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/</guid>
		<description><![CDATA[Spike is an Open Source tool based on the popular RATS C based auditing tool implemented for PHP. The tool Spike basically does static analysis of php code for security exploits, PHP5 and call-time pass-by-reference are currently required, but a PHP4 version is coming out this week. This tool is especially welcomed by Darknet as [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Spike is an Open Source tool based on the popular <a href="http://www.darknet.org.uk/2009/11/rats-rough-auditing-tool-for-security/">RATS</a> C based auditing tool implemented for PHP.</p>
<p>The tool Spike basically does static analysis of php code for security exploits, PHP5 and call-time pass-by-reference are currently required, but a PHP4 version is coming out this week.</p>
<p>This tool is especially welcomed by Darknet as there aren&#8217;t many static analysis tools out there that are free, and there are very few tools for auditing PHP code..which as we all known tends to be coded quite insecurely at times (just look at phpBB and PhpNUKE).</p>
<p>You can find the latest version here:</p>
<p></p>
<p><a href="http://developer.spikesource.com/projects/phpsecaudit">Spike PHP Audit Tool</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=SpikeSource+Spike+PHP+Security+Audit+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D307+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;t=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;title=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;title=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;title=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/&amp;title=SpikeSource+Spike+PHP+Security+Audit+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F08%2Fspikesource-spike-php-security-audit-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/08/spikesource-spike-php-security-audit-tool/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

