Re: malicious code

From: Crispin Cowan (crispin@wirex.com)
Date: 01/28/03

  • Next message: Ed Carp: "safe strcpy()?"
    Date: Mon, 27 Jan 2003 21:31:59 -0800
    From: Crispin Cowan <crispin@wirex.com>
    To: Jeff Williams <jsquared@erols.com>
    
    
    

    Jeff Williams wrote:

    >I'm not looking for technology. It is going to be a very long time before
    >software can even find unintentional security errors. I was hoping that
    >someone had done some research on how human code review can find malicious
    >logic. Is the problem exactly the same as searching for inadvertent
    >security flaws, or are there specialized techniques for searching out
    >malicious logic.
    >
    Given that a would-be attacker who wants to embed a back door in a
    program can do so by embedding code that looks *exactly* like an
    inadvertent security flaw, then I'd say yes, looking for malicious code
    is exactly like a security audit for inadvertent flaws. Overt back doors
    are just easier to see.

    What better way to leave a back door in code than to deposit a half
    dozen subtle buffer overflows?

    Crispin

    -- 
    Crispin Cowan, Ph.D.
    Chief Scientist, WireX                      http://wirex.com/~crispin/
    Security Hardened Linux Distribution:       http://immunix.org
    Available for purchase: http://wirex.com/Products/Immunix/purchase.html
    			    Just say ".Nyet"
    
    




    Relevant Pages

    • RE: Pentester convicted..
      ... and *purposefully* pushed against the door ... When people go look for and find security problems, ... Download FREE whitepaper on how a managed service can ...
      (Pen-Test)
    • RE: Pentester convicted..
      ... If you are walking down a business district strip and just happen to come upon a door that is ajar and report it -- hey thanks for the heads up. ... A security pro notices a flaw, checks to make sure he is not on crack by ... Download FREE whitepaper on how a managed service can ...
      (Pen-Test)
    • Re: Pentester convicted..
      ... The open front door of the store is more likely an error or error message in the Web application that EVERYONE can see: ... A security pro notices a flaw, checks to make sure he is not on crack by ... Download FREE whitepaper on how a managed service can ... Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. ...
      (Pen-Test)
    • Re: hacking through electric outlets!!!
      ... operating system and computer hardware with some actual security built ... wide open door to anyone with the $k1II5. ... Today if you want a shielded computer you ... Nobody cares. ...
      (sci.physics)
    • Re: Pentester convicted..
      ... I notice the door gives a little bit - and out of curiousity and concern, ... I immediately stop what I am doing, and notify the owners and the authorities ... don't report issues to exploit them. ... A security pro notices a flaw, checks to make sure he is not on crack by ...
      (Pen-Test)