Source code audit tool

From: lupin (lupin9809_at_hotmail.com)
Date: 10/15/03

  • Next message: Axelle Apvrille: "Re: Source code audit tool"
    Date: 15 Oct 2003 12:32:44 -0000
    To: secprog@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    Hi,

    I looking for a source code auditing tool in order to find vulnerabilities in WEB applications as early as possible in the developement cycle.

    I would like to scan some JSP/servelts WEB application developped within WebSphere.

    My questions are:

    - Can we find some security vulnerabilty with a source code audit of java code? (Like for c/c++)

    - If yes, Is there a tool in order to do that automaticly?

    I've found the following applications:
    - Sanctum AppScan
    - SPI Dynamics WebInspect
    - Kavado Scando
    - OWASP Webscarab (open source)

    Yes, they check the WEB application overall security but not directly in the source code!

    Thank you in advance for your help.

    Marc


  • Next message: Axelle Apvrille: "Re: Source code audit tool"

    Relevant Pages

    • Re: Source code audit tool
      ... >I looking for a source code auditing tool in order to find vulnerabilities in WEB applications as early as possible in the developement cycle. ...
      (SecProg)
    • Re: gforth webserver, why isnt forth used all over ecommerce?
      ... CGI and ForthScript) servers requires 116kb of ROM. ... But even if your definitions of ASP and CGI and ForthScript are trivial abstractions that faintly reflect on the promise, at least if it comes from someone like you, maybe people here will finally understand that web applications are about more than the ability to serve web pages. ... That's seen in the antagonism against libraries and the elitist attitudes against programmers who choose to specialize or who have different core competencies they draw from. ... Are those source code libraries part of any public distribution of code? ...
      (comp.lang.forth)
    • Automatic source code audit tools?
      ... I would like to find some tools in order to do a source code audit. ... The idea is to find vulnerabilities in WEB applications the earliest ...
      (comp.security.misc)

  • Quantcast