Bugtraq mailing list archives
Re: StackGuard with ... Re: [Paper] Format bugs.
From: deraadt () CVS OPENBSD ORG (Theo de Raadt)
Date: Fri, 21 Jul 2000 15:52:24 -0600
There is no substitute, however, for a careful line-by-line audit of code.
In my mind, there never was. When this came up, we (Todd Miller, Todd Fries, and I) did an audit on our source tree for the following cases *printf() err*() warn*() syslog() setproctitle() hand-made log()-style functions which end up calling v*() functions I estimate it took three developers about 50 hours. Automated tools do not help because you still have to check for the last category by hand, so you might as well read everything. 50 hours isn't that bad. The problem, as I see it, is that we must keep redoing it. We might have missed something (but so do automated tools), and new stuff gets written all the time. We even found some in our kernel, though nothing all that exciting. As an aside, while doing the this "sub-audit", we noticed that we already had some fixed, which other projects hadn't fixed yet in their source trees. So we have looked for this before, without realizing that they were a big problem. That makes for a rather weird feeling..
Current thread:
- Security Update: DoS on gpm, (continued)
- Security Update: DoS on gpm Technical Support (Jul 20)
- Biometrics conference Farrow, Rik (Jul 17)
- Re: CheckPoint FW1 BUG Brian Krahmer (Jul 17)
- Re: CheckPoint FW1 BUG Nicolas FISCHBACH (Jul 18)
- [Paper] Format bugs. Pascal Bouchareine (Jul 18)
- (New ?) Macro security hole in Word 97 Bongard, Dominique (Jul 21)
- Re: (New ?) Macro security hole in Word 97 Bronek Kozicki (Jul 22)
- Jakarta-tomcat.../admin Scott Morris (Jul 21)
- StackGuard with ... Re: [Paper] Format bugs. Alan DeKok (Jul 21)
- [RHSA-2000:044-02] Updated PAM packages are available. bugzilla () REDHAT COM (Jul 21)
- Re: StackGuard with ... Re: [Paper] Format bugs. Theo de Raadt (Jul 21)
- Roxen security alert: Problems with URLs containing null characters. Peter Bortas (Jul 21)
- Re: StackGuard with ... Re: [Paper] Format bugs. Brett Glass (Jul 21)
- Re: StackGuard with ... Re: [Paper] Format bugs. Greg A. Woods (Jul 24)
- Re: StackGuard with ... Re: [Paper] Format bugs. Brett Glass (Jul 25)
- Re: StackGuard with ... Re: [Paper] Format bugs. mixter (Jul 24)
- Re: StackGuard with ... Re: [Paper] Format bugs. Linus Akesson (Jul 24)
- Re: StackGuard with ... Re: [Paper] Format bugs. Dan Harkless (Jul 25)
- Re: StackGuard with ... Re: [Paper] Format bugs. Valentin Nechayev (Jul 24)
- Re: StackGuard with ... Re: [Paper] Format bugs. Greg A. Woods (Jul 24)
- Re: StackGuard with ... Re: [Paper] Format bugs. Dick St.Peters (Jul 25)