Hewlett-Packard will acquire Fortify Software to gain possession of its ability to perform analysis on source code to detect security risks and exposures.. For example, Fortify 360 Static Application Security Testing technology can examine source code and pick out exposures that result from poor or hurried programming. If a programmer has created a form where a user is to enter a zip code, but leaves space for 32 characters to be entered instead of five, 360 SAST would detect that. If the zip code were to be loaded from the form into a database, a 32-character space would open the door to an SQL injection attack. A hacker could put an SQL statement where the zip code was supposed to go and the database would act on it, once the injection was uploaded. The link for this article located at Information Week is no longer available. . For example, Fortify 360 Static Application Security Testing technology can examine source code and . hewlett-packard, acquire, fortify, software, possession, ability, perform, analysis. . LinuxSecurity.com Team
While there're lots of pros and cons to consider when it comes to automated source code scanning, Fortify's pricey automated source code analysis tool has the potential to prevent the most common vulnerabilities while the software's still in the development phrase. Recently, they've added 34 new categories of vulnerabilities to their product: . "Thanks to this effort, Fortify Software continues to lead the industry by identifying over 150 categories of vulnerabilities in software. The updated Secure Coding Rulepacks include: * Increased breadth: 34 new distinct vulnerability categories. * Enhanced support for .NET: 24 new vulnerability categories and coverage for five new third-party libraries, including the Microsoft Enterprise Library. * Expanded JSP support: Coverage for popular tag libraries, including JSTL and Apache Struts, for enhanced protection from cross-site scripting and SQL injection attacks. * Detection of persistent Cross-Site Scripting vulnerabilities: Fortify SCA now detects one of the most common and difficult to identify forms of cross-site scripting, which occurs when malicious data from an attacker is stored in a database and later included in dynamic content sent to a The link for this article located at Dancho Danchev is no longer available. . 'Thanks to this effort, Fortify Software continues to lead the industry by identifying over 150 cate. while, there're, consider, comes, automated, source, scanning. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.