|
Comments on: Blog
|
Security research, news and guidance
|
-
By: Hack In Paris 2011 | Segmentation fault
[...] the security code review Swiss army knife. David Rook expose sa vision de la revue de code : il ne s’agit pas de lire le maximum de lignes de code [...]
-
By: BSidesLondon Wrap Up « /dev/random
[...] David Rook presented his tool: “Agnitio: its static analysis, but not as we know it”. He introduced the concept of static analysis: review applications security without executing it. It can be performed manually or via tools (automated). Classic error: security issues are fixed too late in the SDLC process and cost a huge amount of money! A nice comparison was done between developers and drivers: What if we taught drivers in the same way as developers? Instructors will tell driver about the different ways to crash and inevitably the driver will crash! Then David switched to a deeper presentation of his tool “Agnitio“: [...]
|