SoftwareSecurity2012/Group 3/Log

Uit Werkplaats
Ga naar: navigatie, zoeken

Here we keep a logfile of our actions during this security analysis. We try to keep this as up to date as possible.

Logfile

Action: Done by: Date: Time spent: Comments: Follow up actions:
Reading assignment, reading OWASP_ASVS pdf, downloading, installing and running CodeSecure. Reporting Dima 4/1/2012 4 hours Useless tool due to license restrictions This tool won't be usefull without paying
Install, configure, run and analyze results of RATS Stan 4/16/2012 3 hours Very limited tool for us Might be worth checking which vulnerabilities are exactly checked for, it seems to use some kind of preset list.
Writing about RIPS and RATS Stan 4/19/2012 2 hours none Progress made for deliverable.
Install, configure, run and analyze results of YASCA. Writing about YASCA and CodeSecure Dima 4/19/2012 4 hours none Complete report on both.
Start with dividing and reading about the requirements Group 4/25/2012 3 hours Start with V6.1, most work none
Work on requirement V6.1, RIPS warnings Stan 4/25/2012 4 hours Warnings divided into separate parts none
Work on requirement V6.1, YASCA Dima 4/25/2012 4 hours none none
Work on requirement V6.1, RIPS warnings Adrian 4/22/2012 4 hours Warnings divided into separate parts none
Work on requirement V6.1, RIPS warnings Murad 4/22/2012 4 hours Warnings divided into separate parts none
Continue with requirement V6.1, discuss about other requirements Group 5/3/2012 5 hours Decided to have Stan + Dima start on different requirements as well none
Check requirement V6.2 and V6.7 Dima 5/10/2012 4 hours none none
Check requirement V6.3 Stan 5/10/2012 4 hours none none
Continue with requirement V6.1 Adrian + Murad 5/10/2012 4 hours none none
Start writing the wiki page about requirements Stan + Dima 5/17/2012 2 hours General results about requirements none
Analyze remaining warnings from RIPS for requirement V6.1 Stan + Adrian + Murad 5/17/2012 3 hours none none
Research requirement V6.8 Dima 5/17/2012 3 hours Did not find any different interpreters none
Finalize requirement verification Group 6/14/2012 3 hours none none
Look into additional email validation Dima 6/14/2012 2 hours Since we had some time left Fill in results on requirement page
Write the reflection page Stan 6/14/2012 + 6/15/2012 5 hours none none
Discuss about final verdicts for requirements Group 6/14/2012 2 hours none none
Create draft presentation Group 6/17/2012 1 hours none none
Meet to finish the last parts of requirements Group 6/20/2012 2 hours Finished all the remaining results none
Finish reflection page Group 6/20/2012 2 hours Reflection page finished none
Finalize and discuss presentation Group 6/20/2012 2 hours none none