SoftwareSecurity2012/Group 3/Log
Uit Werkplaats
Here we keep a logfile of our actions during this security analysis. We try to keep this as up to date as possible.
Logfile
Action: | Done by: | Date: | Time spent: | Comments: | Follow up actions: |
---|---|---|---|---|---|
Reading assignment, reading OWASP_ASVS pdf, downloading, installing and running CodeSecure. Reporting | Dima | 4/1/2012 | 4 hours | Useless tool due to license restrictions | This tool won't be usefull without paying |
Install, configure, run and analyze results of RATS | Stan | 4/16/2012 | 3 hours | Very limited tool for us | Might be worth checking which vulnerabilities are exactly checked for, it seems to use some kind of preset list. |
Writing about RIPS and RATS | Stan | 4/19/2012 | 2 hours | none | Progress made for deliverable. |
Install, configure, run and analyze results of YASCA. Writing about YASCA and CodeSecure | Dima | 4/19/2012 | 4 hours | none | Complete report on both. |
Start with dividing and reading about the requirements | Group | 4/25/2012 | 3 hours | Start with V6.1, most work | none |
Work on requirement V6.1, RIPS warnings | Stan | 4/25/2012 | 4 hours | Warnings divided into separate parts | none |
Work on requirement V6.1, YASCA | Dima | 4/25/2012 | 4 hours | none | none |
Work on requirement V6.1, RIPS warnings | Adrian | 4/22/2012 | 4 hours | Warnings divided into separate parts | none |
Work on requirement V6.1, RIPS warnings | Murad | 4/22/2012 | 4 hours | Warnings divided into separate parts | none |
Continue with requirement V6.1, discuss about other requirements | Group | 5/3/2012 | 5 hours | Decided to have Stan + Dima start on different requirements as well | none |
Check requirement V6.2 and V6.7 | Dima | 5/10/2012 | 4 hours | none | none |
Check requirement V6.3 | Stan | 5/10/2012 | 4 hours | none | none |
Continue with requirement V6.1 | Adrian + Murad | 5/10/2012 | 4 hours | none | none |
Start writing the wiki page about requirements | Stan + Dima | 5/17/2012 | 2 hours | General results about requirements | none |
Analyze remaining warnings from RIPS for requirement V6.1 | Stan + Adrian + Murad | 5/17/2012 | 3 hours | none | none |
Research requirement V6.8 | Dima | 5/17/2012 | 3 hours | Did not find any different interpreters | none |
Finalize requirement verification | Group | 6/14/2012 | 3 hours | none | none |
Look into additional email validation | Dima | 6/14/2012 | 2 hours | Since we had some time left | Fill in results on requirement page |
Write the reflection page | Stan | 6/14/2012 + 6/15/2012 | 5 hours | none | none |
Discuss about final verdicts for requirements | Group | 6/14/2012 | 2 hours | none | none |
Create draft presentation | Group | 6/17/2012 | 1 hours | none | none |
Meet to finish the last parts of requirements | Group | 6/20/2012 | 2 hours | Finished all the remaining results | none |
Finish reflection page | Group | 6/20/2012 | 2 hours | Reflection page finished | none |
Finalize and discuss presentation | Group | 6/20/2012 | 2 hours | none | none |