SoftwareSecurity2013/Group 1
Uit Werkplaats
Group nr. 1 - GROUP 6 IN ADMIN
Group members:
- Erwin Middelesch
- Jeroen Senden
- Ruud Verbij
- Bas Stottelaar
- Ruben Lubben
All members are from the University of Twente.
Topic: Verification Requirements V5: Input Validation for FluxBB Version 1.4.5
Deliverables
- The log should be a chronological list of who has been doing what, with dates.
- Also useful to document decisions on who will be doing what, and by when.
- This should discuss the results of the code scanning, for the Verfication Requirements your group is looking at.
- Describe your impressions about the tools, in capabilities, limitations, etc.
- Also, did you learn anything about specific security vulnerabilities from using them?
- This should give your verdict for each requirement (Pass/Fail/Don't know) with motivation, and an indication of what you did to reach this verdict.
- Reflect on the whole process of doing a code review, or "Application Security Verification", in the way you did.
- How to setup FluxBB to start using it.
- Creating custom rules for Fortify to improve scanning results