SoftwareSecurity2013/Group 1

Uit Werkplaats
Ga naar: navigatie, zoeken
Ruud Verbij is working very hard on scanning all the code.
Code scanning 2.0

Group nr. 1 - GROUP 6 IN ADMIN

Group members:

  • Erwin Middelesch
  • Jeroen Senden
  • Ruud Verbij
  • Bas Stottelaar
  • Ruben Lubben

All members are from the University of Twente.

Topic: Verification Requirements V5: Input Validation for FluxBB Version 1.4.5

To-Do list

Deliverables

The log should be a chronological list of who has been doing what, with dates.
Also useful to document decisions on who will be doing what, and by when.
This should discuss the results of the code scanning, for the Verfication Requirements your group is looking at.
Describe your impressions about the tools, in capabilities, limitations, etc.
Also, did you learn anything about specific security vulnerabilities from using them?
This should give your verdict for each requirement (Pass/Fail/Don't know) with motivation, and an indication of what you did to reach this verdict.
Reflect on the whole process of doing a code review, or "Application Security Verification", in the way you did.
How to setup FluxBB to start using it.
Creating custom rules for Fortify to improve scanning results