资源描述:
《find security bugs学习笔记v10》由会员上传分享,免费在线阅读,更多相关内容在行业资料-天天文库。
1、www.gdtesting.com简介http://h3xstream.github.io/find-sec-bugs/FindSecurityBugsisapluginforFindBugsthataimtohelpsecurityauditonJavawebapplication.Somevulnerabilitycategoriescovered:EndpointsfromvariousframeworkCommandInjectionXPathInjectionXmleXternalEntity(XXE)Weakc
2、ryptographyTaintedinputsPredictablerandomSpecificlibraryweaknessXSSinJSPpageSQL/HQLinjectionReDOSPathtraversalFrameworkssupport:SpringMVCApacheTapestry5Struts1Struts2JaxRS(Jersey)JaxWS(Axis2,Metro)J2EEclassicWebapiApacheWicketFindSecurityBugshasatotalof38detectors
3、and45differentbugpatterns.Thecompletelistofbugpatternsarelistinthissection:http://h3xstream.github.io/find-sec-bugs/bugs.htmwww.gdtesting.comwww.gdtesting.comFindBugshttp://findbugs.sourceforge.net/ExperiencewithFindBugs(Google的FindBugs实践)·GoogleFindBugsFixit:Goog
4、lehasatraditionof engineeringfixits,specialdayswheretheytrytogetalloftheirengineersfocusedonsomespecificproblemortechniqueforimprovingthesystemsatGoogle.Afixitmightworktoimprovewebaccessibility,internaltesting,removingTODO'sfrominternalsoftware,etc.In2009,Googlehe
5、ldaglobalfixitforUMD'sFindBugstoolastaticanalysistoolforfindingcodingmistakesinJavasoftware.Thefocusofthefixitwastogetfeedbackonthe4,000highestconfidenceissuesfoundbyFindBugsatGoogle,andletGoogleengineersdecidewhichissues,ifany,neededfixing.www.gdtesting.comwww.gd
6、testing.comMorethan700engineersranFindBugsfromdozensofoffices.Morethan250ofthementeredmorethan8,000reviewsoftheissues.Areviewisaclassificationofanissueasmust-fix,should-fix,mostly-harmless,not-a-bug,andseveralothercategories.Morethan75%ofthereviewsclassifiedissues
7、asmustfix,shouldfixorIwillfix.Manyofthescariestissuesreceivedmorethan10reviewseach.Engineershavealreadysubmittedchangesthatmademorethan1,100ofthe3,800issuesgoaway.Engineersfiledmorethan1,700bugreports,ofwhich600havealreadybeenmarkedasfixedWorkcontinuesonaddressing
8、theissuesraisedbythefixit,andonsupportingtheintegrationofFindBugsintothesoftwaredevelopmentprocessatGoogle.ThefixitatGoogleshowcasednewcapabilitiesofFin