OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: BitchX /ignore bug
From: Crispin Cowan (crispinWIREX.COM)
Date: Fri Jul 07 2000 - 12:32:27 CDT


Bluefish wrote:

> Does anyone know of a site or book which simply is a long list of
> "do not" along with a short explanation of "why"? I would enjoy reading
> such a site/book a lot. And it would definatly be a good studdy material
> for most programmers.

The classic is Matt Bishop's "Writing Safe Setuid Programs"
http://olympus.cs.ucdavis.edu/~bishop/secprog.html

Crispin

--
Crispin Cowan, CTO, WireX Communications, Inc.    http://wirex.com
Free Hardened Linux Distribution:                 http://immunix.org
        Security JOB:  http://immunix.org/jobs.html