Re: Secure C programming



Chris Thomasson wrote:
"Rico Secada" <coolzone@xxxxx> wrote in message
news:20071230223029.f17f1c63.coolzone@xxxxxxxx
Hi.

Doesn't there exist any complete texts on what to do and not do when
programming in C, from a security perspective?

Preferably with examples.

Don't program C if you don't know how to avoid common pitfalls; C gets a
bad rap sometimes. It's the fault of all the _lazy/crap_ programmers out
there which frequently create applications that do not even seem to have
any sense of where there buffer(s) begin, or _end_!!

Yikes! ;^(...

Think your finger is pointing in the wrong direction. Anyone who knows humans
knows that an IQ of 100 is average. A person who designs something that they
know will be used by an average person but doesn't design it for use by such a
person is the one who should have the fault heaped on them. When the standard
library and strings were defined, security may not have been an issue. Bad
future prediction I will forgive. However I can't forgive the standards people
for continuing to permit it. Depreciated should be enforced. Yes, break the
program or make them compile it under the old standard.

.



Relevant Pages

  • Re: GCD(0,0)
    ... standard, nearly universal, while for others there are competing ... but it is barred in most of the texts I've looked at. ... well as many that bar it. ... Many abstract algebra and ring ...
    (sci.math)
  • Re: Process-based vs. Goal-based testing
    ... Appeal to authority will not convince me, nor will it convince many of ... the expert testers who read here. ... Most of the standard texts describe ...
    (comp.software.testing)
  • Re: How does Lakhdar spit so physically, whenever Angela installs the catholic novel very undoubtedl
    ... Are you standard, I mean, handling by means of charming ...
    (rec.skydiving)
  • Re: Stephen J Arnett - limit sin[xy]/y
    ... in responding to Robert Israel in the ... that texts differ in this matter. ... I think it is even possible that Anton, Strang ... nonstandard version of a standard concept. ...
    (sci.math)
  • Re: TRIM
    ... in F77 the loop will terminate after leniterations, in which case the value of i becomes undefined. ... Pray tell me why texts of the day stated that it was ... of the section cited in the Fortran 77 standard? ...
    (comp.lang.fortran)