Re: improved C1X security



Robert Seacord said:

Keith,

Response below:


encode_pointer(), decode_pointer() - useful in eliminating attack
vectors

Can you explain just what these are supposed to do?

There will be a paper on these functions in the WG14 mailing, which
should be out any moment now.

I wasn't planning on proposing these (as they were already being
proposed). I listed them as an example of what I was talking about.

We have a short write up on these functions in The CERT C Secure Coding
Standard here if you want to read more now:


https://www.securecoding.cert.org/confluence/display/seccode/MSC16-C.+Consider+encrypting+function+pointers

Not so long ago I started reviewing the "CERT C" stuff in painstaking
detail, posting the results here (and on my site), but I got so little
feedback from the authors that I stopped bothering.

In general, I was disappointed with the "CERT C" document, and I don't know
of any reason why anything should suddenly have changed for the better.

--
Richard Heathfield <http://www.cpax.org.uk>
Email: -http://www. +rjh@
Google users: <http://www.cpax.org.uk/prg/writings/googly.php>
"Usenet is a strange place" - dmr 29 July 1999
.



Relevant Pages

  • Re: improved C1X security
    ... Response below: ... There will be a paper on these functions in the WG14 mailing, which should be out any moment now. ... I wasn't planning on proposing these. ...
    (comp.lang.c)
  • Re: Proposal for a new PKI model (At least I hope its new)
    ... >> Do you enjoy getting the shaft? ... >> proposing? ... maximum level certs, you can require that both entities sign your domain ... accidently grant a hacker an MS code signing cert. ...
    (sci.crypt)
  • Re: IIS does not listen on ssl port
    ... Thanks for the response. ... I don't believe the issue is in the cert ... must have something to do with IIS and the website. ... then setup static port forwards that point all data sent to ...
    (microsoft.public.inetserver.iis.security)
  • Re: Deleted certificate request
    ... sent that in to get the cert (I still have the .txt file that was ... pending certificate request for this response file was not found. ...
    (microsoft.public.inetserver.iis.security)
  • Re: "The signature or decryption was invalid"
    ... piece of these security headers? ... > We continue to have a problem with a simple signed response using WSE ... > We keep getting the following error message: ... > I'm using a Cert generated by our Cert Authority to generate a Client ...
    (microsoft.public.dotnet.framework.webservices.enhancements)