Sign In
Spot the Bug!
Do you think you have the skills to find security vulnerabilities before they find you? See if you can Spot the Bug!
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
Bug Squashed
Microsoft Developer Security
Personal Blabbering
Spot the Bug
Archive
Archives
May 2007
(1)
March 2006
(2)
February 2006
(1)
January 2006
(1)
December 2005
(1)
November 2005
(1)
October 2005
(1)
August 2005
(4)
July 2005
(5)
March 2005
(3)
February 2005
(1)
January 2005
(2)
August, 2005
MSDN Blogs
>
Spot the Bug!
>
August, 2005
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Spot the Bug!
Spot the Bug - August 31, 2005
Posted
over 7 years ago
by
Rick Samona
15
Comments
It's been a little while since we've had a new bug up. We had some good feedback on the last one. Here is a shorter one: Courtesy of Shanit Gupta, Consultant (Foundstone) try { ElevatePrivilege(); ReadSecretFile(); LowerPrivilege(); } catch(FileException...
Spot the Bug!
Spot the Bug - August 16, 2005
Posted
over 7 years ago
by
Rick Samona
9
Comments
If you haven't taken a look at the solution to the last bug, please do so. There were 4 bugs in that short chink of code -- all of which are found in Visual Studio 2005! One is issued as a compiler warning and the other 3 are found by PREfast. Here...
Spot the Bug!
Spot the Bug - August 14, 2005
Posted
over 7 years ago
by
Rick Samona
9
Comments
I created this bug a couple of weeks ago for a conference I spoke at to illustrate how so few lines of code could be so buggy. Where's the bug here? char dest[50], src[100]; int x, y; if (x=1) { strcpy(dest,src); dest[50] = '\0'; } return y;...
Spot the Bug!
Spot the Bug - August 4, 2005
Posted
over 7 years ago
by
Rick Samona
5
Comments
I think the last bug stumped a few people. Can you find the security vulnerability in this one? Courtesy of Neelay Shah, Consultant, Foundstone #define STD_HASH_LEN 11 #define MAX_HASH_LEN 31 char * strPassHash = (char*)malloc(sizeof(char)*STD_HASH_LEN...
Page 1 of 1 (4 items)