[prev in list] [next in list] [prev in thread] [next in thread] 

List:       full-disclosure
Subject:    Re: [Full-disclosure] What are the basic vulnerabilities of a
From:       Nick FitzGerald <nick () virus-l ! demon ! co ! uk>
Date:       2010-05-31 21:42:44
Message-ID: 4C042D54.30141.5334DE13 () nick ! virus-l ! demon ! co ! uk
[Download RAW message or body]

rajendra prasad wrote:

> Hi List,
> I am preparing a list of main and basic vulnerabilities in software. Please
> let me know If you know other than the below list.

Why yes, I do...

> List of Basic Vulnerabilities:
> 1. Buffer Overflow: Stack, Heap.
> 2. Format String Vulnerabilities
> 3. SQL Injections
> 4. XSS Vulnerabilities

Cheating on a homework assignment?

Arguably only one of the above is a basic vulnerability (and even that 
is probably debatable) -- the other three are just examples of one or 
other basic types (and two of them are probably examples of the same 
basic type).  Try to get hold of the RISOS Project report(s) or sources 
that summarize that work.  Any good, basic CompSec textbook should 
cover this stuff, BUT there is more than one widely referenced 
comprehensive categorization of basic security errors, so you should 
probably check around a bit...



Regards,

Nick FitzGerald


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic