Pages: [1]   Go Down

Author Topic: THE TOP 25 MOST DANGEROUS PROGRAMMING ERRORS  (Read 283 times)

0 Members and 1 Guest are viewing this topic.

Popsikle

  • CoalitionLAN Staff
  • Ultra Kill
  • *****
  • Kudos: +0/-0
  • Offline Offline
  • Gender: Male
  • Posts: 891
    • View Profile
    • WWW
THE TOP 25 MOST DANGEROUS PROGRAMMING ERRORS
« on: January 13, 2009, 12:41:36 PM »
SANS came out with this list, bbc did a story on it.  Most of it is pretty basic stuff that everyone should be aware of, but I guess if it made this list not enough people are!

Quote
CWE-20:Improper Input Validation
CWE-116:Improper Encoding or Escaping of Output
CWE-89:Failure to Preserve SQL Query Structure
CWE-79:Failure to Preserve Web Page Structure
CWE-78:Failure to Preserve OS Command Structure
CWE-319:Cleartext Transmission of Sensitive Information
CWE-352:Cross-Site Request Forgery
CWE-362:Race Condition
CWE-209:Error Message Information Leak
CWE-119:Failure to Constrain Operations within the Bounds of a Memory Buffer
CWE-642:External Control of Critical State Data
CWE-73:External Control of File Name or Path
CWE-426:Untrusted Search Path
CWE-94:Failure to Control Generation of Code
CWE-494:Download of Code Without Integrity Check
CWE-404:Improper Resource Shutdown or Release
CWE-665:Improper Initialization
CWE-682:Incorrect Calculation
CWE-285:Improper Access Control
CWE-327:Use of a Broken or Risky Cryptographic Algorithm
CWE-259:Hard-Coded Password
CWE-732:Insecure Permission Assignment for Critical Resource
CWE-330:Use of Insufficiently Random Values
CWE-250:Execution with Unnecessary Privileges
CWE-602:Client-Side Enforcement of Server-Side Security

http://news.bbc.co.uk/2/hi/technology/7824939.stm
Logged

Manufacturer:     Popsikle Inc. * Processor:    AMD Athlon(tm) 64 X2 DCP 3800+, MMX, 3DNow (2 CPUs), ~2.0GHz * Memory:    1024MB RAM * Hard Drive:    74.3 GB x 2 10K rpm Raptros (Mirrored)  * Video Card:    GeForce 7800 GT SLI 512 MB  * Monitor:    1x Flatron L1720P LG, 1 17in CRT * Sound Card:    SB Audigy Audio [DF00]  * Speakers/Headphones:    Logitec 5.1 Surround Speaker Set * Mouse:    Logitec Mx 700

GenTsoChiken

  • Guest
Re: THE TOP 25 MOST DANGEROUS PROGRAMMING ERRORS
« Reply #1 on: January 13, 2009, 03:16:36 PM »
i dont see PEBKAC and ID-10-T errors :P
Logged
Pages: [1]   Go Up
« previous next »