Gentoo Archives: gentoo-hardened

From: Ned Ludd <solar@g.o>
To: gentoo-hardened@l.g.o
Cc: rumen_yotov@×××.bg
Subject: Re: [gentoo-hardened] flawfinder rats logs
Date: Mon, 20 Jun 2005 08:12:37
Message-Id: 1119255023.8154.8.camel@localhost
In Reply to: [gentoo-hardened] flawfinder rats logs by Rumen Yotov
On Mon, 2005-06-20 at 07:34 +0300, Rumen Yotov wrote:
> Hi, > Recently began using flawfinder& rats and they're working (logging things). > For now don't have time to look at the logs (beside *me* needing more > time to check them), so is there some place/person which > collects/is_interested in such info.
You should probably hold on to these. Most of us are capable of running these commands for ourselves.
> Maybe some meta-bug or other, or > just send they upstream (if correct)?
Real bugs should mailed upstream.
> Any experiences with them, are they correct?
Sadly neither of the tools can take into account program execution flows. I tend to view them these tools as pretty much nothing more than glorified grep commands. Handy if your looking for the obvious, but most of the obvious bugs have been fixed obviously for some time. Keep your logs. When you are sure you have pinpointed something that you know is a bug, then feel free to file a bug preferably with a patch that fixes the problem also. -- Ned Ludd <solar@g.o> -- gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] flawfinder rats logs Rumen Yotov <rumen_yotov@×××.bg>