1 |
On Friday 05 September 2003 23:51, Ned Ludd wrote: |
2 |
> And a slightly improved patch that will make silly sounds and prompt for |
3 |
> user interaction before installing said code. |
4 |
> http://dev.gentoo.org/~solar/ebuild-flawfinder.diff |
5 |
Absolutely fantastic. |
6 |
|
7 |
> But from what I've seen in the last few mins of playing with this code |
8 |
> is that we will end up with alot of false postives. bin86 triggers at |
9 |
> level 5 about chmod vs fchmod but psmisc seems clean. |
10 |
It shows, that flawfinder is far from perfect :) |
11 |
the achievable security is as good as the scanner. If they get widely used, |
12 |
they will improve, i hope :) |
13 |
|
14 |
I get some sleep now and come back with ebuilds for some of the scanners in |
15 |
the next days + patches to ebuild.sh. |
16 |
|
17 |
At least it helps with an ebuild security policy for gentoo hardened that, |
18 |
except me, nobody addressed so far. It resides on my desk, top priority :) |
19 |
|
20 |
Jan |
21 |
|
22 |
|
23 |
-- |
24 |
gentoo-hardened@g.o mailing list |