Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




Vulnerability Development mailing list archives

Re: BitchX /ignore bug
From: 11a () GMX NET (Bluefish)
Date: Fri, 7 Jul 2000 16:30:05 +0200


Is it the teachers' fault, can anyone be blamed? More
importantly, is there anything (short of Java, or any change in language)
that can be done about it?

My experience from 2 years of undergraduate master of science eductation,
is that there's never any mentioning of "insecure" programming. In the
computer security course I took there was some mentioning of buffert
overflows and similar threats, but isn't enough to ensure that code is
written moderately well. And the security course is entirely optional.

Actually, I fear it's the same at most universities. The avarage computer
science students leaves his/her education with hardly any knowledge of
security, and if (s)he has been taught any of it, it has been too
theoretical.

The problem is that security hasn't really been a *real* practice before
the 1980, and it only been somewhat "hot" since 1990. Currently, most
companies and educations still don't take security really seriously. If
they do, it is usually only about getting the magic "C2" which makes
people buy the system (because they don't really know what C2 is)

      Imagine how little we would know if this were
closed source. *Someone* would notice a segmentation violation sometime,
fire up a debugger, produce an exploit, and finally an advisory would be
written. We wouldn't really know a thing. Who knows how long these things
would go unpatched for?

Agree. Although we see numerous people doing really lazy and stupid coding
in GNU, Linux, FreeBSD projects etc, it is from these misstakes most
people learn security today. Because socity still doesn't reallize that
every developer needs a moderate clue about security. When it comes to
security today, it is far easier to scream for punishment for the
induviduals involved in abuse, than to make the changes needed.

..:::::::::::::::::::::::::::::::::::::::::::::::::..
     http://www.11a.nu || http://bluefish.11a.nu
    eleventh alliance development & security team


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]