SpoC 007 - Code review Project

Back to SpoC 007 Selection page

AoC Candidate: Eoin Keary

Project coordinator: Dinis Cruz

Project Progress: 50% Complete, Progress Page

Executive Summary
I am proposing that I complete the OWASP Code review guide during this period. The code review guide was started by me in 2005 and has much information on reviewing code for common vulnerabilities. It is frequently accessed (looking at the stats on the OWASP site) and therefore is useful to practitioners.

I believe the code review guide is an integral part of the OWASP BOK (Body of Knowledge). Ensuring secure development is key to secure applications and code review is of paramount importance in this domain.

There are many sections still to be added and more to be readjusted and rewritten to reflect the current state of the security world. Much needs to be written on Web 2.0 technologies and distributed B2B technologies such as Webservices.

The Code review process and procedure needs also to be covered. A guide to establishing a mature code review process also needs to be done. Code review methodologies also need to be discussed.

Objectives and Deliverables
Update of the code review guide: * Add additional areas relating to the code review process such as: o Benefits and pitfalls o Methodology o The code review process + Transactional analysis + Managing the code review process + Assigning risk to findings

*         o Technical guides + Language specific best practice + Java + .NET + PHP + MySQL + Stored Procs + C/C++

*         o Code review by vulnerability: + Reviewing Code for Buffer Overruns and Overflows + Reviewing Code for OS Injection + Reviewing Code for SQL Injection + Reviewing Code for Data Validation + Reviewing code for XSS issues + Reviewing Code for Error Handling + Reviewing Code for Logging Issues + Reviewing The Secure Code Environment + Reviewing code for Authorization Issues + Reviewing code for Authentication Issues + Reviewing code for Session Integrity + Reviewing code for Cross Site Request Forgery + Reviewing code for Cryptography implementation issues + Reviewing code Dangerous HTTP Methods (Deployment) + Race Conditions

The areas of code are structured giving a brief explanation, the anti-pattern (vulnerable pattern to look for) and a suggested fix.

Why I should be sponsored for the project
I used to head up the code review team as part of the application security group in fidelity investments and have 5+ years of the secure code review process. I also was the lead of the Testing guide until V2 was published via the Autumn of Code.

I have always delivered any work I have volunteered for on time.

I have been involved in OWASP projects for 2/3 years now and have always been an active contributor.

Back to SpoC 007 Selection page