• Jump to Left Menu
  • Jump to Right Menu
  • Jump to Main Content
  • Jump to Footer
  • Accessibility Page
IT-Director.com Logo

 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Register | Login to Member's Area

 
 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
  • Services
  • Channels
FEATURED EVENTS
  • Information Process Quality Improvement
    19th March - 21st March
    London, United Kingdom
  • Convergence Summit North 2012
    17th April - 18th April
    Manchester, United Kingdom
POPULAR PAPERS
  • Best practices for cloud security by Bloor Research
USEFUL LINKS
  • Last 7 Days
  • Archives
  • Top Articles
SHARE THIS PAGE
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Observations - "If you don't advertise yourself, you will be advertised by your loving enemies." - Elbert Hubbard

PAGE TOOLS
  • Request Reprints
  • Tell A Friend
  • Contact Author
RECENT POSTS
  • Kodak runs out of time and money
  • Yammer has plenty of ticker - Part 2
  • Yammer has plenty of ticker - Part 1
  • Nikon UK and the camping club keep shtum
  • A couple of user turn-offs, from Forbes and a national camping club
  • Some free tools for informavores
ADVERTISEMENT
BLOG ARCHIVE
  • January, 2012
  • December, 2011
  • November, 2011
  • October, 2011
  • September, 2011
  • July, 2011
  • June, 2011
  • May, 2011
  • April, 2011
  • March, 2011
  • February, 2011
  • January, 2011
Blogs > Office Jotter

I didn't mean that open!

Roger Whitehead By: Roger Whitehead, Director, Office Futures
Published: 8th October 2006
Copyright Office Futures © 2006

The Register — Google Code Search peers into programs’ flaws

Robert Lemos — 8 October 2006
Security professionals warned developers on Thursday that they need to be aware that their open-source repositories can now be easily mined, allowing attackers to target programs that are likely to be flawed. While Google could previously be used to look for specific strings, now the search engine riffles through code that much better.

“It is going deeper into places where code is publicly available, and it’s clearly picking up stuff really well,” said Chris Wysopal, chief technology officer of security startup Veracode. “This makes it easier and faster for attackers to find vulnerabilities - not for people that want to attack a (specific) Web site, but for people that want to attack any Web site.”

Google announced on Thursday that the tool is now available for public use. Google Code Search digs through open-source code repositories on the internet, compiling the large amount of source code available on the web into an easily searchable database. The tool allows Web surfers to find code that matches certain regular expressions, and searches can be limited to certain file types and licenses.

Google is not the first to offer this sort of service — see Krugle and Koders, for instance — but its name and consequent media coverage will ensure wide publicity and, probably, greater use.

There are fears being expressed that the Google service will expose weaknesses in people’s programs. The macho response to that is to say that they should have been better made in the first place. This would be of little comfort to users whose accounts get hacked because of an oversight by a coder or system administrator. Best to alert your nearest techie to the potential problem. If he or she says there’s nothing to worry about, make a record of it, if only as a CYA measure.

Other responses dwell on the humorous side of what is being found. (This is hacker humour, remember, not necessarily understandable by or tickling the funny bone of ordinary folk.) Jason Kottke has a starter list of these as well as the worrisome possibilities.

Reader Comments

The messages above were all contributed by IT-Director.com readers. Whilst we take care to remove any posts deemed inappropriate, we can take no responsibility for these comments. If you would like a comment removed please contact our editorial team.

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.



  • Report errors / Make Suggestions
  • | Site Map
  • | Terms of Use
  • | Privacy

Published by: IT Analysis Communications Ltd.
T: +44 (0)190 888 0760 | F: +44 (0)190 888 0761