Talk With an Expert

Source Code Revelation Vulnerabilities

Source Code Revelation Vulnerabilities (PDF, 1.61MB)Published: 30 Aug, 2001
Created by:
Christopher Short

Many security related articles and papers are concerned with protecting networks and servers from outside intrusion, and rightly so. This is understandable since many security professionals do not hail from a programming background. However, application security cannot be ignored in today's complex and competitive environment. The most commonly discussed aspect of application security concerns protecting an application from deliberate misuse such as buffer overruns and other such vulnerabilities. These can often be discovered or exploited without access to source code. However, protecting source code is a vital part of information security. Without debating the merits of open vs. closed source programming and business models, it is fair to say that not everyone wishes to share their source code with the world, either because it contains trade secrets or because the author or publisher chooses not to have code examined.