Listen "C++: A Cautionary Tale, or, 1 Hour Of Your Black Hat Trip is Spoken For by Thomas Ptacek, Matasano"
Episode Synopsis
A piece on Security Focus by Thomas talking about what talks at Black Hat you need to see:
>From the article:http://www.securityfocus.com/blogs/238
C++ gives you a resizeable string, so you won’t write splitvt. But in 2007, code vulnerabilities don’t look like splitvt anymore, ever. We’ve moved on, through off-by-one errors into integer overflows and now uninitialized variables. On balance, the bug classes C++ introduces are way scarier than the ones it takes off the table.
So, to kick off our series of posts about which Black Hat talks you should be going to this year, I’m going to recommend this one. Mark Dowd and John McDonald, on stage, talking about the ways C++ screws software security that you hadn't thought of before. "Recommend" is an understatement. If you get paid to find vulnerabilities in code, this is the most valuable talk at the conference this year.
>From the article:http://www.securityfocus.com/blogs/238
C++ gives you a resizeable string, so you won’t write splitvt. But in 2007, code vulnerabilities don’t look like splitvt anymore, ever. We’ve moved on, through off-by-one errors into integer overflows and now uninitialized variables. On balance, the bug classes C++ introduces are way scarier than the ones it takes off the table.
So, to kick off our series of posts about which Black Hat talks you should be going to this year, I’m going to recommend this one. Mark Dowd and John McDonald, on stage, talking about the ways C++ screws software security that you hadn't thought of before. "Recommend" is an understatement. If you get paid to find vulnerabilities in code, this is the most valuable talk at the conference this year.
More episodes of the podcast Black Hat Announcements
Black Hat USA 2010 Training: Assaulting IPS
09/03/2010
Free Black Hat March Webcast - Pen Testing the Web with Firefox by Michael Schearer ("theprez98")
04/03/2010
Black Hat USA 2010 Registration Now Open!
03/03/2010
Feb 18 Webcast
11/02/2010
Black Hat DC Keynote
21/01/2010
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.