also @ TechSpot: Rumor: AMD "Piledriver" FX CPU production to begin Q3 2012

Google Code Search is a hacker's best friend

By

On October 9, 2006, 7:12 AM EST

A new tool from Google that digs through open-source code repositories on the internet is causing concern for security professionals, mostly because the tool is just so damn good at what it does. Security professionals warned developers on Thursday of the need to be aware of Google Code Search being utilised to easily mine code for security flaws that are exploitable. A would-be attacker can now target programs that are likely to be flawed with much greater efficiency using this tool.

"It is going deeper into places where code is publicly available, and it's clearly picking up stuff really well," said Chris Wysopal, chief technology officer of security startup Veracode. "This makes it easier and faster for attackers to find vulnerabilities - not for people that want to attack a (specific) Web site, but for people that want to attack any Web site."
The tool allows users to easily find code that matches certain regular expressions, and searches can be limited to certain file types and licenses. It crawls and indexes publicly hosted archives (.tar.gz, .tar.bz2, .tar, and .zip) and CVS and Subversion repositories, making it an ideal tool to search for flaws in software.

Google's response to the warnings was to make it clear that the tool is intended for helping programmers find coding examples and obscure function definitions, and that it is not intended to help find exploitable security flaws in software.

"Google recommends developers use generally accepted good coding practices including understanding the implications of the code they implement and testing appropriately," the company said in a statement e-mailed to SecurityFocus.

Related Stories

No tags on this story

User Comments (2)

Post a comment
dr3k
on October 13, 2006
7:37 PM
'cry' boo hoo people will now have to write better code, HOW Horrible

Reply

tpl2000
on February 1, 2007
9:20 PM
i'm with dr3k. if there weren't security flaws in the first place, and they took an extra month to proofread and finish off their code, there would be hardly any problem with hackers. unless, of course, it's windows. hehehe.

Reply

Browse more commented news

Post a new comment

Guest user

To post as an anonymous
user click here
.

Members

If you are a TechSpot member,
please login first.


By signing up you gain complete access to the TechSpot community. Join thousands of computer and technology enthusiasts that contribute and share knowledge in our forum. Post messages, get a private inbox, upload your own photo gallery and more.

Subscribe to TechSpot

Get free exclusive content, learn about new features and tech breaking news.