Home › News › Industry News
Google Code Search is a hacker's best friend
A new tool from Google that digs through open-source code repositories on the internet is causing concern for security professionals, mostly because the tool is just so damn good at what it does. Security professionals warned developers on Thursday of the need to be aware of Google Code Search being utilised to easily mine code for security flaws that are exploitable. A would-be attacker can now target programs that are likely to be flawed with much greater efficiency using this tool.
"It is going deeper into places where code is publicly available, and it's clearly picking up stuff really well," said Chris Wysopal, chief technology officer of security startup Veracode. "This makes it easier and faster for attackers to find vulnerabilities - not for people that want to attack a (specific) Web site, but for people that want to attack any Web site."
The tool allows users to easily find code that matches certain regular expressions, and searches can be limited to certain file types and licenses. It crawls and indexes publicly hosted archives (.tar.gz, .tar.bz2, .tar, and .zip) and CVS and Subversion repositories, making it an ideal tool to search for flaws in software.
Google's response to the warnings was to make it clear that the tool is intended for helping programmers find coding examples and obscure function definitions, and that it is not intended to help find exploitable security flaws in software.
"Google recommends developers use generally accepted good coding practices including understanding the implications of the code they implement and testing appropriately," the company said in a statement e-mailed to SecurityFocus.
"It is going deeper into places where code is publicly available, and it's clearly picking up stuff really well," said Chris Wysopal, chief technology officer of security startup Veracode. "This makes it easier and faster for attackers to find vulnerabilities - not for people that want to attack a (specific) Web site, but for people that want to attack any Web site."
The tool allows users to easily find code that matches certain regular expressions, and searches can be limited to certain file types and licenses. It crawls and indexes publicly hosted archives (.tar.gz, .tar.bz2, .tar, and .zip) and CVS and Subversion repositories, making it an ideal tool to search for flaws in software.
Google's response to the warnings was to make it clear that the tool is intended for helping programmers find coding examples and obscure function definitions, and that it is not intended to help find exploitable security flaws in software.
"Google recommends developers use generally accepted good coding practices including understanding the implications of the code they implement and testing appropriately," the company said in a statement e-mailed to SecurityFocus.
Related Stories
User Comments (2)
Post a comment|
dr3k
on October 13, 2006 7:37 PM |
'cry' boo hoo people will now have to write better code, HOW Horrible |
|
tpl2000
on February 1, 2007 9:20 PM |
i'm with dr3k. if there weren't security flaws in the first place, and they took an extra month to proofread and finish off their code, there would be hardly any problem with hackers. unless, of course, it's windows. hehehe. |
Most Popular
| Trending | Featured |
-
iOS 5.1.1 untethered jailbreak tool released, supports 4S, iPad 3
-
After five days, Facebook ranks as worst IPO flop of the decade
-
Rumor: Windows 8 RC will launch June 1, will ship with Adobe Flash
-
Rumor: AMD "Piledriver" FX CPU production to begin Q3 2012
-
Diablo III becomes the fastest-selling PC game in history
Editors' Monitor Picks
Subscribe to TechSpot
Get free exclusive content, learn about new features and tech breaking news.