使用静态分析和 Clang 发现 Heartbleed
blog.trailofbits.com | 博客 | #openssl | #static-analysis | #vulnerability-detection | #compilers | #clang | #heartbleed
摘要
Trail of Bits 介绍用 Clang 静态分析发现 Heartbleed 类漏洞的方法:把 ntohl/ntohs 返回值标记为污点,检测未经约束即用作 memcpy 长度参数的用法,并在存在漏洞的 OpenSSL 代码上验证。
- 发布时间
- 收录时间
Skip to content