Demonstrating risky resource management

Assignment Help Software Engineering
Reference no: EM132701705

Demonstrating Risky Resource Management

Overview

In this homework you use AWS Cloud 9 to create two different unique and complete demonstrations of Risky Resource Management such as Buffer Copy without Checking Size of Input, Improper Limitation of a Pathname to a Restricted Directory, Download of Code Without Integrity Check, Inclusion of Functionality from Untrusted Control Sphere, Use of Potentially Dangerous Function, Incorrect Calculation of Buffer Size, Uncontrolled Format String, and Integer Overflow or Wraparound.

You will provide unique code that contains the vulnerability and then provide an updated version of the code that fixes the vulnerability. You should also describe why the original code was vulnerable and discuss specific attack methods a user could try to exploit the vulnerability. Finally discuss how the new code fixes the vulnerability.

Assignment Details
Be sure you have carefully read and understand the materials in weeks 3 and 4.
1. Select 2 CWE/SANS Top 25 vulnerabilities under the category of Risky Resource Management
from one of these specific issues:
a. Buffer Copy without Checking Size of Input,
b. Improper Limitation of a Pathname to a Restricted Directory ,
c. Download of Code Without Integrity Check, and
d. Inclusion of Functionality from Untrusted Control Sphere.
e. Use of Potentially Dangerous Function
f. Incorrect Calculation of Buffer Size
g. Uncontrolled Format String
h. Integer Overflow or Wraparound
Review and try the existing examples in links in the classroom. Use AWS Cloud 9 to experiment. Work in multiple languages where possible.
2. Using AWS Cloud 9, create your own unique example for each of the 2 vulnerabilities in this category.
3. Your code examples do not need to large or fully functional from an application standpoint. However; they need to include all of the code such that the vulnerability can be fully explained and corrected.
4. Use the information in the CWE/SANS Top 25 vulnerabilities to understand and experiment.
5. Be sure your documentation and descriptions are detailed and completed.
6. You may need to conduct additional research to better understand the vulnerability or the features associated with a specific language.

Attachment:- Vulnerability Assessment Report Template.rar

Reference no: EM132701705

Questions Cloud

Which bond has a higher yield : Coupon payments as Firm AA but with covenants that preclude the manager to engage in empire building. Which bond has a higher yield?
To release or note to release : Should the hospital release him with no place to go? If not, who will pay for his stay if it is no longer medically necessary?
What do you think is the organizations value proposition : What do you think is the organization's value proposition? Use the generic value propositions outlined in the Week 4 Overview. Describe the organization's.
Which callable bonds will be more expensive : Callable bonds with the same characteristics. If there is absolutely no connection between islands, which callable bonds will be more expensive?
Demonstrating risky resource management : Create two different unique and complete demonstrations of Risky Resource Management such as Buffer Copy without Checking Size of Input
Review your strategic plan and what resource would be needed : Work with your preceptor to assess the organization for required resources needed for the strategic plan if the change proposal were to be implemented.
Compute the ARR using the original investment : Depreciation is $40 per year with zero salvage value. Compute the ARR using the original investment
Which is the adjusted cost base of the preferred shares : Under the provisions of ITA 85(1), Which is the adjusted cost base of the preferred shares (first) and the adjusted cost base of the common shares (second)?
Discuss methods of alternative funding for care : Research and discuss two methods of alternative funding for care for this group. What are the benefits and limitations of the methods you discussed?

Reviews

Write a Review

Software Engineering Questions & Answers

  Prepare a table of entities and activities

Prepare a table of entities and activities.- Draw a context diagram.- Draw a physical data flow diagram (DFD).- Draw a level 0 logical DFD.

  Analyzing a real-time system

Understanding a real-time and time-critical system and Analyzing a real-time system and the flow of the corresponding software

  Analyzing project management

This solution utilizes the example of a specific project to install a complex, one hundred computer network for a corporation

  Explain the potential impact it has on everyday life

Crypto does not tend to advance quite as quickly as the general field of computer security, but events happen frequently that have an impact on the applied

  Benefits of web sites

You are to select 1 business that does not already have a Web site, and develop an Internet strategy for it. Most large corporations already have Web sites, so you may have to think of something on a smaller scale such as a local bike store. Sole ..

  Latest implementations of routing protocols

Discuss the latest implementations of routing protocols that would be used in the company's wide area network and the Internet.

  Create a uml class diagram for a survey class

Create a UML Class Diagram for a Survey class - The Survey class will have a static class variable that stores the current respondent's ID. As respondents complete the survey, this value will be incremented by one.

  Ray and jason have just finished developing the

ray and jason have just finished developing the documentation for a system your team recently completed. ray insists

  What measures should be taken to protect the firm

if the decision has been made by the firm that a client should be exited on account of the level of money laundering risk posed by the client, what risk issues in the exiting of the client and what measures should be taken to protect the firm agai..

  Discuss key problems associated with using packaged software

Discuss the key problems associated with using packaged software? How can these problems be minimized? Security and fitness of the software.

  Which is not a factor to consider in software evaluationa

which is not a factor to consider in software evaluation?a. performance effectivenessb. performance efficiencyc.

  Implement required design patterns and practise refactoring

ITECH2309 – Software Engineering - Federation University - Paired Software Development - implement the required design patterns and practise refactoring

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd