Demonstration of risky resource management

Assignment Help Computer Engineering
Reference no: EM132697149

Demonstrating Risky Resource Management

Overview

In this homework you use AWS Cloud 9 to create two different unique and complete demonstrations of Risky Resource Management such as Buffer Copy without Checking Size of Input, Improper Limitation of a Pathname to a Restricted Directory, Download of Code Without Integrity Check, Inclusion of Functionality from Untrusted Control Sphere, Use of Potentially Dangerous Function, Incorrect Calculation of Buffer Size, Uncontrolled Format String, and Integer Overflow or Wraparound.

You will provide unique code that contains the vulnerability and then provide an updated version of the code that fixes the vulnerability. You should also describe why the original code was vulnerable and discuss specific attack methods a user could try to exploit the vulnerability. Finally discuss how the new code fixes the vulnerability.

Assignment Details
Be sure you have carefully read and understand the materials in weeks 3 and 4.
1. Select 2 CWE/SANS Top 25 vulnerabilities under the category of Risky Resource Management from one of these specific issues:
a. Buffer Copy without Checking Size of Input,
b. Improper Limitation of a Pathname to a Restricted Directory ,
c. Download of Code Without Integrity Check, and
d. Inclusion of Functionality from Untrusted Control Sphere.
e. Use of Potentially Dangerous Function
f. Incorrect Calculation of Buffer Size
g. Uncontrolled Format String
h. Integer Overflow or Wraparound
Review and try the existing examples in links in the classroom. Use AWS Cloud 9 to experiment. Work in multiple languages where possible.
2. Using AWS Cloud 9, create your own unique example for each of the 2 vulnerabilities in this category.
3. Your code examples do not need to large or fully functional from an application standpoint. However; they need to include all of the code such that the vulnerability can be fully explained and corrected.
4. Use the information in the CWE/SANS Top 25 vulnerabilities to understand and experiment.
5. Be sure your documentation and descriptions are detailed and completed.
6. You may need to conduct additional research to better understand the vulnerability or the features associated with a specific language.

Attachment:- Vulnerability Assessment Report Template.rar

Reference no: EM132697149

Questions Cloud

Develop and implement a business plan : What are three reasons why an organisation should review their strategic, business and operational plans?
Why fire department treated the female employees as it did : Why do you think the fire department treated the female employees as it did? How do you think the fire department should have 'responded when the women.
Describe the role played by these tools : Describe the role played by these tools in the PDCA cycle using examples of how individual tools can fit into the process. Explain four different tools for each
Customer expect from customers when accessing reputations : What kinds of protections might a customer expect from other customers when accessing reputations?
Demonstration of risky resource management : Create two different unique and complete demonstrations of Risky Resource Management such as Buffer Copy without Checking Size
How would you characterize vetements letes strategy : Vêtements Ltée is a chain of men's retail clothing stores located throughout the province of Quebec, Canada. Two years ago, the company introduced new incentive
How well is the company strategy working : What are the company's competitively important resources and capabilities? how well is the company'sstrategy working? Evaluting a company's external environment
Cloud-based reputation checks is performance : One of the big challenges with cloud-based reputation checks is performance.
How would you characterize vetements letes strategy : Vêtements Ltée is a chain of men's retail clothing stores located throughout the province of Quebec, Canada. Two years ago, the company introduced new incentive

Reviews

Write a Review

Computer Engineering Questions & Answers

  How could information you gained enhance your knowledge base

How could the information you gained through reviewing this book on leadership enhance your knowledge base and development as a leader.

  A program that reads in an unspecified number of integers

The assignment number, your name, StudentID, Lecture number(time), and a class description need to be included at the top of each file/class.

  Write a python procedure to approximate gaussian function

Write a Python procedure to approximate the Gaussian function exp(-(x/3)2 ) in the range -8 ? +8 using Chebyshev polynomials.

  Express the concept and process of data binding

define the concept and process of Data Binding. Include an example of statements that would be used to create a Binding object. Explain the components and effects of your sample statement. Describe how to add, change, and delete records using boun..

  What about writing the first block

Reading the first block of a file from a remote file server is an idempotent operation. What about writing the first block?

  Write a java program to test if an array contain value

Write a Java program to test if an array contains a certain value. Input-The value (x), the items of the array

  Offer the average and worst case running time

offer the average and worst case running time and the space requirements.

  What types of business intelligence could be gathered

What specific types of business intelligence could be gathered from the database? How would this information assist in the decision-making process.

  Create a step-by-step it security policy

Using the guidelines provided in this week's chapter (and other resources as needed), create a step-by-step IT security policy for handling user accounts.

  Validate the input begins with a series of characters

expalin how cookies can be used to store information on a computer and how the information can be retrieved by a PHP program. Assume that cookies are not disabled on the client.

  System analysis and design

In the System Analysis and Design: Mixing Techniques – The question “Whether the structured techniques and object-oriented techniques can be mixed.

  Discuss the issue by giving examples in c pascal and java

Changing the value of a configuration constant requires recompilation. Discuss the issue by giving examples in C, Pascal, Modula-2, Java, C++, or Ada.

Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd