<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2-ppt DokuWiki" -->
<?xml-stylesheet href="http://oss-security.openwall.org/wiki/lib/exe/css.php?s=feed" type="text/css"?>
<feed version="0.3" xmlns="http://purl.org/atom/ns#">
    <title>OSS-Security</title>
    <tagline></tagline>
    <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/"/>
    <id>http://oss-security.openwall.org/wiki/</id>
    <modified>2010-09-05T15:29:13-07:00</modified>
    <generator>FeedCreator 1.7.2-ppt DokuWiki</generator>
    <entry>
        <title>about</title>
        <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/about?rev=1211509210"/>
        <created>2008-05-22T19:20:10-07:00</created>
        <issued>2008-05-22T19:20:10-07:00</issued>
        <modified>2008-05-22T19:20:10-07:00</modified>
        <id>http://oss-security.openwall.org/wiki/about?rev=1211509210</id>
        <summary>The Open Source Security (oss-security) wiki and mailing list are a product of co-operation amongst various open source software vendors, projects, and researchers. The purpose of the oss-security group is to encourage public discussion of security flaws, concepts, and practices in the Open Source community.</summary>
    </entry>
    <entry>
        <title>code-reviews</title>
        <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/code-reviews?rev=1253700072"/>
        <created>2009-09-23T03:01:12-07:00</created>
        <issued>2009-09-23T03:01:12-07:00</issued>
        <modified>2009-09-23T03:01:12-07:00</modified>
        <id>http://oss-security.openwall.org/wiki/code-reviews?rev=1253700072</id>
        <summary>This page will hopefully soon consist of many code review reports with proper description of project/version/architecture/possible flaws and security relevant patches.

As a start, I will add some packages which are common across a lot of Linux distributions and have been identified as a potential risk since they either run privileged or with network input. Feel free to add other OS's or move to another, separate, page. The intention is NOT to enumerate all possibly problematic packages such as …</summary>
    </entry>
    <entry>
        <title>disclosure</title>
        <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/disclosure?rev=1265740420"/>
        <created>2010-02-09T10:33:40-07:00</created>
        <issued>2010-02-09T10:33:40-07:00</issued>
        <modified>2010-02-09T10:33:40-07:00</modified>
        <id>http://oss-security.openwall.org/wiki/disclosure?rev=1265740420</id>
        <summary>Flaw Disclosure

Anytime an individual discovers a security flaw, there are certain steps that should be taken to ensure that the details of the flaw are disclosed in a responsible and acceptable manner.  Reporting a flaw in open source software poses a number of unique challenges compared to the closed source counterparts.</summary>
    </entry>
    <entry>
        <title>distro-patches</title>
        <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/distro-patches?rev=1273423000"/>
        <created>2010-05-09T09:36:40-07:00</created>
        <issued>2010-05-09T09:36:40-07:00</issued>
        <modified>2010-05-09T09:36:40-07:00</modified>
        <id>http://oss-security.openwall.org/wiki/distro-patches?rev=1273423000</id>
        <summary>This page lists how to find and extract patches from various open source-providing vendors, such as distributors of Linux, *BSD, and other related operating systems.  See the general Vendor information page for details on where to find security announcements.</summary>
    </entry>
    <entry>
        <title>infrastructure</title>
        <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/infrastructure?rev=1211910862"/>
        <created>2008-05-27T10:54:22-07:00</created>
        <issued>2008-05-27T10:54:22-07:00</issued>
        <modified>2008-05-27T10:54:22-07:00</modified>
        <id>http://oss-security.openwall.org/wiki/infrastructure?rev=1211910862</id>
        <summary>This page lists security contacts, status links, etc. for various open source-providing infrastructure folks.

When adding to this page, please include the following vendor information: 

	*  email address for the security contact
	*  link to FAQ
	*  link to network/service status information (i.e. scheduled down-times)
	*  link to issue tracker (i.e. Bugzilla)</summary>
    </entry>
    <entry>
        <title>links</title>
        <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/links?rev=1208193739"/>
        <created>2008-04-14T10:22:19-07:00</created>
        <issued>2008-04-14T10:22:19-07:00</issued>
        <modified>2008-04-14T10:22:19-07:00</modified>
        <id>http://oss-security.openwall.org/wiki/links?rev=1208193739</id>
        <summary>Here is a list of other websites with OSS-security-related information (be it articles, tutorials, general information, etc.)

Vulnerability databases and security advisory archives

	*  &lt;http://cve.mitre.org&gt; - MITRE's CVE (Common Vulnerabilities and Exposures) dictionary
	*  &lt;http://nvd.nist.gov&gt; - NIST's NVD (National Vulnerability Database)
	*  &lt;http://osvdb.org&gt; - OSVDB (The Open Source Vulnerability Database)
	*  &lt;http://www.linuxsecurity.com/content/section/3/170/&gt; - LinuxSecurity.com adv…</summary>
    </entry>
    <entry>
        <title>mailing-lists</title>
        <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/mailing-lists?rev=1211509210"/>
        <created>2008-05-22T19:20:10-07:00</created>
        <issued>2008-05-22T19:20:10-07:00</issued>
        <modified>2008-05-22T19:20:10-07:00</modified>
        <id>http://oss-security.openwall.org/wiki/mailing-lists?rev=1211509210</id>
        <summary>This page provides links to a number of security-related mailing list resources.

Public Lists

	*  &lt;oss [dash] security [at] lists [dot] openwall [dot] com&gt;: The open source software security mailing list (oss-security), which is a counter-part to this wiki.  This is a public mailing list for anyone to subscribe to.  Non-members may post to the list, however their messages will be moderated before release.  This list is an open list for open source software authors and vendors to discuss public security issues.
		*  o…</summary>
    </entry>
    <entry>
        <title>mailinglists</title>
        <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/mailinglists?rev=1211510187"/>
        <created>2008-05-22T19:36:27-07:00</created>
        <issued>2008-05-22T19:36:27-07:00</issued>
        <modified>2008-05-22T19:36:27-07:00</modified>
        <id>http://oss-security.openwall.org/wiki/mailinglists?rev=1211510187</id>
        <summary>This page has moved.</summary>
    </entry>
    <entry>
        <title>software</title>
        <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/software?rev=1264782670"/>
        <created>2010-01-29T08:31:10-07:00</created>
        <issued>2010-01-29T08:31:10-07:00</issued>
        <modified>2010-01-29T08:31:10-07:00</modified>
        <id>http://oss-security.openwall.org/wiki/software?rev=1264782670</id>
        <summary>This is a list of various open source software projects with links to security contacts for the project.  Please only list those projects that do have a security contact to list!  The contact may be an email address or a web page with more information.</summary>
    </entry>
    <entry>
        <title>tools</title>
        <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/tools?rev=1253700325"/>
        <created>2009-09-23T03:05:25-07:00</created>
        <issued>2009-09-23T03:05:25-07:00</issued>
        <modified>2009-09-23T03:05:25-07:00</modified>
        <id>http://oss-security.openwall.org/wiki/tools?rev=1253700325</id>
        <summary>This page will give you some hints about which tools might be used to gather useful information during a code review such as debuggers, static and dynamic code analysis tools etc.

cscope

With the help of cscope, reviewers can comfortable search for symbols in the source code of programs. It allows to search for definitions/declarations and calls of certain functions, macro definitions etc.. Most Linux and BSD distributions ship cscope.</summary>
    </entry>
    <entry>
        <title>vendors</title>
        <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/vendors?rev=1275681529"/>
        <created>2010-06-04T12:58:49-07:00</created>
        <issued>2010-06-04T12:58:49-07:00</issued>
        <modified>2010-06-04T12:58:49-07:00</modified>
        <id>http://oss-security.openwall.org/wiki/vendors?rev=1275681529</id>
        <summary>This page lists security contacts, bug tracker links, links to advisories, etc. for various open source-providing vendors, such as distributors of Linux, *BSD, and other related operating systems.

When adding to this page, please include the following vendor information:</summary>
    </entry>
    <entry>
        <title>welcome</title>
        <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/welcome?rev=1232297677"/>
        <created>2009-01-18T08:54:37-07:00</created>
        <issued>2009-01-18T08:54:37-07:00</issued>
        <modified>2009-01-18T08:54:37-07:00</modified>
        <id>http://oss-security.openwall.org/wiki/welcome?rev=1232297677</id>
        <summary>Welcome to the Open Source Software Security Wiki.  This wiki provides information on a variety of open source security resources and “best practices” information.  It is also the counterpart to the oss-security mailing list.  Please note that registration on this wiki is distinct from mailing list subscription; you're not automatically subscribed when you register on the wiki.</summary>
    </entry>
    <entry>
        <title>whattodo</title>
        <link rel="alternate" type="text/html" href="http://oss-security.openwall.org/wiki/whattodo?rev=1211509210"/>
        <created>2008-05-22T19:20:10-07:00</created>
        <issued>2008-05-22T19:20:10-07:00</issued>
        <modified>2008-05-22T19:20:10-07:00</modified>
        <id>http://oss-security.openwall.org/wiki/whattodo?rev=1211509210</id>
        <summary>This page is designed to teach folks who may not be familiar with security what the generally accepted procedures are, and why they exist.

When a user or security researcher submits a bug to a maintainer of an open-source project, there are a number of factors that determine the proper course of action.  The most basic is who is known to consume the software.  If all your users obtain the code directly from your site, do not modify it, and are not known to redistribute it, it is probably OK to …</summary>
    </entry>
</feed>
