25 Most Dangerous Software Coding Errors Hackers Exploit
Most of the vulnerabilities that hackers exploit to attack Web sites and corporate servers are usually the result of common and well-understood programming errors.
The Top 25 list can be an especially tool useful when companies are outsourcing work to a third-party or buying software from smaller vendors, he said.
The state of New York and other state governments are already planning to use it to help with software procurement. The idea is to get software developers to certify in writing that their code is free of the errors mentioned in the list, SANS said. It noted that the Common Criteria program used for federal procurement "may" also use the Top 25 list during the software buying process.
Another important audience for the list is the software programming community. The organizations behind the list hope that it will be used by application development teams to evaluate the security of code under development.
The developers of the list are also hoping that it will be useful at educational institutions in teaching programmers how to avoid errors. One of the organizations that participated in building the list was the University of California, Davis, which has established a secure coding clinic to check student-written software for the presence of the programming errors.
Microsoft



