This report serves as a template for analyzing the attack surface of firmware samples. Samples may
- source code
- compresed binary
- encrypted
- other
- C, C++
- PHP
- SH
- N/A
- source code
- compressed binary
- encrypted
- other
- C, C++
- PHP
- SH
- N/A
- OWASP
- SANS
- CERT
- CVE
- MITRE / CWE / CWE Top 25
- NVE
- PA-DSS
- Data / Input Validation
- Authentication
- Session Management
- Authorization
- Cryptography
- Error Handling
- Logging / Auditing
- Secure Code Environment
- Bad Coding Practices
-
Data / Input Validation
- CWE-665 Improper Initialization
- Stack Overflows
- Formatted Strings
-
Session Management
-
Authorization
- CWE-732 Incorrect Permission Assignment
-
Logging / Auditing