diff --git "a/openKylin-C&C++\350\257\255\350\250\200Fortify\344\273\243\347\240\201\345\256\211\345\205\250\346\243\200\346\237\245.md" "b/openKylin-C&C++\350\257\255\350\250\200Fortify\344\273\243\347\240\201\345\256\211\345\205\250\346\243\200\346\237\245.md" index ed5702e4fb2866549ba08d982fd7bcfc2f08b97e..bb20455e1549bbabd22143267754f5657114fbe9 100644 --- "a/openKylin-C&C++\350\257\255\350\250\200Fortify\344\273\243\347\240\201\345\256\211\345\205\250\346\243\200\346\237\245.md" +++ "b/openKylin-C&C++\350\257\255\350\250\200Fortify\344\273\243\347\240\201\345\256\211\345\205\250\346\243\200\346\237\245.md" @@ -1,5 +1,6 @@ # Fortify代码安全检查 + | 审核人: | 编写日期: | | --- | --- | | 批准人: | 审核日期: | @@ -11,44 +12,7 @@ openKylin | 日期 | 版本号 | 发布说明 | 编写人 | 审核人 | | --- | --- | --- | --- | --- | | 2022.09.19 | v1.0 | 添加命令注入、路径操纵、缓冲区溢出类型的规则 | 苏鑫 | - | - | - | - | - | - | - | - | - -# 目录 - -[0.](#_Toc1474278514)前言...............................................................3 - -[](#_Toc886152291)目的...............................................................3 - -[](#_Toc304473081)适用范围...............................................................3 - -[1.](#_Toc189507830)命令注入(Command Injection)类型...............................................................3 - -[1.1.](#_Toc1077273378)描述...............................................................3 - -[1.2.](#_Toc1128555694)整改建议...............................................................4 - -[2.](#_Toc1156090797)路径操纵(Path Manipulation)类型...............................................................5 - -[2.1.](#_Toc673585654)描述...............................................................5 - -[2.2.](#_Toc1348179914)整改建议...............................................................5 - -[3.](#_Toc892763222)缓冲区溢出(Buffer overflow)类型...............................................................6 - -[3.1.](#_Toc1540032177)描述...............................................................6 - -[3.2.](#_Toc178227594)整改建议...............................................................7 - -[4.](#_Toc168365859)代码规范工具...............................................................8 -[4.1. Fortify](#_Toc763838464)工具...............................................................8 # 0.前言