Microsoft crashes in with open-source security tool
Application developers and testers will be able to examine bugs which crash software without the need of a security expert.
Microsoft's security team has released a new open-source program that will examine crash data information gathered when an application stops performing without the aid of a security expert.
The interestingly named !exploitable Crash Analyser tool (pronounced bang exploitable) is aimed at streamlining the process of finding security vulnerabilities while software it is still in development.
Importantly, developers and testers, who aren't necessarily trained in the security issues which dog application development, should be able to use the tool to identify the unique issues which caused the crash on Microsoft platforms.
The !exploitable Crash Analyser could also be used by security researchers to create more secure products and services.
Microsoft said in a statement: "The tool narrows down the list of issues that cause a crash so users can focus on just the unique issues.
"In addition, the information collected using the tool helps developers and security researchers create more secure products and services."
According to security researcher Dan Kaminsky, speaking to the Register, the tool is a "game changer", which allows developers to sort through thousands of bugs and identify those which created the most risk.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
He said: "Microsoft has taken years of difficulties with security and really condensed that experience down to a repeatable tool that takes a look at the crash and says You better take a look a this'."
The !exploitable Crash Analyser is available on Microsoft's website.
Web developers also received a new free software tool from HP, intended to help those working with Flash to protect their websites against security flaws, and reduce the risk of hackers accessing sensitive data.
-
Comment Destination AI™ démocratise l’expertise de TD SYNNEX en matière d’IACommencer votre parcours vers l’IA avec un partenaire de confiance est la première étape. La suivante consiste à adopter un programme de bout en bout couvrant l’IA, les données et bien plus encore
-
Destination AI™ pone al alcance de todos la especialización de TD SYNNEX en Inteligencia ArtificialSponsored El primer paso es comenzar en el mundo de la IA con un socio de confianza; el siguiente es adoptar un programa integral sobre IA, datos y mucho más