8000 Security audit and testing of program · Issue #10 · WR4F/ZeroChat · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
Security audit and testing of program #10
Open
@WR4F

Description

@WR4F

Webapp pentesting is a skill that will be needed to make sure ZeroChat is a secure application. I am almost certain that there is something vulnerable - there are already more than 700 lines of code at the first commit.
I will prioritize the following:

  • Research memory leaks and how to detect/exploit and avoid them or protect against exploitation
  • Reduce code size and attack surface
  • Make the program more modular so that debugging and bug hunting/fixing becomes easier
  • Use fuzzers and try to break the server/take it down/inject malicious code
  • Automatically detect and block DDoS attempts

Metadata

Metadata

Assignees

Labels

ImportantThis issue is high priority

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions

    0