<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
	>
<channel>
	<title>Comments on: Static Code Analysis Using Google Code Search</title>
	<atom:link href="http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/feed/" rel="self" type="application/rss+xml" />
	<link>http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/</link>
	<description>A weblog dedicated to educating the community on security threats that matter</description>
	<lastBuildDate>Mon, 08 Mar 2010 22:35:14 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Google Code Search for Fun &#38; Profit &#171; 0&#215;0e &#124; a pentester&#8217;s view</title>
		<link>http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/comment-page-1/#comment-156641</link>
		<dc:creator>Google Code Search for Fun &#38; Profit &#171; 0&#215;0e &#124; a pentester&#8217;s view</dc:creator>
		<pubDate>Mon, 01 Sep 2008 04:40:33 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/#comment-156641</guid>
		<description>[...] Dug Song: http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Dug Song: <a href="http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/" rel="nofollow">http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jugar poquer internet</title>
		<link>http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/comment-page-1/#comment-137428</link>
		<dc:creator>jugar poquer internet</dc:creator>
		<pubDate>Fri, 20 Jun 2008 16:51:39 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/#comment-137428</guid>
		<description>&lt;strong&gt;poker en internet...&lt;/strong&gt;

Will casino bonus code poker flash game regle du poker ringtones for nextel phone roulette paginas internet...</description>
		<content:encoded><![CDATA[<p><strong>poker en internet&#8230;</strong></p>
<p>Will casino bonus code poker flash game regle du poker ringtones for nextel phone roulette paginas internet&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: google code search at 不断往后看</title>
		<link>http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/comment-page-1/#comment-106993</link>
		<dc:creator>google code search at 不断往后看</dc:creator>
		<pubDate>Mon, 28 Apr 2008 06:16:01 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/#comment-106993</guid>
		<description>[...] 如果你是一个程序员，却没有好好利用互联网带给我们的一切，那实在是暴殄天物了。 Google code search可以看作是google送给我们程序员最好的礼物，不用下载，在任何地方都可以阅读mysql源代码的感觉实在是很好。 当然，要最大程度地发挥这个工具的作用，你需要一点技巧和学习。 今天找到了一篇文章，可以作为入门指导，供大家参考。 Static Code Analysis Using Google Code Search [...]</description>
		<content:encoded><![CDATA[<p>[...] 如果你是一个程序员，却没有好好利用互联网带给我们的一切，那实在是暴殄天物了。 Google code search可以看作是google送给我们程序员最好的礼物，不用下载，在任何地方都可以阅读mysql源代码的感觉实在是很好。 当然，要最大程度地发挥这个工具的作用，你需要一点技巧和学习。 今天找到了一篇文章，可以作为入门指导，供大家参考。 Static Code Analysis Using Google Code Search [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Smacchia</title>
		<link>http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/comment-page-1/#comment-17856</link>
		<dc:creator>Patrick Smacchia</dc:creator>
		<pubDate>Thu, 03 May 2007 09:56:22 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/#comment-17856</guid>
		<description>You might be ineterested by the tool NDepend:
http://www.NDepend.com

NDepend analyses source code and .NET assemblies. It allows controlling the complexity, the internal dependencies and the quality of .NET code. NDepend provides a language (CQL Code Query Language) dedicated to query and constraint a codebase. It also comes from with advanced code visualization (Dependencies Matrix, Metric treemap, Box and Arrows graph...), more than 60 metrics, facilities to generate reports and to be integrated with mainstream build technologies and development tools. NDepend also allows to compare precisely different versions of your codebase.</description>
		<content:encoded><![CDATA[<p>You might be ineterested by the tool NDepend:<br />
<a href="http://www.NDepend.com" rel="nofollow">http://www.NDepend.com</a></p>
<p>NDepend analyses source code and .NET assemblies. It allows controlling the complexity, the internal dependencies and the quality of .NET code. NDepend provides a language (CQL Code Query Language) dedicated to query and constraint a codebase. It also comes from with advanced code visualization (Dependencies Matrix, Metric treemap, Box and Arrows graph&#8230;), more than 60 metrics, facilities to generate reports and to be integrated with mainstream build technologies and development tools. NDepend also allows to compare precisely different versions of your codebase.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Harald Korneliussen</title>
		<link>http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/comment-page-1/#comment-2925</link>
		<dc:creator>Harald Korneliussen</dc:creator>
		<pubDate>Thu, 09 Nov 2006 13:12:59 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/#comment-2925</guid>
		<description>This was brilliant, I&#039;ll definitively remember (or rather, bookmark) these regexps to use myself when maintaining large, old c apps... There should be a collection of such expressions. 

On a side note, I found this site by searching reddit for &quot;static&quot;, because I was looking for articles on static analysis.</description>
		<content:encoded><![CDATA[<p>This was brilliant, I&#8217;ll definitively remember (or rather, bookmark) these regexps to use myself when maintaining large, old c apps&#8230; There should be a collection of such expressions. </p>
<p>On a side note, I found this site by searching reddit for &#8220;static&#8221;, because I was looking for articles on static analysis.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Digital Bond &#187; Fun with Google Code Search</title>
		<link>http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/comment-page-1/#comment-2856</link>
		<dc:creator>Digital Bond &#187; Fun with Google Code Search</dc:creator>
		<pubDate>Wed, 08 Nov 2006 13:22:31 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/#comment-2856</guid>
		<description>[...] Last week, on many security mailing lists, folks were talking about using Google Code Search to look for various sorts of vulnerabilities in publicly-accessible source code repositories. Given the tool&#8217;s robust support for regular expressions, it is not inconceivable for static analysis tools (aka source code scanners) to be quickly google-ified to search repositories instead of a local filesystem. [...]</description>
		<content:encoded><![CDATA[<p>[...] Last week, on many security mailing lists, folks were talking about using Google Code Search to look for various sorts of vulnerabilities in publicly-accessible source code repositories. Given the tool&#8217;s robust support for regular expressions, it is not inconceivable for static analysis tools (aka source code scanners) to be quickly google-ified to search repositories instead of a local filesystem. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lzh</title>
		<link>http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/comment-page-1/#comment-2411</link>
		<dc:creator>lzh</dc:creator>
		<pubDate>Thu, 02 Nov 2006 18:28:26 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/#comment-2411</guid>
		<description>er... I meant \s+ isn&#039;t as readable as \ *. Remind me not to do this stuff when short of sleep. :/</description>
		<content:encoded><![CDATA[<p>er&#8230; I meant \s+ isn&#8217;t as readable as \ *. Remind me not to do this stuff when short of sleep. :/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lzh</title>
		<link>http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/comment-page-1/#comment-2408</link>
		<dc:creator>lzh</dc:creator>
		<pubDate>Thu, 02 Nov 2006 18:07:55 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/#comment-2408</guid>
		<description>hmm... that comes of as quite the jerk comment. Sorry. I just wanted to recommend something that will likely find stuff a little more correctly. I suppose \ * isn&#039;t as readable as \s+. But since source code often has tabs \ * will likely miss stuff that you probably don&#039;t want to miss.

Yes \s also matches newline, carriage return, and form feed. I don&#039;t think that aspect matters much here. I have yet to get a regex to match across a line boundary using Google&#039;s code search.</description>
		<content:encoded><![CDATA[<p>hmm&#8230; that comes of as quite the jerk comment. Sorry. I just wanted to recommend something that will likely find stuff a little more correctly. I suppose \ * isn&#8217;t as readable as \s+. But since source code often has tabs \ * will likely miss stuff that you probably don&#8217;t want to miss.</p>
<p>Yes \s also matches newline, carriage return, and form feed. I don&#8217;t think that aspect matters much here. I have yet to get a regex to match across a line boundary using Google&#8217;s code search.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lzh</title>
		<link>http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/comment-page-1/#comment-2406</link>
		<dc:creator>lzh</dc:creator>
		<pubDate>Thu, 02 Nov 2006 17:26:16 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/#comment-2406</guid>
		<description>your \ * should be either \s*, or \s+. \ * will match zero or more spaces. \s* will match zero or more spaces or tabs. + is 1 or more of the preceding. You may realize this. But why not use the correct thing.</description>
		<content:encoded><![CDATA[<p>your \ * should be either \s*, or \s+. \ * will match zero or more spaces. \s* will match zero or more spaces or tabs. + is 1 or more of the preceding. You may realize this. But why not use the correct thing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CMoi</title>
		<link>http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/comment-page-1/#comment-1462</link>
		<dc:creator>CMoi</dc:creator>
		<pubDate>Wed, 11 Oct 2006 19:42:08 +0000</pubDate>
		<guid isPermaLink="false">http://asert.arbornetworks.com/2006/10/static-code-analysis-using-google-code-search/#comment-1462</guid>
		<description>Some PHP ones are also nice :
http://www.google.com/codesearch?hl=en&amp;lr=&amp;q=include%5C%28%5C%24_GET
http://www.google.com/codesearch?hl=en&amp;lr=&amp;q=SELECT+%5C*+FROM+%27%5C.%5C%24_GET</description>
		<content:encoded><![CDATA[<p>Some PHP ones are also nice :<br />
<a href="http://www.google.com/codesearch?hl=en&amp;lr=&amp;q=include%5C%28%5C%24_GET" rel="nofollow">http://www.google.com/codesearch?hl=en&amp;lr=&amp;q=include%5C%28%5C%24_GET</a><br />
<a href="http://www.google.com/codesearch?hl=en&amp;lr=&amp;q=SELECT+%5C" rel="nofollow">http://www.google.com/codesearch?hl=en&amp;lr=&amp;q=SELECT+%5C</a>*+FROM+%27%5C.%5C%24_GET</p>
]]></content:encoded>
	</item>
</channel>
</rss>
