Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [aspectj-users] Plans for dflow pointcut

Hi Rohit,

I would say we haven't had time to even look at whether we'd want to do that, so it hasn't already been dismissed.  There is no bugzilla entry for it, and if it isn't in bugzilla then it is completely off the radar.  Feel free to raise a bugzilla entry so it is at least being tracked and it will get reviewed at some point.

cheers,
Andy.

2008/8/11 Rohit Lists <rklists@xxxxxxxxx>
Hello, are there are any plans to implement the data flow pointcut as
defined here www.graco.c.u-tokyo.ac.jp/~masuhara/papers/aplas2003.pdf
in AspectJ? This would be an invaluable resource to application
security since large classes of security problems deal with tracing
data from source to sink (e.g. cross site scripting,
SQL/XML/Xpath/Ldap injection, OS interaction vulnerabilities, etc.).

If there are no such plans, is it because there are not enough
resources to work on this? Has there already been a discussion on
implementing dflow pointcut and a decision was made not to implement
it?

Thanks,

--
Rohit Sethi
Security Compass
http://www.securitycompass.com
_______________________________________________
aspectj-users mailing list
aspectj-users@xxxxxxxxxxx
https://dev.eclipse.org/mailman/listinfo/aspectj-users


Back to the top