[WEB SECURITY] C# test suite for testing static code analyzers

Michael Williams mw7301 at hotmail.com
Sat Jan 24 18:15:13 EST 2009

Yes you are correct I am not looking for a tool, I am looking for a suite of C# programs that have security vulnerabilities in them like poor input validation, buffer overflow problems, SQL injection problems, etc that I can use as a test suite to test the quality of static code analyzing tools in their ability to find and report on the problems contained in the C# programs. 
There seems to be lots test suites like this for C,C++ and Java but almost nothing for C#. So I'm starting to think that it would be a pretty nice project for me to write a dozen or so small C# programs which contain the standard list of application security programming errors and make it freely available for people who are trying to decide which static code analyzer is best at picking out these vulnerabilities. 
