

Mark Dowd
The Art of Software Security Assessment
The code-audit bible, and the Sendmail and Flash bugs behind it
Rating
84Impact score
Domains
Code auditingMemory corruptionExploit mitigation
Scouting report
Co-wrote The Art of Software Security Assessment with John McDonald and Justin Schuh, still the most thorough published treatment of how to find memory-safety and logic flaws by reading code. Found deep bugs in Sendmail, OpenSSH and Flash while at ISS X-Force and IBM, and founded Azimuth Security. His work is why a generation of auditors know what to look for in a parser.
Curator’s note
The book that turned code review from a chore into a craft.
Sources
- 01The Art of Software Security Assessment informit.com
- 02Azimuth Security azimuthsecurity.com