#033 · Security ProfessionalsRareLocked in

Mark Dowd

The Art of Software Security Assessment

The code-audit bible, and the Sendmail and Flash bugs behind it

Rating

84Impact score
Technical depth98
Defensive craft82
Research94
Influence84
FromAustralia
Era2002–present

Domains

Code auditingMemory corruptionExploit mitigation

Scouting report

Co-wrote The Art of Software Security Assessment with John McDonald and Justin Schuh, still the most thorough published treatment of how to find memory-safety and logic flaws by reading code. Found deep bugs in Sendmail, OpenSSH and Flash while at ISS X-Force and IBM, and founded Azimuth Security. His work is why a generation of auditors know what to look for in a parser.

Curator’s note

The book that turned code review from a chore into a craft.

Sources