Hunting for vulnerabilities with Joern, open-sourced code analysis tool. VLC Buffer Overflow Example

  Рет қаралды 2,724

ShiftLeft

ShiftLeft

3 жыл бұрын

Demo preparation links down below!
This video is an introduction to Joern, an open-sourced static analysis tool. Joern is an award-winning open-source platform for robust query-based analysis of C/C++. It enables mining large codebases for vulnerabilities using a Scala-based domain-specific query language and provides the reference implementation for code property graphs. With its fuzzy parsing approach, it is specifically suited for machine learning applications. Joern serves as the fundamental for the commercial SAST and code exploration products at ShiftLeft.
Important Links
Joern Documentation: docs.joern.io
Joern query database: queries.joern.io
Joern Community: / discord
Demo preparation:
Download VLC v3.0.12 source and extract in a convenient directory
$ wget get.videolan.org/vlc/3.0.12/vl...
$ tar -xvf vlc-3.0.12.tar.xz
Download Joern and install
$ wget github.com/joernio/joern/rele...
$ chmod +x ./joern-install.sh
$ sudo ./joern-install.sh

Пікірлер: 2
@user-rg9jl2hv2n
@user-rg9jl2hv2n 6 ай бұрын
hi,Is joern support Class.forName("MyClass") for java code scan?
@soaphornseuo8630
@soaphornseuo8630 3 жыл бұрын
Advance statics analysis
Sources and Sinks - Code Review Basics
7:53
LiveOverflow
Рет қаралды 47 М.
Nastya and SeanDoesMagic
00:16
Nastya
Рет қаралды 44 МЛН
Llegó al techo 😱
00:37
Juan De Dios Pantoja
Рет қаралды 61 МЛН
Как бесплатно замутить iphone 15 pro max
00:59
ЖЕЛЕЗНЫЙ КОРОЛЬ
Рет қаралды 8 МЛН
What is Apache Kafka®?
11:42
Confluent
Рет қаралды 347 М.
ShiftLeft CORE: Interactive Remediation
2:02
ShiftLeft
Рет қаралды 89
Stop, Intel’s Already Dead! - AMD Ryzen 9600X & 9700X Review
13:47
Linus Tech Tips
Рет қаралды 1 МЛН
But, what is Virtual Memory?
20:11
Tech With Nikola
Рет қаралды 249 М.
I've been using Redis wrong this whole time...
20:53
Dreams of Code
Рет қаралды 348 М.
Google Data Center 360° Tour
8:29
Google Cloud Tech
Рет қаралды 5 МЛН
pfSense Firewall - pfSense Administration Full Course
3:35:47
Knowledge Power
Рет қаралды 497 М.
Using joern to Find GraphQL Authorization Issue
37:47
LiveUnderflow
Рет қаралды 6 М.
Waka Waka 💦💃😁 #funnyshorts #rianashow
0:14
RianaShow
Рет қаралды 21 МЛН
Идеально повторил? Хотите вторую часть?
0:13
⚡️КАН АНДРЕЙ⚡️
Рет қаралды 12 МЛН
Мне приснился очень страшный сон
0:38
Хитрая ГОРНИЧНАЯ вернула ДОМ матери 😱 #shorts
0:57
Лаборатория Разрушителя
Рет қаралды 3,6 МЛН
ЖЕСТКИЙ ШАПАЛАК👋
0:33
RFC Fighting Championship
Рет қаралды 252 М.