Using joern to Find GraphQL Authorization Issue

  Рет қаралды 6,900

LiveUnderflow

LiveUnderflow

Күн бұрын

Пікірлер: 10
@viva453453
@viva453453 2 жыл бұрын
I hope to see the conclusion this year :D
@ElenaWilliams-nc9xu
@ElenaWilliams-nc9xu 2 ай бұрын
its not working after ./joern, shows Error: Could not find or load main class .Cause by: java.lang.ClassNotFoundException:
@ElenaWilliams-nc9xu
@ElenaWilliams-nc9xu 2 ай бұрын
please help
@भारतवासी-प6प
@भारतवासी-प6प Ай бұрын
You are using the wrong module import. As you may be having the latest version but you don't know the latest import modules and classes
@damejelyas
@damejelyas 2 жыл бұрын
the real question is does joern tool provide dataFlow analysis and Taint analysis because I think it is the real power of CodeQL
@themadichib0d
@themadichib0d 2 жыл бұрын
the site says it does, but finding good joern resources and examples is kinda hard
@himanipku22
@himanipku22 Жыл бұрын
kzbin.infoqtGRNb_2Khs?feature=share&t=2699 This seems kind of similar to taint analysis.
@homegrown4335
@homegrown4335 2 жыл бұрын
The conclusion is...
@viva453453
@viva453453 2 жыл бұрын
There is a learning curve in both cases to learn the tools. As we see in the videos brute force approach in both cases takes time to find how to formulate the query (and would take even longer without helpful comments from live observers). While the tools overlap, the specific case may not be the best for comparison - Joern failed to analyze one of the TypeScript classes. The fact that in Joern case you need to think in terms of the JavaScript, that the TypeScript is transpiled to, is not convenient. But the experience when comparing a different programming language may be different. I *personally* find the CodeQL query more readable than the one liner mix with lambdas approach of Joern. From the performance point of view Joern looks more interactive and fast, when CodeQL always takes time to compile and execute.
Using CodeQL to Investigate GraphQL Resolvers
50:57
LiveUnderflow
Рет қаралды 17 М.
How The RIDL CPU Vulnerability Was Found
25:24
LiveOverflow
Рет қаралды 122 М.
How to have fun with a child 🤣 Food wrap frame! #shorts
0:21
BadaBOOM!
Рет қаралды 17 МЛН
БОЙКАЛАР| bayGUYS | 27 шығарылым
28:49
bayGUYS
Рет қаралды 1,1 МЛН
I Sent a Subscriber to Disneyland
0:27
MrBeast
Рет қаралды 104 МЛН
How to Analyze Code for Vulnerabilities using Joern
1:13:50
OWASP DevSlop
Рет қаралды 6 М.
Trying to Find a Bug in WordPress
18:07
LiveOverflow
Рет қаралды 92 М.
Hacking for an Intelligence Agency
13:56
LiveUnderflow
Рет қаралды 29 М.
LEEROY fällt auf HACKER rein?
37:38
LiveUnderflow
Рет қаралды 301 М.
CodeQL query to detect RCE via ZipSlip - $5,500 bounty from GitHub Security Lab
13:20
Bug Bounty Reports Explained
Рет қаралды 7 М.
Authorization in GraphQL: Peanut Butter and Chocolate - Sam Scott
22:40
Security Issue Found in US Gov CISA Tool?
10:18
LiveUnderflow
Рет қаралды 8 М.
All Rust string types explained
22:13
Let's Get Rusty
Рет қаралды 198 М.
Rant: Entity systems and the Rust borrow checker ... or something.
1:01:51
Finding Your Next Bug: GraphQL
49:34
InsiderPhD
Рет қаралды 25 М.
How to have fun with a child 🤣 Food wrap frame! #shorts
0:21
BadaBOOM!
Рет қаралды 17 МЛН