Powering up your source code auditing with parsers

  Рет қаралды 412

HackOvert

HackOvert

Күн бұрын

Get the code here: github.com/Hac...
Full Disclosure link: seclists.org/f...
This video is a follow up to a called Source Code Auditing which looked at methods for manual source code audits to find bugs. This time we revisit source code auditing, but apply more intelligence to the problem by using a parser to power our analysis.
Watch the Source Code Auditing video:
• Source Code Auditing
Thumbnail photo by Luigi Estuye, LUCREATIVE on Unsplash.
Intro/outro music is "In Reverse" (Lone Wolf Albumn) by Streambeats / Harris Heller.

Пікірлер: 2
@BookishOwlWhispers
@BookishOwlWhispers 3 жыл бұрын
Did you get a chance to look into CodeQL? That should save you so much time instead of using tree-sitter. PHP is unfortunately not supported...
@HackOvert
@HackOvert 3 жыл бұрын
CodeQL looks so cool. I'm really hoping the future will bring additional language support to the platform. I just noticed their bug bounty program which rewards CodeQL queries that models vulnerabilities in open source software (details here securitylab.github.com/bounties/). Thanks for bringing this up, I think this would be a fun project to work on.
Bug hunting using the "Portnoy Process"
24:02
HackOvert
Рет қаралды 352
Source Code Auditing
17:52
HackOvert
Рет қаралды 3,6 М.
А ВЫ ЛЮБИТЕ ШКОЛУ?? #shorts
00:20
Паша Осадчий
Рет қаралды 8 МЛН
Новый уровень твоей сосиски
00:33
Кушать Хочу
Рет қаралды 4,5 МЛН
A journey into anti-debugging
17:41
HackOvert
Рет қаралды 3,8 М.
Hunting Format String Vulnerabilities
29:10
HackOvert
Рет қаралды 453
Premature Optimization
12:39
CodeAesthetic
Рет қаралды 808 М.
Modeling functions with Z3
14:21
HackOvert
Рет қаралды 1,8 М.
Let's Create a Compiler (Pt.1)
1:11:03
Pixeled
Рет қаралды 519 М.
C++ Should Be C++ - David Sankel - C++Now 2024
1:28:49
CppNow
Рет қаралды 18 М.
[AntiDBG] NtQueryInformationProcess
11:17
HackOvert
Рет қаралды 961
А ВЫ ЛЮБИТЕ ШКОЛУ?? #shorts
00:20
Паша Осадчий
Рет қаралды 8 МЛН