No video

How to do Code Review - The Offensive Security Way

  Рет қаралды 32,266

OWASP DevSlop

OWASP DevSlop

Күн бұрын

Fri Aug 20, 2021 8pm (EDT)
▬▬▬▬▬▬ ABSTRACT & BIO 📝 ▬▬▬▬▬▬
In this session, we will explore how source code analysis can lead to finding vulnerabilities in large enterprise codebases. By combining offensive security skillsets with code auditing and curiosity, it's often possible to find high and critical risk vulnerabilities affecting all the organizations using the software. If you're interested in the concept of finding 0days in web applications, source code disclosure and auditing, and common vulnerabilities classes this exposes - we'll cover the process of finding bugs and applying them to bug bounties.
SHUBHAM SHAH
Shubham Shah is the co-founder and CTO of Assetnote. Shubham is a prolific bug bounty hunter in the top 50 hackers on HackerOne and has presented at various industry events including QCon London, Kiwicon, AusCert, BSides Canberra and CrikeyCon. In his free time, Shubham enjoys performing high-impact application security research.
▬▬▬▬▬▬ LINKS🔗 ▬▬▬▬▬▬
Sources and Sinks - Code Review Basics ► • Sources and Sinks - Co...
CVE-2008-1930: WordPress 2.5 Cookie Integrity Protection Vulnerability ► pentesterlab.c...
Semgrep ► semgrep.dev/
graudit ► github.com/wir...
CodeQL ►securitylab.gi...
▬▬▬▬▬▬ Producer 🎥 ▬▬▬▬▬▬
Nancy Gariché ► / nancygariche
▬▬▬▬▬▬ Hosts 🎙️ ▬▬▬▬▬▬
Bec ► / errbufferoverfl
James ► / devec0
Lilly ► / attacus_au
Mimi ► / p0kemina
▬▬▬▬▬▬ Connect with Us 👋 ▬▬▬▬▬▬
KZfaq ► / owaspdevslop
DEV ► dev.to/devslop​
INSTAGRAM ► / ​
TWITTER ► / owasp_devslop​
LINKEDIN ► / owasp-devslop

Пікірлер
Finding bugs with Nuclei with PinkDraconian (Robbe Van Roey)
1:04:57
OWASP DevSlop
Рет қаралды 29 М.
Finding Security Vulnerabilities through Code Review - The OWASP way
1:16:38
Schoolboy Runaway в реальной жизни🤣@onLI_gAmeS
00:31
МишАня
Рет қаралды 3,2 МЛН
WHO CAN RUN FASTER?
00:23
Zhong
Рет қаралды 43 МЛН
Smart Sigma Kid #funny #sigma #comedy
00:40
CRAZY GREAPA
Рет қаралды 39 МЛН
黑天使遇到什么了?#short #angel #clown
00:34
Super Beauty team
Рет қаралды 44 МЛН
API Security for PCI Compliance (Data Security Standard)
58:20
freeCodeCamp.org
Рет қаралды 31 М.
How Senior Programmers ACTUALLY Write Code
13:37
Thriving Technologist
Рет қаралды 1,5 МЛН
OWASP ASVS: Unlocking Stronger Application Security
32:15
Bishop Fox
Рет қаралды 714
Attacking JSON Web Tokens with Louis Nyffenegger
1:23:49
OWASP DevSlop
Рет қаралды 6 М.
Secure Coding - Best Practices (also for non developers!)
57:45
I forced EVERYONE to use Linux
22:59
NetworkChuck
Рет қаралды 424 М.
Shubham Shah: From Burgers to Bounties (Ep. 30)
1:19:39
Critical Thinking - Bug Bounty Podcast
Рет қаралды 4,7 М.
Source Code Auditing
17:52
HackOvert
Рет қаралды 3,5 М.
Schoolboy Runaway в реальной жизни🤣@onLI_gAmeS
00:31
МишАня
Рет қаралды 3,2 МЛН