Перейти к содержимому

Stop Chasing Sources and Sinks: Rethinking Security Code Review

PentesterLab

0:00 / 0:00

Stop Chasing Sources and Sinks: Rethinking Security Code Review

6 791 просмотр · 2 недели назад
PentesterLab
558 подписчиков
6 791 просмотр · 2 недели назад
Finding exploitable vulnerabilities is part of security code review. But if you work in AppSec, your goal is also to make the application harder to hack over time. In this webinar, I explain the limitations of relying on source-to-sink tracing and what we miss when we focus only on proving that a bug is exploitable today. Using examples from Ruby on Rails and Ruby deserialization gadget chains, we look at how narrow fixes leave dangerous capabilities available for the next exploit. We also cover the "exploitability tax": spending two days proving that something is exploitable when identifying the problem and fixing it could each take five minutes. Topics include: • Source-to-sink and sink-to-source code review • The different goals of vulnerability research and AppSec engineering • Reviewing complete features and trust boundaries • Hardening dangerous capabilities and breaking exploit chains • Using CVEs for variant analysis • Moving from individual findings to patterns, guardrails, and lasting improvements Presented by Louis Nyffenegger, founder of PentesterLab. Recorded live on August 25, 2026. Practice hands-on security code review with PentesterLab: https://pentesterlab.com/ Read the CVE Archeologist’s Field Guide: https://pentesterlab.com/book CHAPTERS 00:00 Introduction 01:03 What are sources and sinks? 02:45 Two approaches to security code review 05:11 The limitations of source and sink tracing 08:43 Security research vs AppSec engineering 13:07 Building a deeper understanding of the codebase 19:31 The exploitability tax 21:07 Case study: Ruby on Rails 24:28 Case study: Ruby universal gadget chains 26:37 What should we do instead? 29:38 Code review as an engineering discipline 30:52 Book and code review training