Stop Chasing Sources and Sinks: Rethinking Security Code Review
PentesterLab
0:00 / 0:00
Stop Chasing Sources and Sinks: Rethinking Security Code Review
6 791 просмотр · 2 недели назад
PentesterLab
558 подписчиков
6 791 просмотр · 2 недели назад
Finding exploitable vulnerabilities is part of security code review. But if you work in AppSec, your goal is also to make the application harder to hack over time.
In this webinar, I explain the limitations of relying on source-to-sink tracing and what we miss when we focus only on proving that a bug is exploitable today. Using examples from Ruby on Rails and Ruby deserialization gadget chains, we look at how narrow fixes leave dangerous capabilities available for the next exploit.
We also cover the "exploitability tax": spending two days proving that something is exploitable when identifying the problem and fixing it could each take five minutes.
Topics include:
• Source-to-sink and sink-to-source code review
• The different goals of vulnerability research and AppSec engineering
• Reviewing complete features and trust boundaries
• Hardening dangerous capabilities and breaking exploit chains
• Using CVEs for variant analysis
• Moving from individual findings to patterns, guardrails, and lasting improvements
Presented by Louis Nyffenegger, founder of PentesterLab.
Recorded live on August 25, 2026.
Practice hands-on security code review with PentesterLab:
https://pentesterlab.com/
Read the CVE Archeologist’s Field Guide:
https://pentesterlab.com/book
CHAPTERS
00:00 Introduction
01:03 What are sources and sinks?
02:45 Two approaches to security code review
05:11 The limitations of source and sink tracing
08:43 Security research vs AppSec engineering
13:07 Building a deeper understanding of the codebase
19:31 The exploitability tax
21:07 Case study: Ruby on Rails
24:28 Case study: Ruby universal gadget chains
26:37 What should we do instead?
29:38 Code review as an engineering discipline
30:52 Book and code review training