Code Scanning That Works With Your Code - Scott Norberg - ASW #317
11 February 2025 - 1 hour 12 minsCode scanning is one of the oldest appsec practices. In many cases, simple grep patterns and some fancy regular expressions are enough to find many of the obvious software mistakes. Scott Norberg shares his experience with encountering code scanners that didn't find the .NET vuln classes he needed to find and why that led him to creating a scanner from scratch. We talk about some challenges in testing tools, making smart investments in engineering time, and why working with .NET's compiler made his decisions easier.
Segment Resources:
-https://github.com/ScottNorberg-NCG/CodeSheriff.NET
Identifying and eradicating unforgivable vulns, an unforgivable flaw (and a few others) in DeepSeek'...
Can AI help critical infrastructure, the state of the cyber market, and weekly news - Mike Privette, Kara Sprague - ESW #451
1 hour 42 mins
23 March Finished
Ahab and Peewee Herman, Zoom, Vibe Hacking, SharePoint, Meta, AgeID, Josh Marpet - SWN #565
33 mins
20 March Finished
Hacking IP KVMs & Reversing with Radare2 - Sergi Àlvarez - PSW #918
2 hours 10 mins
19 March Finished
AI Spicy Mode, Steam, Glassworm, Samsung, Stryker, Waymo, Cole Porter, and More - SWN #564
29 mins
17 March Finished
Creating Better Security Guidance and Code with LLMs - Mark Curphey - ASW #374
1 hour 4 mins
17 March Finished