Code Scanning That Works With Your Code - Scott Norberg - ASW #317 Image

Code Scanning That Works With Your Code - Scott Norberg - ASW #317

11 February - 1 hour 12 mins
Podcast Series Security Weekly Podcast Network (Audio)

Code scanning is one of the oldest appsec practices. In many cases, simple grep patterns and some fancy regular expressions are enough to find many of the obvious software mistakes. Scott Norberg shares his experience with encountering code scanners that didn't find the .NET vuln classes he needed to find and why that led him to creating a scanner from scratch. We talk about some challenges in testing tools, making smart investments in engineering time, and why working with .NET's compiler made his decisions easier.

Segment Resources:

-https://github.com/ScottNorberg-NCG/CodeSheriff.NET

Identifying and eradicating unforgivable vulns, an unforgivable flaw (and a few others) in DeepSeek'...

1 hour 12 mins

Series Episodes

Recommended

Show name

Title

Sub title

Now Playing

The Pat Kenny Show

Live Now: 9AM - 12PM

Presenter logo
Brand

9AM

12AM

Now Playing

The Pat Kenny Show

The Pat Kenny Show

Of The Ball

1 hour left

Today Finished


Next Up

Default

Default

default

0 mins

No Account

Subscriptions to podcast series are only available to users with an account. Sign in or register to subscribe and access your subscriptions.

Register Sign in

Woops!

Error text.