Mr.Trunk · @mrtrunk
12 followers · 19837 posts · Server dromedary.seedoubleyou.me
ITSEC News · @itsecbot
1438 followers · 36821 posts · Server schleuss.online

Secure your Apollo GraphQL server with Semgrep - By Vasco Franco
tl;dr: Our publicly available Semgrep ruleset has nine new rules to detec... blog.trailofbits.com/2023/08/2

#semgrep

Last updated 1 year ago

Mr.Trunk · @mrtrunk
6 followers · 13542 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
7 followers · 12214 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
5 followers · 9040 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
5 followers · 6044 posts · Server dromedary.seedoubleyou.me
Geoff Baskwill · @geoff_baskwill
42 followers · 74 posts · Server mastodon.cloud

I wonder if anyone out there has written a rule to catch typos in Go struct tags; something that can find and catch `dyanmodbav:"foo"` or `dynamodb:"foo"` would be super-awesome. Not finding joy in the docs / examples that I can find. Technically doesn't need to be semgrep, but trying to step up from regular grep.

#semgrep

Last updated 1 year ago

Mr.Trunk · @mrtrunk
3 followers · 4090 posts · Server dromedary.seedoubleyou.me

SecurityOnline: semgrep v1.32 releases: Fast and syntax-aware semantic code pattern search securityonline.info/semgrep-fa @news@lemmy.seedoubleyou.me

#webvulnerabilityanalysis #programming #semgrep

Last updated 1 year ago

Arjun G · @247arjun
107 followers · 162 posts · Server infosec.exchange

🤯

can generate a (roughly) equivalent rule for a given rule. That's NUTS!

#chatgpt #CodeQL #semgrep

Last updated 1 year ago

· @bmahe
7 followers · 4 posts · Server mamot.fr

Super excited to see the release of Code. Amazing results with higher coverage, higher confidence and deeper analysis. And on top of that, the new taint traces make it so easy to understand your finding!
See for details:
semgrep.dev/blog/2023/announci

#semgrep #SAST

Last updated 1 year ago

Hamid Kashfi · @Hamid
255 followers · 56 posts · Server infosec.exchange

Better late than never, but I just learned that I have missed the release of DeepSemgrep last year. Global variables support and taint tracking across packages seem pretty useful to eliminate false positives in many cases in larger projects. Has anyone used it in their engagements? Any quirks one needs to be aware of?

semgrep.dev/docs/deepsemgrep/d

#semgrep

Last updated 2 years ago

Marco Ivaldi · @raptor
1276 followers · 441 posts · Server infosec.exchange

And finally, this is our most successful article this year on the @hnsec blog, by yours truly:

Automating binary discovery with and
security.humanativaspa.it/auto

#vulnerability #ghidra #semgrep

Last updated 2 years ago

lapt0r :verified: · @lapt0r
1217 followers · 350 posts · Server infosec.exchange

Every time my project has an issue, I write a rule for it, preferably with autofix. I just found a few bugs, and truing things up to pass CI again was as easy as running with autofix enabled.

Never do a task more than once that you can convince a computer to do for you

#semgrep

Last updated 2 years ago

Max Maass :verified: · @hacksilon
200 followers · 112 posts · Server infosec.exchange

Just published part 3 of my blog series on Actuators - today, I'm discussing how to find exposed Actuators using dynamic testing with my favorite swiss army knife for web security tests: ffuf.

blog.maass.xyz/spring-actuator

If you missed the previous articlesor don't know what I am talking about: In part 1, I discuss why Spring Actuators can be dangerous if you inadvertently expose them to the internet (blog.maass.xyz/spring-actuator), and in part 2 I show you how to use to analyze your code for common misconfigurations related to them (blog.maass.xyz/spring-actuator). This third article rounds out the attacker side with a look at dynamic testing using . Now, on to writing a final article from the perspective of the defender.

#java #spring #semgrep #ffuf #security #bugbounty #redteam

Last updated 2 years ago

Marco Ivaldi · @raptor
1217 followers · 351 posts · Server infosec.exchange
· @bmahe
6 followers · 1 posts · Server mamot.fr

Amazing to see the work done by the team on !
Adding deeper analysis while keeping it fast is no small feat.

r2c.dev/blog/2022/static-analy

#semgrep

Last updated 2 years ago

· @bmahe
7 followers · 4 posts · Server mamot.fr

Amazing to see the work done by the team on !
Adding deeper analysis while keeping it fast is no small feat.

r2c.dev/blog/2022/static-analy

#semgrep

Last updated 2 years ago

Marco Ivaldi · @raptor
1000 followers · 214 posts · Server infosec.exchange

Beside the powerful usual suspects and , here’s a couple less-known code scanners that get the job done:

github.com/googleprojectzero/w

github.com/chris-anley/cq

I haven’t tried this one yet, but it looks promising:

github.com/CoolerVoid/codewarr

Happy hacking! :hecked:

#semgrep #CodeQL #source #security

Last updated 2 years ago

In case you missed Ellen Wang's release of - A tool to detect malicious python packages using , catch the write up here. It's been very successful at surfacing sneaky packages that make their way to the PyPi registry. @datadoghq@twitter.com

#guarddog #semgrep #python #malware #oss

Last updated 2 years ago

Great time this week at by hearing from folx like @bubblewire about paved road and highways!
@Datadog@twitter.com 's Ellen Wang released an open source tool called from that helps detect malicious python packages using .

#appsecusa #owasp #guarddog #securitylabs #semgrep

Last updated 2 years ago