PLAY PODCASTS
Code Scanning That Works With Your Code - Scott Norberg - ASW #317

Code Scanning That Works With Your Code - Scott Norberg - ASW #317

Security Weekly Podcast Network (Video) · Security Weekly Productions

February 11, 202537m 1s

Audio is streamed directly from the publisher (dts.podtrac.com) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.

Show Notes

Code scanning is one of the oldest appsec practices. In many cases, simple grep patterns and some fancy regular expressions are enough to find many of the obvious software mistakes. Scott Norberg shares his experience with encountering code scanners that didn't find the .NET vuln classes he needed to find and why that led him to creating a scanner from scratch. We talk about some challenges in testing tools, making smart investments in engineering time, and why working with .NET's compiler made his decisions easier.

Segment Resources:

-https://github.com/ScottNorberg-NCG/CodeSheriff.NET

Show Notes: https://securityweekly.com/asw-317