✨Happening Now ✨@compaluca' presenting the #OWASP Testability Patterns for Webapps project at the @owasp@AppSecEU. Join us to learn more about testability patterns, and how you can use our framework to pick the right SAST tools!
buff.ly/3E3jsFM#testable_eu#appsec
4/5: Do you want to contribute? Found a code snippet affecting a SAST tool? Join and contribute to our catalogue. Want to test your SAST tools against our catalogue? Extend our framework to support your tool.
👉 github.com/testable-eu/sast-…
3/5: We also built a framework to check if your code base has these patterns AND you can add your SAST tools to check if they are affected by them 🔥
👉 github.com/testable-eu/sast-…
2/5: We are building the first open-source catalogue of testability patterns for many programming languages, i.e., problematic code snippets that hamper the capability of static analyzers to find vulnerabilities.
👉​​github.com/testable-eu/sast-…
The testability metric aims to estimate of how easy/hard is to detect vulnerabilities over a target application with respect to a certain class of testing techniques (e.g., SAST, DAST, …)
Super cool idea to check if malicious JS is running/injected on a web page, in particular when it’s opened from an app. Cc @Testable_EU. @KrauseFx, I would wrap the whole JS code in a IIFE to prevent malicious code to overwrite controls. 😉
🔥 New Post: Announcing InAppBrowser - see what JavaScript commands get injected through an in-app browser
👀 TikTok, when opening any website in their app, injects tracking code that can monitor all keystrokes, including passwords, and all taps.
krausefx.com/blog/announcing…
Core to TESTABLE is a new testability metric to compute a more precise risk score, complementing existing vulnerability indicators (e.g., LoC, presence of security-sensitive function calls)
#testable_eu
Interested to detect security and privacy issues? Do you use/develop any static or dynamic testing tools? Do you work on testing tools to make your ML-based components more robust against adversarial attacks?
Keep an eye on TESTABLE! #testable_eu