How to review code for security

beginnerCode Review

TL;DR

Security code review isn’t reading every line — it’s following untrusted input from where it enters the app to the sensitive places it might reach. Find the entry points, follow the data, check what happens when it arrives.

What it is

Whitebox testing: you have the source, so instead of poking the app from outside you read how it actually works. Done well it finds things black-box testing never would — and finds them without firing a single request.

How to approach it

The next two pages go deeper on the sinks to watch for and tracing input to them.

← Back to Code Review