How to review code for security
TL;DR
Security code review isn’t reading every line — it’s following untrusted input from where it enters the app to the sensitive places it might reach. Find the entry points, follow the data, check what happens when it arrives.
What it is
Whitebox testing: you have the source, so instead of poking the app from outside you read how it actually works. Done well it finds things black-box testing never would — and finds them without firing a single request.
How to approach it
- Get oriented. What language and framework? Where’s routing, auth, and data access handled?
- Find the entry points (sources): anywhere user input arrives — parameters, headers, uploads, APIs.
- Follow the input to the dangerous places (sinks): queries, command execution, file paths, template rendering.
- Ask at each sink: was this input validated or encoded before it got here? If not, that’s a finding.
- Check the crosscutting stuff: authentication, authorisation, secrets, error handling.
The next two pages go deeper on the sinks to watch for and tracing input to them.