Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Is Your Code Tainted? Finding Security Vulnerabilities Using Taint Tracking

EuroPython Conference via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Discover how to identify security vulnerabilities using taint tracking in this 27-minute conference talk from EuroPython 2018. Learn about the concept of "tainted" data from untrusted sources and how it can reach vulnerable parts of your code. Explore the principles of taint tracking analysis, including sources, sinks, and sanitizers. Watch a live demonstration of finding a cross-site scripting (XSS) vulnerability in a Django app using code analysis tools. Gain insights into writing safer code by thinking in terms of "taint," even without access to sophisticated analysis tools. Understand various security issues like code injection and SQL injection that can be detected through this technique. The talk covers introductory concepts, practical demonstrations, and advanced topics such as flow analysis and tank checking, providing a comprehensive overview of taint tracking for improved code security.

Syllabus

Intro
What is taint
What does taint mean
Sources
Injection
Sanitisation
Code Injection
Other security checks
Demonstration
Flow analysis
Tank checking

Taught by

EuroPython Conference

Reviews

Start your review of Is Your Code Tainted? Finding Security Vulnerabilities Using Taint Tracking

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.