Time
4 hours 39 minutes
Difficulty
Beginner
CEU/CPE
5

Video Transcription

00:00
lesson 4.3 of deaths that got fundamentals. We're gonna talk about static application, security testing or the fast
00:08
we've talked about a couple times. I think we briefly mentioned it what it is. You should have an idea, but when I delve a little bit deeper, so we understand when we're actually running the tools
00:19
what we're looking for.
00:21
So the lesson objectives were going to list some. The open source tools for static analysis
00:26
describe the benefits of limp based tools. Look that that look for style issues and any other some type of security issues top in Java script or some of these other non compiled languages
00:38
and relate the need for container security as well.
00:41
And then I want to demonstrate de compiling code. It's kind of it's slightly off topic, but it's an interesting issue that I've run into before, so I just want to kind of make sure we understand what byte code is, and you know how we can take a look at it.
00:55
You're interested in the static analysis, really, In doing security checks,
00:59
there's thestreet ill based lint tool that we could check the structure, typos, some some security issues like she see this little bit later, when I wish I showed the Jenkins demo. I do a check style
01:14
check in there and you'll see a number of errors in the type of errors that come up with that.
01:18
There's a mother specific ones called like, yes, lint that can check the security and check JavaScript special when you're doing node. Andi. It's important when things are running our that
01:27
what the code behind his JavaScript.
01:30
And we also have to look at container security,
01:33
especially as you start moving towards micro services. And those is shift air that the application development is shifting to the left. Where there's this, it's no longer this monolithic
01:45
application that's deployed. You have these individual pieces of code and they're built into the containers. That's that's running the libraries, and it's really moving towards the developer side.
01:55
And there's
01:56
so much later on. I think one of the last modules will talk about this. Is that
02:01
an application called Falco, which is a rules based engine? It you can actually monitor containers, which is interesting topic.
02:08
And then there's benchmarks to harden containers I have mentioned in this one
02:14
back in the first module.
02:17
So static analysis tools. We actually have a s s d f with nist.
02:22
Ah, framework
02:23
for ah, met up. Sorry, a requirement p w 0.5. So you have to have these type type of tool. So for Java, there's tons out there. But there's some free one that there's one called PMD spot bugs. Both of these will be in the demo later where I show
02:39
Puma scan for dot Net is a free tool, but there's also get you have to pay for advanced features of it.
02:46
Does the loss dependency check which one of my favorite tools. It looks at the third party libraries
02:53
and shows you what vulnerabilities accept is this for versions that are included in your application?
02:59
Is also commercial tools out there that do all these type of checks as well.
03:07
So there's a question for you. Are you familiar with vulnerability scoring other than a lost top 10
03:13
that the very we all kind of heard of this. We know this, but do you know there's other ones out there?
03:20
It was when you may not have heard off, but it is the common weaknesses in new Marais Shin which is related specifically to secure it relates started the vulnerabilities in applications specifically to secure code.
03:35
So this is the C W E. They actually publish a top 25 most dangerous software errors. What they do is they pull in the C V D data from the NPD
03:44
and then they take thesis E V S s scores. But what they do it is map each one of these vulnerabilities specifically to a CBE i d. And then rank them that way so that you can see what the common coding errors are.
04:00
I won't go through all Top 25. It just pulled out a couple here. There's ah linked to you can see the CB dot miter website where this is stored.
04:11
The 1st 1 is improper restrictions operations. This is the parent to the classic buffer over close. You see, they're still 75. It's the top
04:20
rank here and there. There's errors are still going on.
04:28
When the issues I mentioned I want to talk about quick is being able to d compiled code doesn't work for all languages like C on some of the other ones. But it does work for dot Net and job because they're the code is actually by code,
04:45
which can be decomp. I'll go back to the source code
04:47
and the reason this is someone interesting topic cause I've run in this before where either I was given a special or a a private library or an application. And the developer said This is not in my contract. Actually give the source code. I only have to deliver the final application.
05:03
Well, we couldn't run static analysis on the built application we needed to decomp, I'll it. So when I found some tools and ability to
05:13
decomp, I'll take the bite code or the application and reverse engineer back to the source code so they could run static analysis on it,
05:20
dont Lee said. Java has bite code dot net has assemblies.
05:27
The first
05:28
tool is DNS by
05:30
that could take dot net. So actually went out and I wrote just quick application compiled it, and then I ran it through the end spy and then got a screen capture here so you can see on the right side. That's the D compiled code, and you can see it's
05:46
near clear tax iffy. If you've ever written in dot net, or just that you can understand basic apple or a basic source code. What looks like So I actually have a secret here. I did a right line, I added. Asked for some text.
06:00
What do you see? It all This was a dot net assembly built application. I was able to de compile it
06:05
and the ends by actually has ability to then save off
06:09
that D compiled code into a workspace, and I was able to bring it up in visual studio and run that Puma skin on it.
06:16
We could do the same thing in Java. It's a different program called JD Gooey.
06:21
Same thing I wrote up a Java program, compiled it into a class file,
06:26
brought it back in or brought it into the day D
06:30
and D compiled it, and you see the same way on the right. It has a, uh,
06:34
clear text, and it looks almost exactly like the original code,
06:39
and this one has. The you could do is what the same thing. You can take a whole jar file or war file, actually save it off the whole entire source code and then run it through the SAS tool.
06:49
Um, one of the other ways I found that interesting is that this good search functionality the D N spice a little bit better, but I would guess you go through and look forward. The word passwords secret. And it's just amazed that these low hanging fruit you find in these applications
07:03
some of the static analysis tool who find that but other ones
07:08
there might be specific things, like in this case, I knew the developers, their domain name or their email addresses. They're up for the domain portion of email. Actually start searching and finding this privacy information in the application.
07:24
Here's a quick quiz
07:26
spot bugs and other source code review tools perform. Is it static analysis or dynamic analysis?
07:33
This should be an easy one to have been paying attention. Static analysis is poor is performed before the apus built dynamic analysis is gonna be done after its is running in the environment. We'll look at that later module.
07:46
We talked about static analysis tools and some of the concepts that we need.
07:50
Uh, and then next we'll talk about external libraries and adding them during the deployment. And what security ramic a ramifications. There are

Up Next

DevSecOps Fundamentals

DevSecOps training helps students learn to incorporate security features in every step of the development process and navigate distinct security challenges in custom software and web applications.

Instructed By

Instructor Profile Image
Philip Kulp
Instructor