A Static Tainting Analysis Method for Aspect-Oriented Programs - AppSecUSA 2017
600 views · Published 11 October 2017 · 36:35 · Indexed 22 September 2026
Channel: OWASP Foundation · 2017 · Science & Technology
A Static Tainting Analysis Method for Aspect-Oriented Programs Many web applications contain security vulnerabilities that enable attackers to access sensitive data or gain control of client computers or the servers on which those applications are running. These vulnerabilities are caused by web applications failing to correctly sanitize input data and to safely format output data. Many tools and techniques have been created to detect and correct these problems in web applications written using widely-used programming languages such as PHP and Java but little has been done to address vulnerabilities in web applications written using aspect-oriented languages such as AspectJ. This presentation will introduce a new method of detecting potential vulnerabilities in aspect-oriented web applications. Speakers Evan H. Dygert President, Dygert Consulting, Inc. Evan Dygert is a consultant (Dygert Consulting, Inc.) with over 30 years of experience in software development in areas including compilers, databases, finance, insurance, computer networking and security, and software security. - Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP_Media_Project
More from this channel
-
50:12
OWASP Global Webinar - OWASP HIVE Project - Welcome to the Grid
-
2:26:27
OWASP AppSecUSA 2014 - Breakers Track - Friday
-
53:26
OWASP AppSecUSA 2014 - Keynote: OWASP Global Board
-
49:40
Building Your Application Security Data Hub: The Imperative for Structured Vulnerability Information
-
48:32
Blended Web and Database Attacks on Real-time, In-Memory Platforms - OWASP AppSecUSA 2014
-
1:02:26
AppSec EU15 - Ange Albertini - Preserving Arcade Games
-
39:40
AppSec EU15 - Martin Johns, Sebastian Lekies, Ben Stock - Client-Side Protection Against DOM-Base...
-
56:49
Attack tree vignettes for Containers as a Service applications - Tony Uceda Vélez - AppSec Ca 2016