Logo video2dn
  • Сохранить видео с ютуба
  • Категории
    • Музыка
    • Кино и Анимация
    • Автомобили
    • Животные
    • Спорт
    • Путешествия
    • Игры
    • Люди и Блоги
    • Юмор
    • Развлечения
    • Новости и Политика
    • Howto и Стиль
    • Diy своими руками
    • Образование
    • Наука и Технологии
    • Некоммерческие Организации
  • О сайте

Скачать или смотреть Black Hat USA 2013 - Javascript Static Security Analysis made easy with JSPrime

  • Black Hat
  • 2013-12-02
  • 2317
Black Hat USA 2013 - Javascript Static Security Analysis made easy with JSPrime
HatInformation SecurityBlackBriefingBlackHatBriefings2013JavaScript (Programming Language)SecurityUSAInfoSecBlack Hat BriefingsBlack Hat
  • ok logo

Скачать Black Hat USA 2013 - Javascript Static Security Analysis made easy with JSPrime бесплатно в качестве 4к (2к / 1080p)

У нас вы можете скачать бесплатно Black Hat USA 2013 - Javascript Static Security Analysis made easy with JSPrime или посмотреть видео с ютуба в максимальном доступном качестве.

Для скачивания выберите вариант из формы ниже:

  • Информация по загрузке:

Cкачать музыку Black Hat USA 2013 - Javascript Static Security Analysis made easy with JSPrime бесплатно в формате MP3:

Если иконки загрузки не отобразились, ПОЖАЛУЙСТА, НАЖМИТЕ ЗДЕСЬ или обновите страницу
Если у вас возникли трудности с загрузкой, пожалуйста, свяжитесь с нами по контактам, указанным в нижней части страницы.
Спасибо за использование сервиса video2dn.com

Описание к видео Black Hat USA 2013 - Javascript Static Security Analysis made easy with JSPrime

By: Nishant Das Patnaik & Sarathi Sabyasachi Sahoo

Today, more and more developers are switching to JavaScript as their first choice of language. The reason is simple JavaScript has now been started to be accepted as the mainstream programming for applications, be it on the web or on the mobile; be it on client-side, be it on the server side. JavaScript flexibility and its loose typing is friendly to developers to create rich applications at an unbelievable speed. Major advancements in the performance of JavaScript interpreters, in recent days, have almost eliminated the question of scalability and throughput from many organizations. So the point is JavaScript is now a really important and powerful language we have today and it's usage growing everyday. From client-side code in web applications it grew to server-side through Node.JS and it's now supported as proper language to write applications on major mobile operating system platforms like Windows 8 apps and the upcoming Firefox OS apps.

But the problem is, many developers practice in-secure coding which leads to many clients side attacks, out of which DOM XSS is the most infamous. We tried to understand the root cause of this problem and figured out is that there are not enough practically usable tools that can solve real-world problems. Hence as our first attempt towards solving this problem, we want to talk about JSPrime: A javascript static analysis tool for the rest of us. It's a very light-weight and very easy to use point-and-click tool! The static analysis tool is based on the very popular Esprima ECMAScript parser by Aria Hidayat.

I would like to highlight some of the interesting features of the tool below:

JS Library Aware Source & Sinks
Most dynamic or static analyzers are developed to support native/pure JavaScript which actually is a problem for most developers since the introductions and wide-adoption for JavaScript frameworks/libraries like jQuery, YUI etc. Since these scanners are designed to support pure JavaScript, they fail at understanding the context of the development due to the usage of libraries and produce many false-positives and false-negatives. To solve this we have identified the dangerous user input sources and code execution sink functions for jQuery and YUI, for the initial release and we shall talk about how users can easily extend it for other frameworks.
Variable & Function Tracing
This feature is a part of our code flow analysis algorithm
Variable & Function Scope Aware analysis
This feature is a part of our code flow analysis algorithm
Known filter function aware
OOP & Protoype Compliant
Minimum False Positive alerts
Supports minified javascript
Blazing fast performance
Point and Click :-) (my personal favorite)

Upcoming features:

Automatic code de-obfuscation & decompression through Hybrid Analysis (Ra.2 improvisation; http://code.google.com/ra2-dom-xss-sc...)
ECMAScript family support (ActionScript 3, Node.JS, WinJS)

Комментарии

Информация по комментариям в разработке

Похожие видео

  • О нас
  • Контакты
  • Отказ от ответственности - Disclaimer
  • Условия использования сайта - TOS
  • Политика конфиденциальности

video2dn Copyright © 2023 - 2025

Контакты для правообладателей [email protected]