Resources for source code review for beginner
دي ريسورس للي حابب يذكر source code review
١- اتعلم لغة برمجه باك ايند php or python او اي لغة باك ايند
2- اعمل كام ابلكيشن زاي الي قال عليهم المهندس ابراهيم حجازي الي هم صفحة سيرش، صفحة رفع صور، صفحة تسجيل دخول، الاخر
3- شوف كورس بتاع المهندس او بتاع فليكس ولم تخلص مثلاً ثغره Xss وطبق عليها روح شوف الكود الي المهندس عاملو مع كل ليفيل
4- بعدين روح بقا علي DVWA وشوف كل ليفيل لنفس ثغره من low, medium, high وسيب impossible دلوقتي هنجيلو بعدين
link DVWA: https://github.com/digininja/DVWA/tree/master/vulnerabilities
5- طبب ياعمر لي هنشوف كل ليفيل في ثغره علشان يامعلم تفهم لي bypass ده حصل ولي بيتمنع وده هيخليك تفرق عن ناس كتير بطبق وخلاص
6- خلصت انت كده لا فاضل خطوه اتعلم بقا ازي تعمل mitigation وده لينك هيفيدك جدا انت بس اختار لغة البرمجة الي انت عارفها واختار ثغره وهتلقي كود مصاب وكود معمله mitigation
link:
https://rules.sonarsource.com/
وبرضو عندك المهندس اوسام الزيرو عامل كام فديو حلوين اوي
اكتب بس في يوتيوب php security وفي قناة تانيه اكتب برضو pro php security الاتنين بيشرحو بلعربي طبعا لو معرفتش تلقيهم ادخل عندي علي
صفحة هتلقيني كونت منزله
pro php security
https://www.youtube.com/watch?v=RbuLNDobNv8
7- دلوقتي ارجع لي ليفيل impossible وهتلقي نفسك فهمت لي بقا impossible وتعلم منه وضيف للاب بتاعك
افتكر كويس انك تعمل كل الكلام ده مع كل ثغره بتذكرها
8- طبق بقا mitigation الي تعلمتو في للاب بتاعك الي انت عاملتو
9-بعد كام ثغره حلو كده روح علي pentestarlab في بلوج لل source code review هتفرق معاك جامد اوي
10-لم تخلصهم وتخلص كام ثغره ادخل علي link ده link ده ياباشا في كودين انت مفروض هتقراء ده وهتقراء ده وتختار اين فيهم معموله mitigation صح ولو صح هيديك لون اخضر ولو غلط هيديك لون احمر ويقولك غلط ليه
link:
https://owasp.org/SecureCodingDojo/codereview101/
to practice your skills
لو انت مخلص كل الكلام الي فوق وحابب تزود شوف لينك ده
https://www.linkedin.com/posts/gabriellebotbol_cybersecurity-cybersaezcuritaez-pentest-activity-7085211260232814592-5d5p?utm_source=share&utm_medium=member_android
ان احسن فمن الله وان اخطات فمن نفسي اومن الشيطان
Resources for source code review for beginner
1- Start by learning a backend programming language such as PHP, Python, or .NET.
2-Create 5 or 10 applications like a search page, login page, registration page, file upload page, etc.
3-Then go to learn OWASP TOP 10 ,wine you learn any models like model XSS (Cross-Site Scripting), and finshed the model go to in your search page and try to exploit that, then looking the source code in your page the code is vulnerable to Reflect XSS (RXXS).
4-Then Visit the DVWA (Damn Vulnerable Web Application) repository on GitHub and analyze the source code for RXXS. Look at all levels of difficulty (low, medium, high).
link DVWA: https://github.com/digininja/DVWA/tree/master/vulnerabilities
5-Omar Why I see all levels??!
because wien you seeing all levels, Understanding why the bypass is happened,and what is mistakes that lead to vulnerabilities
6- Now Learn about mitigation techniques for the identified vulnerabilities. Visit the following link for guidance: https://rules.sonarsource.com/. Select the programming language and vulnerability you want to learn about.
7-Return to the DVWA "impossible" level and apply the mitigation techniques to enhance the security of your search page's code.
8-Return in your code to mitigation your code
$$$ Remember repeat this process for every vulnerability model you learn from OWASP $$$
9-then go to pentestarlab there many labs for source code review , Choose a programming language you are familiar with, such as PHP or python to learn more
10. Once you have completed the above steps, practice your skills by visiting the following link: https://owasp.org/SecureCodingDojo/codereview101/.
If you need more resources after completing these steps, you can refer to the following LinkedIn post: https://www.linkedin.com/posts/gabriellebotbol_cybersecurity-cybersaezcuritaez-pentest-activity-7085211260232814592-5d5p?utm_source=share&utm_medium=member_android
البشمهندس عمر ناصر