Code Analysis
Static Code Analysis - Tools
Sourcebot
Training - Vulnerable Code Snippets
Search for credentials
Credentials in git reposXSS in PHP Source Code
PHP Code Analysis
SpotBugs
Java Code
Semgrep
Rules - C/C++
Rules - Python, Javascript/GraphQL, Go, Rust
Rules - Java/Android, PHP, Kotlin
Rules - Multiple Languages
Opengrep
Sonarqube
Scan
Snyk
Online
Not recommanded or remove sensitive information

Snyk CLI
CodeQL
Example with Visual Studio:
Vulnhuntr
PHP Static Analysis Tool
Dependency Takeover - Node.js
List of Static Application Security Testing (SAST) Tools
Resources
SEI CERT C Coding Standard
SEI CERT C++ Coding Standard
SEI CERT Oracle Coding Standard for Java
OWASP Secure Coding Practices
Interesting Books
Interesting BooksThe Web Application Hacker’s Handbook The go-to manual for web app pentesters. Covers XSS, SQLi, logic flaws, and more
Bug Bounty Bootcamp: The Guide to Finding and Reporting Web Vulnerabilities Learn how to perform reconnaissance on a target, how to identify vulnerabilities, and how to exploit them
Real-World Bug Hunting: A Field Guide to Web Hacking Learn about the most common types of bugs like cross-site scripting, insecure direct object references, and server-side request forgery.
Support this Gitbook
I hope it helps you as much as it has helped me. If you can support me in any way, I would deeply appreciate it.
Last updated


