Finding log4shell with CodeQL

Agenda:

  • OWASP Updates
  • Talk: Rise of captain hindsight: Finding Log4Shell with CodeQL with Alvaro Munoz
  • Open discussion

Title: Rise of captain hindsight: Finding Log4Shell with CodeQL

Abstract: In this talk, Alvaro Muñoz of the GitHub Security Lab will use Log4Shell to demonstrate CodeQL, a free and powerful static analysis tool, in action. He will review Log4Shell’s root cause, how it manifests in code and how it could have been discovered using CodeQL.

In CI/CP pipelines, CodeQL is configured to operate in a developer-first mode to reduce false positives to a minimum and return the most accurate results. However for security researchers, CodeQL can also be configured to operate in a less conservative mode which results in more false positives but also less false negatives.

In this process, Alvaro will discuss some specific examples of what it means to operate on each of the above-mentioned modes and how someone could configure CodeQL to better serve their objectives, either as a security researcher or a developer.

Bio: Alvaro Muñoz works as Principal Security Researcher with GitHub Security Lab team. Previously he worked as an Application Security Consultant helping top enterprises to deploy their application security programs. He is passionate about Web Application security where he has focused most of his research. Muñoz has presented at many Security conferences including BlackHat, DEFCON, RSA, OWASP AppSec EU and US, JavaOne, etc, and holds several infosec certifications, including OSCP, GWAPT, and CISSP.

The talk will be streamed on YouTube - we will provide the YouTube link closer to event.

We are looking to publish on @YouTube the recordings of our meetups. If you would like to be notified when we a new video is published, please feel free to subscribe on our channel at:
https://www.youtube.com/channel/UC1lUjD1zM1gD2JkSa1rxMYQ