Seattle Java User Group: Detect complex code patterns using Semgrep

A walk through of practical and real-world Semgrep examples for Java

October 7th, 2021
Share

In this talk, Kurt Boberg from Chegg and Daghan Altas from r2c show how to use Semgrep to detect complex code patterns in Java, with a particular focus on real-word and practical examples including detection of SQL injections, reverse shells, and XML external entity injections.

Thanks to the Seattle Java User Group for hosting this event!

About

Semgrep enables teams to use industry-leading AI-assisted static application security testing (SAST), supply chain dependency scanning (SCA), and secrets detection. The Semgrep AppSec Platform is built for teams that struggle with noise by helping development teams apply secure coding practices.