Code Review badge

4 exercisesEarned by 0Certificate of completion

Find the bug by reading the source. The source-to-sink method applied to SQL injection, XSS in templates, and the hardest one to see — the missing access-control check.

#ExerciseTypeAvg. timeDifficultyTier
1 SQL Injection: Code Review
Find the injection by reading the source, not just by poking the app. Learn to trace user input from a source to a dangerous sink and spot the fix.
Code review 30 min Medium 🔒 Pro
2 Secure Code Review
A repeatable way to read code for security: where to look first, the handful of risky functions to grep for, and how to write a finding a developer can act on.
Code review 30 min Medium 🔒 Pro
3 XSS: Code Review
Find cross-site scripting by reading templates, not by poking the page. Learn where output encoding is on by default, where it is switched off, and how to spot the unsafe line.
Code review 30 min Medium 🔒 Pro
4 Access Control: Code Review
Broken access control is a missing check, which makes it the hardest bug to see — there is nothing on the line, because the line is not there. Learn to review for the check that should exist.
Code review 30 min Medium 🔒 Pro