DEV Community

Mohamed AboElKheir profile picture

Mohamed AboElKheir

Helping teams build secure software

Secure Code Review Challenge #2: Professional — Solution (Clean Code Can Still Be Vulnerable)

Secure Code Review Challenge #2: Professional — Solution (Clean Code Can Still Be Vulnerable)

Comments 2
11 min read

Want to connect with Mohamed AboElKheir?

Create an account to connect with Mohamed AboElKheir. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
Secure Code Review Challenge #1: Schooled — Solution (One Whitespace Character Away From Admin)

Secure Code Review Challenge #1: Schooled — Solution (One Whitespace Character Away From Admin)

Comments
10 min read
Introducing the Secure Code Review Challenge (Practice Real-World Reviews)

Introducing the Secure Code Review Challenge (Practice Real-World Reviews)

Comments
4 min read
Clinejection: One Misconfigured GitHub Action Can Compromise Your App (Deep Dive & Lessons Learned)

Clinejection: One Misconfigured GitHub Action Can Compromise Your App (Deep Dive & Lessons Learned)

Comments
9 min read
Let "Claude Code" Do Your Pentesting!

Let "Claude Code" Do Your Pentesting!

Comments
7 min read
GitHub RCE (CVE-2026-3854) - Deep Dive & Lessons Learned

GitHub RCE (CVE-2026-3854) - Deep Dive & Lessons Learned

1
Comments
8 min read
AI-Powered Security Code Reviews That Actually Work: A Threat-Model-First Methodology

AI-Powered Security Code Reviews That Actually Work: A Threat-Model-First Methodology

Comments
9 min read
What AppSec Engineers Actually Do (and Why It Matters)

What AppSec Engineers Actually Do (and Why It Matters)

Comments
7 min read
How Reachability Analysis 🔎 can help with open source vulnerabilities mess (Coana as an example)

How Reachability Analysis 🔎 can help with open source vulnerabilities mess (Coana as an example)

Comments
10 min read
Lessons Learned #4: One error message could expose all your data (FileSender CVE-2024–45186)

Lessons Learned #4: One error message could expose all your data (FileSender CVE-2024–45186)

Comments
5 min read
Lessons Learned #3: Is your random UUID really random? (Account takeover with the sandwich 🥪 attack)

Lessons Learned #3: Is your random UUID really random? (Account takeover with the sandwich 🥪 attack)

1
Comments
7 min read
Lessons Learned #2: Your new feature could introduce a security vulnerability to your old feature (Clickhouse CVE-2024-22412)

Lessons Learned #2: Your new feature could introduce a security vulnerability to your old feature (Clickhouse CVE-2024-22412)

Comments
4 min read
Lessons Learned #1: One line of code can make your application vulnerable (Pre-Auth RCE in Metabase CVE-2023–38646)

Lessons Learned #1: One line of code can make your application vulnerable (Pre-Auth RCE in Metabase CVE-2023–38646)

Comments
4 min read
How to make “Input validation” easy for your devs

How to make “Input validation” easy for your devs

1
Comments
5 min read
loading...