Performing JavaScript Static Analysis by Lewis Ardern

Abstract: Performing JavaScript Static Analysis! JavaScript is everywhere, in our browsers, on our servers, and even runs our databases. Blackbox testing is all well and good, but to be able to understand issues, you need to look under the hood and look at the code. This talk will give a high-level overview on how to perform static analysis against JavaScript in a manual and automated fashion, with the emphasis on: • Common review methods • Common security issues • Strongly typed JavaScript and Transpiling • Tools and Linters • Customizing Tools and Linters Bio: Lewis Ardern is a senior security consultant at Synopsys. His primary areas of expertise are in web security and security engineering. Lewis enjoys creating and delivering security training to various types of organizations and institutes in topics such as web and JavaScript security. He is also the founder of the Leeds Ethical Hacking Society and has helped develop projects such as SecGen (https://github.com/cliffe/secgen), which generates vulnerable virtual machines on the fly for security training purposes. Lewis is currently working toward his PhD in web security.
