OWASP Code Review Guide Table of Contents

Chapters Assigned

Methodology

 * 1) Introduction
 * 2) Steps and Roles
 * 3) Code Review Processes

Design review

 * 1) Designing for security

Examples by Vulnerability

 * 1) Reviewing Code for Buffer Overruns and Overflows
 * 2) Reviewing Code for OS Injection
 * 3) Reviewing Code for SQL Injection
 * 4) Reviewing Code for Data Validation
 * 5) Reviewing code for XSS issues
 * 6) Reviewing Code for Error Handling
 * 7) Reviewing Code for Logging Issues
 * 8) Reviewing The Secure Code Environment
 * 9) Transaction Analysis
 * 10) Authorization
 * 11) Authentication
 * 12) Session Integrity
 * 13) Cross Site Request Forgery
 * 14) Cryptography
 * 15) Dangerous HTTP Methods
 * 16) Race Conditions

Java

 * 1) Inner classes
 * 2) Class comparison
 * 3) Cloneable classes
 * 4) Serializable classes
 * 5) Package scope and encapsulation
 * 6) Mutable objects
 * 7) Native Methods
 * 8) Private methods & circumvention
 * 9) Static Fields

C

 * 1) Memory management
 * 2) String management
 * 3) Secure access to file system items

Automating Code Reviews

 * 1) Preface
 * 2) Reasons for using automated tools
 * 3) Education and cultural change
 * 4) Tool Deployment Model