
HackerNotes TLDR for episode 172! https://blog.criticalthinkingpodcast.io/p/hackernotes-ep-172-critical-guide-to-code-review ►⠀Map auth requirement on every route before reading a single handler: ⠀•⠀The Grafana CVE-2020-13379 chain (25+ crits) came from one anomaly: every route had reqSignedIn except /avatar/:hash. Annotate routes with their auth middleware in a table, sort by exposure, and the unauth rows are your targets, pre-auth bugs scale across programs and pay better. ►⠀Framework wrappers are the real sinks, don’t grep only for eval() ⠀•⠀total.js's U.set() reaches new Function() internally with a bypassable blacklist. Ruby object.send(params[:method]) invokes anything on the object including Kernel#system. Spring controllers returning user input as a view name get it interpreted as SpEL. The dangerous behaviour is one or two layers inside framework code, never visible at the call site, sink lists must be built per framework, not per language primitive. ►⠀Parser differentials: ⠀•⠀When the security layer and backend interpret input differently, the security layer can be broken. When a WAF or auth gateway parses one way and the backend parses another, the disagreement between them is the bypass you need to chase. ►⠀Custom sanitizers fail in five predictable ways, run the checklist on every one ⠀•⠀Case-insensitive? ⠀•⠀Global (/g or replaceAll)? ⠀•⠀Recursive (one pass leaves ....// → ../)? ⠀•⠀Complete (a SQLi filter without UNION is still exploitable)? ⠀•⠀Consistent across all routes? ⠀Dev-written security functions are almost always bypassable on at least one of these, and this checklist gets you to the bug. ►⠀"Sniff for blood": anomalies are bugs in disguise, chase them immediately ⠀•⠀The one endpoint missing auth when every other has it, or the URL-fetcher that follows redirects, or the custom sanitizer that diverges from the standard library... When something looks off, the developer lost control of something. Open a scratch file, write down "what's the worst case if I fully control this?" and work backward.
Post summary
The post offers code‑review guidance highlighting common auth and framework pitfalls, referencing the Grafana CVE‑2020‑13379 chain, but it does not present new exploits, PoCs, patches, or debunking claims.
