wsastsupport Profile Banner
wSAST Support Profile
wSAST Support

@wsastsupport

Followers
82
Following
3
Media
4
Statuses
19

Support for wSAST (https://t.co/TbMwz0RfG3)

Joined June 2022
Don't wanna be here? Send us removal request.
@wsastsupport
wSAST Support
9 months
Our activation server had a problem updating which may have made activation of wSAST fail - if you encountered this please try again it should all be fixed now!.
0
1
1
@wsastsupport
wSAST Support
9 months
RT @peterwintrsmith: My @IOActive hack::soho talk on wSAST is finally online! If static code analysis interests you then you may enjoy hear….
0
23
0
@wsastsupport
wSAST Support
1 year
Finally the latest wSAST update is released. This adds a number of optimisations for repeated function calls, fixes some bugs in rules engine instance sharing, and adds more rules courtesy of GPT. Full changes here:. User guide:.
Tweet media one
0
0
6
@wsastsupport
wSAST Support
1 year
… the latter will help focus rule creation and hopefully creation of shims for common frameworks. I plan to look into using GPT to automate this from reported missing code.
0
0
1
@wsastsupport
wSAST Support
1 year
Development of wSAST continues! A number of bugs have been fixed when handling interface types, a race condition in the common rules engine, and functionality to dump missing imports, types and methods to file soon incoming….
1
1
0
@wsastsupport
wSAST Support
1 year
RT @peterwintrsmith: Thanks everyone who came out to @IOActive hack soho to see my talk on wSAST! I’ve put my slides online here: https://t….
0
19
0
@wsastsupport
wSAST Support
2 years
RT @peterwintrsmith: I had an idea for @wsastsupport - I might write a “parser” that allows you to specify language components in a regex f….
0
3
0
@wsastsupport
wSAST Support
2 years
wSAST v0.1-alpha (release date 18-12-2023) is now public!. This release contains support for annotation-based rules, and support for filtering entry points when launching scans, as well as several important improvements to path finding, rule matching.
Tweet media one
1
7
15
@wsastsupport
wSAST Support
2 years
Development of wSAST is still actively ongoing - soon an update will be released which should substantially improve pathfinding, fix a few issues with analysis, provide new annotation-based rules for popular frameworks, reduce FPs and increase accuracy for static and df scans!.
0
1
0
@wsastsupport
wSAST Support
2 years
Following a slight hiatus in development annotation based rules are now working in the common rules engine; this should allow attributes such as Serialized or QueryParam to taint variables being traced. Further improvements underway and hope to release in a few weeks.
0
1
1
@wsastsupport
wSAST Support
2 years
wSAST v0.1-alpha (release date 25-08-2023) is now public. This adds a basic JSP processor and includes quite a number of minor fixes and improvements to Java parsing and general analysis. Full list of changes: Mustache compiler call graph for eyecandy!
Tweet media one
1
7
11
@wsastsupport
wSAST Support
2 years
Apologies for the wSAST site being down today; the Azure subscription needed updated billing. It should be back now!. Coming this weekend, a number of fixes and improvements to Java parsing, and JSP support.
0
1
2
@wsastsupport
wSAST Support
2 years
Soon incoming, some further minor Java language processor fixes, and basic JSP processor enabling scanning of JSP files. Planned are annotation-based rules allowing parameters marked e.g. QueryParam or entire classes marked Serialized etc. to be sources.
0
1
0
@wsastsupport
wSAST Support
2 years
The --filter-root feature allows graphing calls where only the root call matches the specified filter rather than requiring source and/or dest to match. Useful for investigating flows from a specific function or family of functions.
0
0
0
@wsastsupport
wSAST Support
2 years
wSAST v0.1-alpha (release date 07-08-23) is now available for download from This fixes a number of bugs in analysis, graphing and adds a few useful features for manual analysis such as --filter-root (see image). Changes here:
Tweet media one
1
2
7
@wsastsupport
wSAST Support
2 years
A small update for wSAST will be released in the next few days, fixing a couple of bugs in graphing and path discovery and containing some minor improvements to Java translation.
0
0
0
@wsastsupport
wSAST Support
2 years
RT @peterwintrsmith: Today I am pleased to announce the release of a code analyser I’ve been working in my free time - wSAST ( https://t.co/….
0
163
0