Skip to content

Commit 7eb9c1e

Browse files
Fix markdown syntax.
1 parent ce7cad6 commit 7eb9c1e

1 file changed

Lines changed: 17 additions & 17 deletions

File tree

README.md

Lines changed: 17 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
This is the main git repository of [GitHub Security Lab](https://securitylab.github.com/).
44
We use it for these main purposes:
55

6-
* We use [issues on this repo](https://github.com/github/securitylab/issues?q=is%3Aissue+is%3Aopen+label%3A%22All+For+One%22+) to track CodeQL [bounty requests](https://securitylab.github.com/bounties).
6+
* We use [issues on this repo](https://github.com/github/securitylab/issues?q=is%3Aissue+is%3Aopen+label%3A%22All+For+One%22) to track CodeQL [bounty requests](https://securitylab.github.com/bounties).
77
* We use it for publishing some of our proof-of-concept exploits (after the vulnerability has been fixed). These PoCs can be found in the [SecurityExploits](SecurityExploits) sub-directory.
88
* Examples of CodeQL queries, which can be found in the [CodeQL_Queries](CodeQL_Queries) sub-directory.
99

@@ -17,28 +17,28 @@ We use it for these main purposes:
1717
### Example queries
1818

1919
* Java
20-
** [Apache Struts CVE-2018-11776](CodeQL_Queries/java/Apache_Struts_CVE-2018-11776)
20+
* [Apache Struts CVE-2018-11776](CodeQL_Queries/java/Apache_Struts_CVE-2018-11776)
2121
* C/C++:
22-
** [Apple XNU icmp_error CVE-2018-4407](CodeQL_Queries/cpp/XNU_icmp_error_CVE-2018-4407)
23-
** [Facebook Fizz integer overflow vulnerability (CVE-2019-3560)](CodeQL_Queries/cpp/Facebook_Fizz_CVE-2019-3560)
24-
** [Eating error codes in libssh2](CodeQL_Queries/cpp/libssh2_eating_error_codes)
22+
* [Apple XNU icmp_error CVE-2018-4407](CodeQL_Queries/cpp/XNU_icmp_error_CVE-2018-4407)
23+
* [Facebook Fizz integer overflow vulnerability (CVE-2019-3560)](CodeQL_Queries/cpp/Facebook_Fizz_CVE-2019-3560)
24+
* [Eating error codes in libssh2](CodeQL_Queries/cpp/libssh2_eating_error_codes)
2525
* Javascript
26-
** [Etherpad CVE-2018-6835](CodeQL_Queries/javascript/Etherpad_CVE-2018-6835)
26+
* [Etherpad CVE-2018-6835](CodeQL_Queries/javascript/Etherpad_CVE-2018-6835)
2727
* C#
28-
** [C# Zip Slip demo](CodeQL_Queries/csharp/ZipSlip)
28+
* [C# Zip Slip demo](CodeQL_Queries/csharp/ZipSlip)
2929
* GitHub Actions:
30-
** [pull_request_target with explicit pull request checkout](CodeQL_Queries/actions/pull_request_target.ql)
31-
** [Command injection from user-controlled Actions context](CodeQL_Queries/actions/script_injections.ql)
30+
* [pull_request_target with explicit pull request checkout](CodeQL_Queries/actions/pull_request_target.ql)
31+
* [Command injection from user-controlled Actions context](CodeQL_Queries/actions/script_injections.ql)
3232

3333
### Videos
3434

3535
* Conference talks/workshops:
36-
** [Finding security vulnerabilities in JavaScript with CodeQL - GitHub Satellite 2020](https://www.youtube.com/watch?v=pYzfGaLTqC0)
37-
** [Finding security vulnerabilities in Java with CodeQL - GitHub Satellite 2020](https://www.youtube.com/watch?v=nvCd0Ee4FgE)
38-
** [CodeQL as an auditing oracle - POC 2020](https://www.youtube.com/watch?v=XmAEgl8bVhg)
39-
** [mbuf-oflow: Finding Vulnerabilities In iOS/MacOS Networking Code](https://www.youtube.com/watch?v=0EHP2gzwVAY)
36+
* [Finding security vulnerabilities in JavaScript with CodeQL - GitHub Satellite 2020](https://www.youtube.com/watch?v=pYzfGaLTqC0)
37+
* [Finding security vulnerabilities in Java with CodeQL - GitHub Satellite 2020](https://www.youtube.com/watch?v=nvCd0Ee4FgE)
38+
* [CodeQL as an auditing oracle - POC 2020](https://www.youtube.com/watch?v=XmAEgl8bVhg)
39+
* [mbuf-oflow: Finding Vulnerabilities In iOS/MacOS Networking Code](https://www.youtube.com/watch?v=0EHP2gzwVAY)
4040
* CodeQL demos from the Semmle days (short Youtube videos):
41-
** [PII data leaks: Identifying personal information in logs with CodeQL](https://www.youtube.com/watch?v=hHaOxbyqy44)
42-
** [Vulnerability Hunting: Quest for an Exploit using QL](https://www.youtube.com/watch?v=irrYp3wdtsw)
43-
** [Finding Insecure Deserialization in Java](https://www.youtube.com/watch?v=XsUcSd75K00)
44-
** [Finding integer overflows in Libssh2](https://www.youtube.com/watch?v=czXicfULOfk)
41+
* [PII data leaks: Identifying personal information in logs with CodeQL](https://www.youtube.com/watch?v=hHaOxbyqy44)
42+
* [Vulnerability Hunting: Quest for an Exploit using QL](https://www.youtube.com/watch?v=irrYp3wdtsw)
43+
* [Finding Insecure Deserialization in Java](https://www.youtube.com/watch?v=XsUcSd75K00)
44+
* [Finding integer overflows in Libssh2](https://www.youtube.com/watch?v=czXicfULOfk)

0 commit comments

Comments
 (0)