发布于 

T-SEC Application Security Development

Xcheck

Introduction to Xcheck

Xcheck is a static application security testing (SAST) tool that aims to uncover hidden security risks in code and improve code security quality.
Xcheck supports security checks in Go, Java, Nodejs, PHP, and Python. Vulnerabilities include SQL injection, code injection, command injection, cross-site scripting, deserialization vulnerability, and path traversal. In terms of framework support, xcheck has built-in coverage of common web frameworks.

language frame
Go Gin,Beego,Iris,net/http,fastrouter,httprouter,go-restful,mux
Java Spring,HttpServlet,WebService,jax-rs
Nodejs Koa,Express
PHP Thinkphp,Laravel,CodeIgniter,Yii,Yaf
Python Django,Flask,Tornado,Webpy,Bottle,BaseHTTPServer

Directions for use

On the Solution page, you can see that the Xcheck security rule package is enabled in the TCA Official Experience Analysis Solution. Go to the official scheme > select the codebase for the analysis > start the analysis.
Note: Currently, Xcheck security rule packages can only be tried in the official experience analysis solution.


image
image

T-SEC Application Security Development

T-SEC Application Security Development
Application Security Development (codenamed Xcheck) provides you with high-quality code analysis services. With excellent algorithms and engineering implementations, Xcheck can find security vulnerabilities in the code at a very fast speed with a very low false positive and false negative rate.

Product Features:

Low false positives

Xcheck is able to accurately understand the syntax characteristics of different languages, which basically solves the false positives caused by not understanding the code. In addition, Xcheck is able to identify user-defined security guards, further reducing false positives

Low false negatives

Xcheck already has a rich set of rules built into mainstream frameworks and risk functions; In addition, for unsupported frameworks and functions, you can supplement the corresponding recognition capabilities with custom rules.

It’s fast

Xcheck has a set of excellent code analysis algorithms, which solves the problem of low efficiency of traditional static analysis tools on the premise of ensuring accurate analysis.

Compare editions

Function

  1. SaaS test drive
  2. Privatized Deployment Edition

Trial method

  1. WeChat login, online experience
  2. Contact a worker to apply for privatization testing

Suitable for

  1. Personal Security Researcher/Enterprise User
  2. Only applicable to corporate users

Trial time

  1. No limit
  2. Contact staff to request a test authorization

Number of scans

  1. There is a limit of 20 per account
  2. There is no limit to the number of times you can use the trial period

Supported Languages

  1. Java/Go/Python/PHP/JavaScript
  2. Java/Go/Python/PHP/JavaScript/C/C++

Code source

Only the platform can upload code compressed packages

  1. Support the platform to upload code compression packages;
  2. Git、SVN、FTP;
  3. Support integration into various DevOps platforms;
  4. Support integration into IDE tools in the form of plug-ins.

Platform features

Only task scanning and result viewing are supported

  1. Support task scanning and result viewing;
  2. Support project management capabilities;
  3. Support user organization structure setting and user role and authority management;
  4. Support rule customization and rule base management;
  5. Support statistical analysis;
  6. Support email, SMS, enterprise WeChat and defect management system docking;
  7. Support log management, device management, queue management, background configuration and other system settings