Whitebox testing or source code review can be most effective to identify hidden security issues in the source code. Before we begin our whitebox source code review, there are some preparation and input will help us to judge how (approaches, tools) and what (which modules) to do the security source code review.
The following is a list we may check before performing the source code review; take a look at this table:
Whitebox testing input |
Considerations |
Source code |
|
Threat-modeling documents |
The threat-modeling provides a good reference to identify... |