TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Webseclab – Web security test cases and a construction toolkit

114 点作者 Allstar超过 10 年前

3 条评论

dguido超过 10 年前
If you&#x27;re planning on scanning all of your web apps at scale, you probably want to know what you can find and what you&#x27;ll miss.<p>As for competitors, I think there is WavSep but I&#x27;m not sure how suitable it is for Yahoo&#x27;s use case (it looks like an overgrown J2EE app). People involved in that project infrequently rank scanners on their blog:<p>* <a href="https://code.google.com/p/wavsep/" rel="nofollow">https:&#x2F;&#x2F;code.google.com&#x2F;p&#x2F;wavsep&#x2F;</a><p>* <a href="http://sectooladdict.blogspot.ro/2014/02/wavsep-web-application-scanner.html" rel="nofollow">http:&#x2F;&#x2F;sectooladdict.blogspot.ro&#x2F;2014&#x2F;02&#x2F;wavsep-web-applicat...</a><p>I have the feeling that the Yahoo bug bounties are about to get a whole lot harder to claim.
评论 #8981145 未加载
what-no-tests超过 10 年前
No tests? Hello?
jdawg77超过 10 年前
This can&#x27;t be because the most advanced unit in the entire United States Military reminded the world that, last month, they <i>already</i> played the trump card can it?<p><a href="http://www.army.mil/article/141734/Army_cyber_defenders_open_source_code_in_new_GitHub_project/" rel="nofollow">http:&#x2F;&#x2F;www.army.mil&#x2F;article&#x2F;141734&#x2F;Army_cyber_defenders_open...</a><p>Nah; that must be a coincidence. After all, why would somebody after the US Military try to convince people that their security was better? Do you honestly think Yahoo has better stuff than the Tony Stark of the armed forces?<p>Please. Let&#x27;s see, Ycombinator&#x27;s got some ex-Yahoo&#x27;s as alumni, I&#x27;m sure they&#x27;ll chime in and disagree with me any moment. Yep yep. Bring it.
评论 #8980851 未加载