Jay Cuthrell · @jay
103 followers · 438 posts · Server cuthrell.com
Romano Roth · @romanoroth
17 followers · 60 posts · Server fosstodon.org

Learn How to Implement DAST (Dynamic Application Security Testing)in GitHub for Enhanced Application Security

With DAST, you evaluate a web application by simulating an attack in real-time to identify vulnerabilities and potential security flaws.

youtu.be/v_xo1kgNYsE

#cybersecurity #applicationsecurity #github #dast #securitytesting #devops

Last updated 2 years ago

· @Dingodare
4 followers · 23 posts · Server mastodon.cloud
Brian Pavicic · @brianpavicic
1 followers · 3 posts · Server infosec.exchange

Extensive trials finished successfully βœ….
Blessing from trial participants βœ… Solid vetting by outside experts βœ… Set to launch at πŸš€ True-Inspect.com πŸš€ is FREE TO USE enterprise-intensive testing.

#appsec #tools #dast #websecurity #qa #pentesting

Last updated 2 years ago

OWASP ZAP · @zaproxy
607 followers · 12 posts · Server infosec.exchange

How to configure ZAP to handle difficult authentication use cases: zaproxy.org/blog/2023-02-01-au

#zaproxy #owasp #dast

Last updated 2 years ago

Ben Stroz6i · @stroz
131 followers · 674 posts · Server infosec.exchange

If you're looking for an SCA and/or DAST tool that doesn't break the bank, check out SOOS, it's pretty rad and has super simple pricing: soos.io/

#sca #SBOM #SBOMs #dast #cyclonedx

Last updated 2 years ago

aegilops :github::microsoft: · @aegilops
71 followers · 264 posts · Server fosstodon.org

@ibboard yep, it's painful!

A mix of compiler warnings, static analysis & dynamic analysis with sanitizers helped tame it for me.

Try Clang with `-Weverything -Werror`. Fix them and sometimes suppress them.

Free static analyzers include Clang Analyzer, GCC's static analyzer, CodeQL (free for open source), cbmc, cppcheck, and DevSkim.

Clang's sanitizers (ASan, UBSan, MSan, TSan) with a fuzzer (e.g. AFL++) will find lots of bugs.

#c #sast #dast #clang #securecoding

Last updated 2 years ago

white amarok · @whiteamarok
6 followers · 13 posts · Server mastodon.uno
sumgr0 · @sumgr0
146 followers · 65 posts · Server infosec.exchange

RT @emgeekboy@twitter.com

Just released: the latest version of , featuring –

β†’ URL Fuzzing
β†’ Automatic http probing
β†’ ASN / CIDR Input
β†’ Session/value sharing in workflows
β†’ Custom template (GitHub/S3)
β†’ Search engine query + template execution

github.com/projectdiscovery/fu

πŸ¦πŸ”—: twitter.com/emgeekboy/status/1

#nuclei #dast #bugbounty

Last updated 2 years ago

Brian Rogers · @brogers
153 followers · 92 posts · Server social.sdf.org

@nonlinear
Boosted and bookmarked. I'll be curious to see what SaaS recommendations you get. I hope to be researching next year to recommend one to my employer. Doesn't Burp Suite Enterprise also have this capability?

#dast #appsec

Last updated 2 years ago

Kris Hardy 🧐 · @nonlinear
34 followers · 92 posts · Server mastodon.nz

Does anyone have any thoughts about specific systems? I'm putting together some recommendations for a small team that wants automated vuln scans on a website, and it needs to be SaaS. I've used before, and I'm curious what people think of etc.

#dast #tinfoilsecurity #insightappsec #reconwithme #tenablewebapplicationscanning

Last updated 2 years ago

sumgr0 · @sumgr0
146 followers · 65 posts · Server infosec.exchange

RT @emgeekboy@twitter.com

Next major @pdnuclei@twitter.com release in progress, this time automating nuclei templates to discover "unknown" vulnerabilities in web applications.

More details to be published soon.

πŸ¦πŸ”—: twitter.com/emgeekboy/status/1

#hackwithautomation #dast #security #opensource

Last updated 2 years ago

Angerman πŸ¦… · @Angerman
22 followers · 53 posts · Server infosec.exchange

So. Should solutions include aside to / ?
For example; include a CVE like β€œjquery or glassphish out of date” etc?

#dast #cve #cwe #owasp #infosec #webapp

Last updated 2 years ago

Angerman πŸ¦… · @Angerman
38 followers · 65 posts · Server infosec.exchange

So. Should solutions include aside to / ?
For example; include a CVE like β€œjquery or glassphish out of date” etc?

#dast #cve #cwe #owasp #infosec #webapp

Last updated 2 years ago

G(0_o)S · @kgoossens
28 followers · 22 posts · Server fosstodon.org

πŸŽ‰ 15.6 is here! With β›” abuse rate limiting, Support for πŸ”£ special characters in CI/CD variables, πŸ‘₯ group and subgroup-level scan result policies, πŸ”¬ DAST API analyzer for on-demand DAST API scans and 🫢 much more!

about.gitlab.com/releases/2022

#gitlab #git #cicd #devops #devsecops #piplines #dast #policies

Last updated 2 years ago

Alex Floyd Marshall · @afloydmarshall
47 followers · 39 posts · Server infosec.exchange

The standout quote: β€œintrusive black-box testing techniques like DAST and pen testing are particularly effective for surfacing exploitable vulnerabilities in the software development lifecycle”
thenewstack.io/synopsyss-repor

#infosec #softwaredevelopment #devsecops #dast #pentest

Last updated 2 years ago

@steceroni βœ… · @steceroni
16 followers · 30 posts · Server ioc.exchange

RT @Burp_Suite@twitter.com

Introducing the brand new flavour of Burp Suite - completely free, and available for a CI/CD pipeline near you … portswigger.net/blog/free-dast

πŸ¦πŸ”—: twitter.com/Burp_Suite/status/

#cicd #dast

Last updated 2 years ago

ITSEC News · @itsecbot
856 followers · 32557 posts · Server schleuss.online

DevSecOps Scanning Challenges & Tips - There are many ways to do DevSecOps, and each organization β€” each security team, ... feedproxy.google.com/~r/securi

#dast #probely #devsecops

Last updated 3 years ago