Dynamic application security testing: Difference between revisions

Content deleted Content added
NEUrOO (talk | contribs)
NEUrOO (talk | contribs)
Line 8:
=== Vulnerabilities ===
Even if we cannot enumerate all vulnerabilities that the webapps scanners are looking for, they are divided in 4 parts:
* [Input/Output validation]/[Weaknesses]: [[XSS]], [[SQL Injection]], ...
* Logical flaws: [[Cross-Site Request Forgery]] (CSRF), ...
* Specific application problems
* Server configuration mistakes/errors: Path Disclosure ...