Urgent.News

What's breaking now, across thousands of outlets.

Tech

13 findings at the Juice Shop. None became an issue.

Pessoal, eu ia colar o Juice Shop na tabela do post das três portas . Tinha 13 findings com requisito ASVS e arquivo:linha . SQL concatenado, eval no username, CORS * , cesto de outro usuário. O modelo tinha trabalhado. A tabela ia ficar “mais completa”. Aí li o package.json : probably the most modern and sophisticated insecure web application . Não é gap. É o produto. O que você leva daqui: lab…

Translated from Portuguese Read in Portuguese

A security researcher analyzed the Juice Shop and WebGoat applications, which are intentionally insecure, using a static scanner and found 13 and 11 security findings respectively. The findings included issues such as SQL injection, cross-site scripting (XSS), and insecure configurations. However, the researcher noted that these findings were not actual security issues, but rather part of the learning experience provided by the applications.

The researcher emphasized the importance of distinguishing between a security lab, like Juice Shop, and a real-world product, and highlighted the value of experienced security professionals who can prioritize and contextualize security findings.

Written by urgent.news from Dev.to's report — not a translation of it. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Finding "Duplicates Through Time"

Finding "Duplicates Through Time": How I Cleaned Up 300GB of Photos Without Losing Quality Lately, I have been playing around with my personal photo and video library (around 300GB of files, spanning…

How to get a Confluence table into Excel

Short answer. Confluence exports whole pages to PDF and Word, but it has no built-in export for a single table. Select the table on the page, copy it, and paste into Excel: for a simple rectangular…

More from Sunday 6 September →