13 findings no Juice Shop. Nenhuma virou issue.
Pessoal, eu ia colar o Juice Shop na tabela do post das três portas . Tinha 13 findings com requisito ASVS e arquivo:linha . SQL concatenado, eval no username, CORS * , cesto de outro usuário. O modelo tinha trabalhado. A tabela ia ficar “mais completa”. Aí li o package.json : probably the most modern and sophisticated insecure web application . Não é gap. É o produto. O que você leva daqui: lab…
In a recent report, 13 vulnerabilities were identified in the Juice Shop web application, but no issues were reported. The findings include issues such as SQL injection, XSS, CORS, and insecure user management. The report highlights that Juice Shop is designed to be an insecure lab environment, not a hardened application. The author stresses that the table of 13 findings should not be considered as issues since the sinkholes already have challenge names.
The report emphasizes that the purpose of the academy is to help professionals identify and understand sinks rather than report them as incidents. The takeaway is that professionals should question whether a finding should be reported as an issue or left as a sinkhole, encouraging a more thoughtful approach to security testing.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.