A
A
Alexey Vladykin2022-01-24 11:29:26
Scanning
Alexey Vladykin, 2022-01-24 11:29:26

Should I trust the risk assessment in OWASP ZAP?

Should I trust the risk assessment in OWASP ZAP? Or is it individually calculated?

61ee630cabaa5297206382.png

All good and positive :-)

Answer the question

In order to leave comments, you need to log in

2 answer(s)
A
Alexander, 2022-01-24
@AlexVladika

OWASP - serious guys, their tools are popular.
But an attack is a complex event. And the tools only indicate potentially "interesting" places that the information security specialist could analyze them and not overlook anything.
You have a warning that a cookie without the "HttpOnly" flag means that it can be stolen via JavaScript, for example. Badly? Yes. Dangerously? Yes. But if the attacker does not have access to modify the content on the site (or there is no XSS vulnerability), then the risks with HttpOnly are reduced to zero. What's the point if you can't pull them out?

U
Uncle Seryozha, 2022-01-28
@Protos

It’s worth it, some companies don’t eliminate everything above low immediately when writing the code, they leave it in the backlog until free time if AppSec doesn’t prove the opposite with pens

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question