WEBBOOK CHAPTER

웹서비스 개발 도구 상자: 33장. Security scanner를 허가된 범위에서 사용한다

33장. Security scanner를 허가된 범위에서 사용한다

OWASP ZAP 같은 scanner는 proxy·active scan으로 요청을 만들 수 있다. 소유한 환경과 승인된 범위, rate, 인증 계정, 제외 경로를 정한다. production destructive endpoint를 active scan하지 않는다.


passive scan -> authenticated staging crawl -> bounded active scan
-> finding reproduce -> owner/severity -> fix test -> rescan

scanner 결과를 취약점 확정이나 무취약 보증으로 취급하지 않는다. false positive와 missed business authorization을 사람이 검토한다. report에 token과 개인정보가 없는지 확인한다.