33장. Security scanner를 허가된 범위에서 사용한다
OWASP ZAP 같은 scanner는 proxy·active scan으로 요청을 만들 수 있다. 소유한 환경과 승인된 범위, rate, 인증 계정, 제외 경로를 정한다. production destructive endpoint를 active scan하지 않는다.
passive scan -> authenticated staging crawl -> bounded active scan
-> finding reproduce -> owner/severity -> fix test -> rescan
scanner 결과를 취약점 확정이나 무취약 보증으로 취급하지 않는다. false positive와 missed business authorization을 사람이 검토한다. report에 token과 개인정보가 없는지 확인한다.