Open GoogleCodeExporter opened 9 years ago
They are. Didn't plan to release it for different development technologies (I'm
trying to mimic their behavior in some of the test cases), but I'll think how
they can be used.
Original comment by sectoola...@gmail.com
on 16 Dec 2011 at 2:57
Please be very careful about mimicing other languages/vulnerabilities. You
can't guess all the ways a scanner attempts to determine a vulnerability and
you could end up making scanners FN and have your results be untrustworthy.
(See:
http://www.veracode.com/blog/2012/05/whitepaper-broken-logic-avoiding-the-test-s
ite-fallacy/).
Original comment by isaac.da...@gmail.com
on 20 Jul 2012 at 8:41
Original issue reported on code.google.com by
soroush....@gmail.com
on 24 Jan 2011 at 10:50Attachments: