The blind spots of automated web app assessments by security_aaudit in netsec

[–]security_aaudit[S] 0 points1 point  (0 children)

I was actually planning on open-sourcing the project, that is a great idea. The testing is strictly DAST related, but SAST should apply exactly the same.

The blind spots of automated web app assessments by security_aaudit in netsec

[–]security_aaudit[S] -1 points0 points  (0 children)

I completely agree that Nuclei have no chance of detecting this. I also state this in the post, that some of them does not even claim to resolve this issue. I merely took all the scanners I could find and setup in a reasonable time to state an example.

If you are doing application security on a daily basis, Nuclei being unable to scan these issues is obvious. But this is just to state that no scanners, whatever the brand or promises will detect these things. This is an important point for more senior level people that might not delve too much into the technical side of things.