HNHacker News
TopNewBestAskShowJobs

psiinon

28 karma · joined August 20, 2013

submissionscomments
psiinon··on OWASP Vulnerable Web Applications Directory
A comprehensive registry of known vulnerable web and mobile applications for legal security testing and training.
psiinon··on OWASP Needs to Evolve
A group of OWASP leaders and contributors believe it needs to evolve. Now.
psiinon··on Open Source Security Foundation
Have you tried using OWASP ZAP? We're focusing on automation and feedback gratefully received. I'm also on the OpenSSF Security Tools Working Group and making security tools easier to use is definitely one of our priorities
psiinon··on Hetty: An HTTP toolkit for security research
There's been an open source option for 10 years - ZAP :)
psiinon··on Target=“_blank” – the most underestimated vulnerability ever
It's called Reverse Tabnabbing on OWASP: https://www.owasp.org/index.php/Reverse_Tabnabbing - lots more details there. Its detected by the ZAP beta passive scan rules: https://github.com/zaproxy/zap-extensions/wiki/HelpAddonsPsc...
psiinon··on Hacking with the OWASP ZAP HUD
Thanks :) Let me know what you think of it - feedback very much appreciated!
psiinon··on Setting a Baseline for Web Security Controls at Mozilla
Well, burp suite is a bit like some parts of ZAP :) Theres an overlap, but ZAP is completely free and open source. It was originally a fork of Paros (now much extended) which actually predates burp.