Ten Years of Service
Posts: 117
Threads: 29
New MIT Scanner Finds Web App Flaws in a Minute 04-19-2016, 07:42 AM
#1
"..Its developer Joseph P. Near, under the supervision of MIT Computer Science and Artificial Intelligence Laboratory professor Daniel Jackson, ran the scanner against 50 open source Ruby on Rails applications that were favorited on Github for one reason or another. The scans turned up 23 new vulnerabilities that were reported to the respective developers; the maximum time per scan, MIT said, was 64 seconds."
Source [
Threatpost]
PLX-2M
~ Dead Enough For Life ~
β’
Fourteen Years of Service
Posts: 18,868
Threads: 2,029
RE: New MIT Scanner Finds Web App Flaws in a Minute 04-19-2016, 09:28 AM
#2
Is it only useful for Ruby on Rails? I don't know many that use that.
β’
Twelve Years of Service
Posts: 1,038
Threads: 59
RE: New MIT Scanner Finds Web App Flaws in a Minute 04-19-2016, 12:37 PM
#3
There's still only so much a scanner can find, "advanced" or not. Bugs hide, they're never easy to find.
β’
Twelve Years of Service
Posts: 1,038
Threads: 59
New MIT Scanner Finds Web App Flaws in a Minute 04-19-2016, 03:10 PM
#7
DEFCON quote
>Companies request pentest
>No exploitation, just a vulnerability scan.
(._.)
β’
Twelve Years of Service
Posts: 1,334
Threads: 67
RE: New MIT Scanner Finds Web App Flaws in a Minute 04-20-2016, 02:09 AM
#8
If it's just scanning source code... yeah...
Might not be too great in the wild.
β’
Ten Years of Service
Posts: 117
Threads: 29
RE: New MIT Scanner Finds Web App Flaws in a Minute 04-20-2016, 04:09 AM
#9
We will find out more once the ICSE conference takes place May 14-22. I will keep looking for more info on this and will report back.
PLX-2M
~ Dead Enough For Life ~
β’
Twelve Years of Service
Posts: 1,038
Threads: 59
RE: New MIT Scanner Finds Web App Flaws in a Minute 04-20-2016, 01:50 PM
#10
I'm sure the developers will bring up the obvious weaknesses in the conference. Preferably in large, red, bold letters:
THIS IS NOT A COMPLETE PEN TEST
Static Code Analysis Only Gets You So Far
β’