3 ms·
I don't think "someone who just scans websites with automated tools reporting vulnerabilities" is inherently a bad thing. At worst you get a free invocation of
by mooman219 5y ago
I don't think "someone who just scans websites with automated tools reporting vulnerabilities" is inherently a bad thing. At worst you get a free invocation of a tool you didn't know existed, at best you start a dialog and integrate the tool in your automated testing.
- ALittleLight 5y agoNo, I think at worst you waste your time and attention reading reports of benign issues from the invocation of an automated tool that you didn't care to execute. I think this is probably the worst, and median case. Maybe there is a way this could be useful. "I'm a security researcher. I ran this tool on your site which found these vulnerabilities. Here's why I think these vulnerabilities may be meaningful, even if they are first seem not to be" is, I think, a nice contribution and, if you make a change based on those suggestions, that merits some kind of credit. That's not really what is discussed in the article though.