2 ms·
Just scanned one of my websites. Pretty quick results, once I got through the signup, email confirmation (why!), and site ownership confirmation. My favorite p
by cloudwalking 14y ago
Just scanned one of my websites. Pretty quick results, once I got through the signup, email confirmation (why!), and site ownership confirmation.
My favorite part? They point out security problems AND give actionable advice on how to fix them. That's useful.
- ZoFreX 14y agoCan you give examples of the sort of problems it found?
- cloudwalking 14y ago- Private IP address disclosure (1) - Allowed HTTP methods (1) - Non HTTP-Only Cookies (2) - Insecure Cookies (4) Note: This is a 2-page website. Looks like the cookie problems are a result of the default Heroku 404 page.
- tptacek 14y agoIt's good to have a fast check for these things, but you realize how simple that stuff is to spot, right? Insecure cookies and HTTPOnly (which: HTTPOnly is a bit of a band-aid; it's not a vulnerability not to have it) are trivial regexes on set-cookie headers; methods is something you can do with curl and a shell script. If you're spotting these kinds of things only after using a 3rd-party tool, consider whether this is the kind of stuff you want to build into your integration testing.
- borski 14y agoIn that vein, we search for a lot more than just these. We're actually working on some tools to help integrate Tinfoil into your integrating testing scheme - more to come on that in the future. :)
- tptacek 14y agoSorry! I know you do (for the benefit of the thread: I've been talking to 'borski for awhile about Tinfoil). I'm not commenting about Tinfoil so much as developers who are surprised to not be using secure cookies. :)