You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<p>We are not aware of a definitive list of the vulnerabilities in AltoroJ.</p>
219
+
<p>Not too surprisingly you will need to configure the <ahref="/docs/desktop/addons/automation-framework/job-ascan/">activeScan</a> job, and you will probably want to generate a <ahref="/docs/desktop/addons/report-generation/automation/">report</a>.</p>
<li>The NoSQL Injection in the coupon validation functionality.</li>
284
284
<li>The SSRF in the contact mechanic functionality.</li>
285
285
</ul>
286
+
<p>Not too surprisingly you will need to configure the <ahref="/docs/desktop/addons/automation-framework/job-ascan/">activeScan</a> job, and you will probably want to generate a <ahref="/docs/desktop/addons/report-generation/automation/">report</a>.</p>
<p>Gin & Juice Shop has a well documented set of <ahref="https://ginandjuice.shop/vulnerabilities">vulnerabilities</a>.</p>
221
+
<p>Not too surprisingly you will need to configure the <ahref="/docs/desktop/addons/automation-framework/job-ascan/">activeScan</a> job, and you will probably want to generate a <ahref="/docs/desktop/addons/report-generation/automation/">report</a>.</p>
222
+
<p>Some of the Gin N Juice shop vulnerabilities can only be found using <ahref="/blog/2021-08-23-oast-with-owasp-zap/">OAST</a>. You will need to configure ZAP to use OAST as it is disabled by default,
223
+
due to the fact that it will send data to 3rd party services.</p>
<p>Although Juice Shop has lots of vulnerabilities, many of them can be very challenging for a DAST tool to identify.</p>
248
248
<p>The only significant vulnerability that we are aware of which ZAP should be able to identify but cannot is the DOM XSS vulnerability in the Search box.</p>
249
+
<p>Not too surprisingly you will need to configure the <ahref="/docs/desktop/addons/automation-framework/job-ascan/">activeScan</a> job, and you will probably want to generate a <ahref="/docs/desktop/addons/report-generation/automation/">report</a>.</p>
0 commit comments