14,953
edits
No edit summary |
m (→建議/可用) |
||
| Line 24: | Line 24: | ||
* 填寫個資申請: 不用 | * 填寫個資申請: 不用 | ||
[https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project OWASP Zed Attack Proxy Project] 掃描報告內容包含 Cross-site scripting (XSS), SQL Injection 等部分 OWASP 項目。報告內容有標示漏洞[https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAlerts 嚴重程度]。 | [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project OWASP Zed Attack Proxy Project] (ZAP) v. 2.7.0 掃描報告內容包含 Cross-site scripting (XSS), SQL Injection 等部分 OWASP 項目。報告內容有標示漏洞[https://github.com/zaproxy/zap-core-help/wiki/HelpStartConceptsAlerts 嚴重程度]。 | ||
* 公司/維護者: [https://www.owasp.org/index.php/Main_Page OWASP] | * 公司/維護者: [https://www.owasp.org/index.php/Main_Page OWASP] | ||
* 作業系統: {{Win}}, {{Linux}} & {{Mac}} | * 作業系統: {{Win}}, {{Linux}} & {{Mac}} | ||
* 授權: [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project Apache 2 License] | * 授權: [https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project Apache 2 License] | ||
* 試用版限制: | * 試用版限制: | ||
* 檔案掃毒: VirusTotal 掃描結果 [https:// | * 檔案掃毒: VirusTotal 掃描結果 [https://groups.google.com/forum/#!topic/zaproxy-develop/GT0_k6PkqjI Win 版] ok | ||
* 掃描對象: | * 掃描對象: | ||
* 掃描報告內容: 內容包含 X-Frame-Options header not set, Cross-Domain javascript source file inclusion, Cross-site scripting (XSS), SQL Injection, X-content-type-options header missing | * 掃描報告內容: 內容包含 X-Frame-Options header not set, Cross-Domain javascript source file inclusion, Cross-site scripting (XSS), SQL Injection, X-content-type-options header missing | ||