✨Happening Now ✨@compaluca' presenting the #OWASP Testability Patterns for Webapps project at the @owasp@AppSecEU. Join us to learn more about testability patterns, and how you can use our framework to pick the right SAST tools!
https://t.co/ADbGbH3pP9
#testable_eu#appsec
The testability metric aims to estimate of how easy/hard is to detect vulnerabilities over a target application with respect to a certain class of testing techniques (e.g., SAST, DAST, …)
Super cool idea to check if malicious JS is running/injected on a web page, in particular when it’s opened from an app. Cc @Testable_EU. @KrauseFx, I would wrap the whole JS code in a IIFE to prevent malicious code to overwrite controls. 😉
Core to TESTABLE is a new testability metric to compute a more precise risk score, complementing existing vulnerability indicators (e.g., LoC, presence of security-sensitive function calls)
#testable_eu
Interested to detect security and privacy issues? Do you use/develop any static or dynamic testing tools? Do you work on testing tools to make your ML-based components more robust against adversarial attacks?
Keep an eye on TESTABLE! #testable_eu