16
A false positive flood ruined our whole Friday sprint
Last Thursday our pipeline flagged 40+ API calls as SQLi, turned out it was our own load balancer throwing encoded params at a health check endpoint. Took our team till 4pm to whitelist the pattern and rerun the scans, wasted a full day of our release prep. Has anyone else had a scanner that screams louder at its own infra than at real threats?
1 comments
Log in to join the discussion
Log In1 Comment
phoenix_thompson425d ago
Man, that brings back a memory. We had a scanner once that kept flagging our own backup script because it had the word "drop" in a filename. Like "drop_old_logs.sh" and the thing went berserk thinking we were dropping a database. Took us two days to realize it was the filename causing it, not the actual content. I swear these tools have zero common sense sometimes. Ended up renaming everything to "remove_old_stuff" just to shut it up. Worst part was the security guy kept insisting we had a real breach until we literally showed him the script line by line.
8