17
Blew $150 on a fancy DAST scanner that missed everything
I bought this hyped cloud DAST tool called HackerGuardian Pro after their sales pitch at a conference in Austin. Spent a whole Saturday setting it up against our staging API and it only found 3 low severity XSS issues. Manual curl commands and Burp caught 14 real bugs including a broken auth bypass. Anyone else have a scanner that just made you feel dumb for paying?
2 comments
Log in to join the discussion
Log In2 Comments
kim6931mo ago
Burp is worth every penny. I wasted $200 on a "zero false positive" scanner last year. It missed a full SQL injection chain that was literally in the OWASP top 10. The sales demo was all cherry picked endpoints. Real codebases are messy. Your manual testing skills are way more valuable than some shiny dashboard.
8
kelly3851mo ago
Kim's exactly right about the demo trick. That HackerGuardian Pro demo had them running it against a perfect little Node.js app they built themselves. Real staging environments have legacy PHP endpoints, weird auth flows, and custom headers that confuse these tools. Manual Burp work found us a race condition in a password reset flow that no scanner would ever catch because it doesn't fit their pattern matching. Has your team had better luck with any tool for those weird custom endpoints?
6