9
My DAST scanner flagged our login page 40 times, turns out it was the honeypot
Spun up a fresh DAST run on our staging app last Tuesday morning, and it went haywire on the auth endpoint. 40 alerts in about 3 minutes, all pointing to some SQLi payload I didn't even write. After an hour of digging, I realized the scanner was hitting the fake login form our team built as a honeypot, not the real one. The tool did its job, just against a decoy we forgot to exclude from the scan scope. Has anyone else had a scanner chase a honeypot or test endpoint and waste a whole morning on false positives?
0 comments
Log in to join the discussion
Log In0 Comments
No comments yet
Be the first to share your thoughts on this discussion.