|
|
|
|
|
by dguido
4156 days ago
|
|
If you're planning on scanning all of your web apps at scale, you probably want to know what you can find and what you'll miss. As for competitors, I think there is WavSep but I'm not sure how suitable it is for Yahoo's use case (it looks like an overgrown J2EE app). People involved in that project infrequently rank scanners on their blog: * https://code.google.com/p/wavsep/ * http://sectooladdict.blogspot.ro/2014/02/wavsep-web-applicat... I have the feeling that the Yahoo bug bounties are about to get a whole lot harder to claim. |
|
Unfortunately, this will do nothing for the engineering hours being sunk into monitoring the thousands of invalid reports submitted each year.