🌟 Product Update: Changes made to DAST Exit Status and Default Configuration

In an ongoing effort to provide more insight into what is occurring during a Dynamic Analysis scan and augment performance, we are making modifications to scan exit statuses and default configurations.

 

Exit status change: Whenever the DAST scanner was unable to authenticate after 50 consecutive retries during a scan, it would exit with a status of KILLED. Feedback from the field noted that this was vague and didn't express what went wrong with the scan.

 

Starting today, that status will be replaced by LOCKOUT. This will communicate that the scanner has been locked out of the application and will be unable to continue until correct credentials are provided or network conditions allow a stable connection.

 

Default Configuration: During our work to make DAST scans more stable, we identified that the Brute Force attack setting was disproportionately correlated to scans ending prematurely. After further investigation, we have determined that this vulnerability is rarely found, and have made the decision to temporarily disable it by default until we have it performing reliably.

 


Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.