ZAP审查的桌面应用程序代码

时间:2018-12-14 12:33:56

标签: zap

据我所知,ZAP可以用于.NET Web应用程序和服务测试,而不能用于桌面应用程序测试。如果我错了,请纠正我!!!因为我需要测试桌面应用程序。
在ZAP入门PDF中,它可以进行代码审查。因此,ZAP可能会对.NET桌面应用程序进行代码审查???如果是,那怎么可能? enter image description here 感谢进阶:)

1 个答案:

答案 0 :(得分:1)

您似乎还没有阅读完整的文本。 Code Review被列为一种安全测试...

Security testing is often broken out, somewhat arbitrarily, according to either the type of 
vulnerability being tested or the type of testing being done. A common breakout is:
• Vulnerability Assessment – The system is scanned and analyzed for security
issues.
• Penetration Testing – The system undergoes analysis and attack from simulated
malicious attackers.
• Runtime Testing – The system undergoes analysis and security testing from an enduser.
• Code Review – The system code undergoes a detailed review and analysis looking
specifically for security vulnerabilities.

然后,文档继续说明Penetration Testing是什么,以及ZAP如何用作Penetration Test的一部分。