据我所知,ZAP可以用于.NET Web应用程序和服务测试,而不能用于桌面应用程序测试。如果我错了,请纠正我!!!因为我需要测试桌面应用程序。
在ZAP入门PDF中,它可以进行代码审查。因此,ZAP可能会对.NET桌面应用程序进行代码审查???如果是,那怎么可能?
感谢进阶:)
答案 0 :(得分:1)
您似乎还没有阅读完整的文本。 Code Review
被列为一种安全测试...
Security testing is often broken out, somewhat arbitrarily, according to either the type of vulnerability being tested or the type of testing being done. A common breakout is: • Vulnerability Assessment – The system is scanned and analyzed for security issues. • Penetration Testing – The system undergoes analysis and attack from simulated malicious attackers. • Runtime Testing – The system undergoes analysis and security testing from an enduser. • Code Review – The system code undergoes a detailed review and analysis looking specifically for security vulnerabilities.
然后,文档继续说明Penetration Testing
是什么,以及ZAP如何用作Penetration Test
的一部分。