-
Updated
Nov 23, 2020 - Shell
auditing
Here are 188 public repositories matching this topic...
-
Updated
Oct 28, 2020 - Shell
-
Updated
Sep 12, 2018 - HTML
-
Updated
Apr 10, 2020 - Python
.well-known (RFC) is becoming an increasingly popular destination for stashing site-wide metadata. Some of that metadata is relevant to site security or may unintentionally leak information, so we should scan it.
Some starting points:
- Presence of/interesting things in an MTA-STS policy (RFC)
- This might be
WAF detection
-
Updated
Feb 20, 2020 - Go
-
Updated
Dec 2, 2020 - Go
-
Updated
Mar 24, 2020 - Shell
-
Updated
Nov 28, 2020 - Python
-
Updated
Sep 6, 2018 - Ruby
-
Updated
Dec 3, 2020 - Scala
-
Updated
Nov 30, 2020 - Python
-
Updated
Feb 8, 2020 - C
-
Updated
Jun 25, 2020 - Java
-
Updated
Jun 16, 2020 - C#
-
Updated
Nov 21, 2020 - Go
-
Updated
Mar 29, 2016 - PHP
-
Updated
Sep 11, 2020 - HTML
-
Updated
Dec 2, 2020 - Jupyter Notebook
-
Updated
Jul 26, 2019 - C#
The same way we have flags for avoiding indexing and scanning forks or repositories on personal namespaces, we should add one for ignoring repositories that are marked as private, in both GitLab and GitHub.
-
Updated
May 25, 2016 - Python
-
Updated
Dec 3, 2020 - Ruby
Improve this page
Add a description, image, and links to the auditing topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the auditing topic, visit your repo's landing page and select "manage topics."
Currently, facades implement good exception handling, but resource parsing does not. That means that for a given resource type, if parsing fails for any given resource, the
fetch_allmethod fails and stops, hence not parsing any additional resources.All resources should be reviewed and updated, to ensure they handle parsing errors.
e.g., for AWS IAM roles (https://github.com/nccgroup/Scou