Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

Introducing GitLab browser-based active checks in DAST

Blog post from GitLab

Post Details
Company
Date Published
Author
Cameron Swords
Word Count
1,075
Company Posts That Month
17
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab has introduced its first active check for browser-based dynamic application security testing (DAST), enhancing the tool's ability to detect path traversal vulnerabilities in modern web applications. This new feature, available in GitLab 16.4 or DAST 4.0.9, replaces the previous ZAP alerts with GitLab's own active checks, aiming to improve vulnerability detection for developers and security teams. Active checks involve a series of attacks on web applications to identify weaknesses, utilizing different techniques such as match response, timing, and callback attacks. Each attack injects specific payloads into HTTP requests, testing various injection locations like cookie values and query parameters, and uses the HTTP responses to assess the success of the attack. The GitLab active checks are automatically implemented during full scans, though users can opt out by modifying a CI/CD variable. The system prioritizes match response and timing attacks, written in YAML for quick updates, while callback attacks focus on detecting unauthorized data exposure.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.