Are You Giving Out Cheat Codes if You Whitelist Pen Testers?
bishopfox.com | blog | #waf | #penetration-testing | #methodology | #scoping | #security-controls | #whitelisting
Summary
Brianne Hughes explains why whitelisting pen testers is a scoping decision driven by project goals rather than a cheat code, and when bypassing WAFs better simulates real attackers.
- Published
- Collected
Skip to content