什么是业务逻辑漏洞,为什么它们如此难以捕获?
theori.io | 研究 | #ai-security | #cloud | #appsec | #sast | #vulnerability-detection | #business-logic | #code-analysis
摘要
业务逻辑漏洞执行「正常」却违背业务意图,例如重置口令 Token 直接出现在 HTTP 响应中;Xint 解释为何规则式 SAST 与人工测试都会漏掉这类缺陷。
- 发布时间
- 收录时间
Skip to content