<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: True Positives, LLC.</title>
    <description>The latest articles on DEV Community by True Positives, LLC. (@truepositives).</description>
    <link>https://dev.to/truepositives</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F7901%2F860cb0d4-56e0-4b4e-812e-088e9ed4625e.png</url>
      <title>DEV Community: True Positives, LLC.</title>
      <link>https://dev.to/truepositives</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/truepositives"/>
    <language>en</language>
    <item>
      <title>Clearing the Way for Proactive Code Security Testing</title>
      <dc:creator>Brian Pavicic</dc:creator>
      <pubDate>Wed, 22 Nov 2023 02:51:38 +0000</pubDate>
      <link>https://dev.to/truepositives/clearing-the-way-for-proactive-code-security-testing-21n</link>
      <guid>https://dev.to/truepositives/clearing-the-way-for-proactive-code-security-testing-21n</guid>
      <description>&lt;p&gt;To clients and the broader AppSec community, it is &lt;a href="https://www.true-positives.com"&gt;True Positive's&lt;/a&gt; mission to deliver precise and affordable software security testing solutions. &lt;/p&gt;

&lt;p&gt;One offering enormous potential benefits to the DEV community is the &lt;a href="https://www.ptk-plus.io/owasp-ptk"&gt;OWASP Penetration Testing ToolKit (aka PTK)&lt;/a&gt;, an &lt;strong&gt;open source tool made freely accessible&lt;/strong&gt; by T+. &lt;/p&gt;

&lt;p&gt;With PTK, you can unlock breakthrough browser-enabled security analysis to supercharge security testing to: &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Effortlessly discover potential security bugs.&lt;/li&gt;
&lt;li&gt;Go deeper to verify bugs and expose hidden threats.&lt;/li&gt;
&lt;li&gt;Inform remediation and test fixes.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;OWASP PTK: Key Capabilities &amp;amp; Features&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Insightful Information:&lt;/strong&gt; Get one-click access to insightful information about the target application, including its technology stack, Web Application Firewalls (WAFs), security headers, crawled links, and authentication flow.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;In-Browser Runtime Scanning:&lt;/strong&gt; PTK offers Dynamic Application Security Testing (DAST) and Software Composition Analysis (SCA) scanning within your browser. Detect SQL Injections, Command Line Injections, Stored and Reflected Cross-Site Scripting (XSS) vulnerabilities, and more. It even identifies complex threats like SQL Authentication Bypass, XPath injections, and JWT attacks.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Proxy with Traffic Log:&lt;/strong&gt; PTK includes a proxy with a detailed traffic log. This log allows you to repeat any request in the R-Builder or send it to the R-Attacker. You can automate the execution of Cross-Site Scripting (XSS), SQL injection, or OS Command injections.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Request Builder for Request Tampering:&lt;/strong&gt; The extension includes R-Builder, a powerful tool that allows you to craft and manipulate HTTP requests with precision. It empowers you to execute complex maneuvers, including HTTP request smuggling attacks, for a comprehensive assessment of application vulnerabilities.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Cookie Management:&lt;/strong&gt; PTK includes a cookie editor, allowing you to manage cookies efficiently. Add, edit, remove, block, protect, export, and easily import cookies.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Decoder/Encoder Utility:&lt;/strong&gt; The integrated utility helps you manage encoding and decoding from and to various formats, including UTF-8, Base64, MD5, and more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Swagger.IO Integration:&lt;/strong&gt; We've integrated Swagger.IO to enhance your understanding of API documentation. Easily create requests to interact with API endpoints.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Selenium Integration:&lt;/strong&gt; With Selenium integration, PTK aids in identifying security risks at the early stages of the development cycle, ensuring robust security from the outset.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Tool Roadmap&lt;/strong&gt;. &lt;strong&gt;Coming December 2023&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;JWT Inspector:&lt;/strong&gt; We've added a crucial new feature – JWT Inspector. It empowers you to analyze JSON Web Tokens (JWT), build new tokens using different algorithms (including None algorithm), and generate public and private keys for JWT signing.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.ptk-plus.io/owasp-ptk"&gt;Get the OWASP PTK open-source tool free here&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.ptk-plus.io"&gt;Explore the feature-enhanced edition, PTK Plus(PTK+) &lt;/a&gt;. &lt;/p&gt;

&lt;p&gt;Question? ](&lt;a href="mailto:ptk-support@ptk-plus.io"&gt;ptk-support@ptk-plus.io&lt;/a&gt;)&lt;/p&gt;

</description>
      <category>security</category>
      <category>opensource</category>
      <category>testing</category>
      <category>api</category>
    </item>
  </channel>
</rss>
