Loading...
Loading...
Compare original and translation side by side
../../shared/schemas/flags.md--scopechanged--depth standard--depth deep--severitylowcritical../../shared/schemas/flags.md--scopechanged--depth standard--depth deep--severitylowcritical../../shared/frameworks/owasp-top10-2021.md../../shared/frameworks/owasp-top10-2021.mdreferences/detection-patterns.mdreferences/detection-patterns.md../../shared/schemas/flags.md**/crypto/****/security/****/utils/encrypt***/auth/****/login/****/password***/.env***/config/****/settings***/models/****/ssl/****/tls/****/certs/**../../shared/schemas/flags.md**/crypto/****/security/****/utils/encrypt***/auth/****/login/****/password***/.env***/config/****/settings***/models/****/ssl/****/tls/****/certs/**../../shared/schemas/scanners.mdsemgrepbanditgosecgitleakstrufflehog../../shared/schemas/scanners.mdsemgrepbanditgosecgitleakstrufflehogsemgrep scan --config auto --json --quiet <target>gitleaks detect --source <target> --report-format json --report-path /dev/stdout --no-bannersemgrep scan --config auto --json --quiet <target>gitleaks detect --source <target> --report-format json --report-path /dev/stdout --no-banner--depth deep--depth deep../../shared/schemas/findings.mdCRYPTCRYPT-001CRYPT-002../../shared/schemas/findings.mdCRYPTCRYPT-001CRYPT-002references/detection-patterns.mdMath.random()rand()random.random()references/detection-patterns.mdMath.random()rand()random.random()| Scanner | Coverage | Command |
|---|---|---|
| semgrep | Weak crypto, hardcoded keys, insecure random | |
| bandit | Python crypto issues (MD5, DES, hardcoded passwords) | |
| gosec | Go crypto (weak TLS, hardcoded creds) | |
| gitleaks | Hardcoded keys and secrets | |
references/detection-patterns.mdconfidence: mediumpython.cryptography.security.insecure-hash-*python.cryptography.security.insecure-cipher-*javascript.crypto.security.weak-*java.crypto.security.weak-*generic.secrets.security.detected-*| 扫描器 | 覆盖范围 | 命令 |
|---|---|---|
| semgrep | 弱加密、硬编码密钥、不安全随机数 | |
| bandit | Python加密问题(MD5、DES、硬编码密码) | |
| gosec | Go加密问题(弱TLS、硬编码凭据) | |
| gitleaks | 硬编码密钥和机密信息 | |
references/detection-patterns.mdconfidence: mediumpython.cryptography.security.insecure-hash-*python.cryptography.security.insecure-cipher-*javascript.crypto.security.weak-*java.crypto.security.weak-*generic.secrets.security.detected-*../../shared/schemas/findings.mdCRYPTCRYPT-001cryptoowaspA02A02:2021ITMath.random()../../shared/schemas/findings.mdCRYPTCRYPT-001cryptoowaspA02A02:2021ITMath.random()