Skip to main content

Vulnerabilities and Observations

Vulnerabilities

Fuzzing Hero will report detected vulnerabilities with a title, description, technical concern, impact, severity, recommendations, steps to reproduce, and proof.

The output is structured in a familiar way to pentest reports.

Observations

The scan may detect notable behavior that is worth investigating. These are not vulnerabilities but may be indicative of issues with your application. This can include things like unexpected responses, unusually long response times, or other deviations from normal behavior.

Observations are structured similarly to vulnerabilities, however they don't have a severity. Simply put, we recommend that you work to fix vulnerabilities first and then investigate observations to see if your application is behaving as expected.

Fuzzing Hero uses observations as a starting point for behavioral issues. Something may not be able to be classified directly as an automated security vulnerability, but upon further inspection it may lead to discovering one.

Baselines​

A baseline is the expected behavior of a request. It is what we expect the request to return under normal conditions. The engine sends a baseline request to compare the baselines response against fuzzed responses. This can be used to dynamically test for patterns.

Proof​

Proof is a bundle of evidence that Fuzzing Hero gathered for either an issue or an observation. Proof typically consists of fuzzed HTTP requests and matching responses that demonstrate that a pattern was observed. Some proof may include non-HTTP data, such as evidence of an Out-of-band Interaction (OAST) request or DNS lookup.

Fuzzing Hero allows users to quickly compare proof requests and responses against the baselines to understand what was modified and how it effected the target application.