Skip to main content

Best Practices

Authentication​

Make sure you've configured authentication for your scans. Granting access to the application allows for us to simulate traffic that real users and services could send to your application.

You can configure authentication for your scans by following the steps in the Configure Authentication task.

Populate Collections with Working Requests​

Does your application really expect values like "string" or "bool"? No, probably not. It expects real data. Ensure your collection requests are configured to provide valid examples. Fuzzing works best when starting with functional data and not boilerplate templates.

Use Fuzzing Hero to perform a health check before scanning to confirm that your endpoints all return valid statuses before scanning.

Allow Listing Security Controls​

Fuzzing is used to evaluate how the application behaves. When there is a WAF or other security controls in place, your application is getting an obfuscated view of security concerns. Real attackers will work to circumvent controls and spend time to evade detections.

We recommend allow listing the following Fuzzing Hero assets for the best results:

  • Fuzzing Hero's IP range: scanner.fuzzinghero.com,34.192.189.146
  • Fuzzing Hero's OAST domain: fh-oast.com

Leverage Directives and Validators​

Fuzzing Hero allows for you to bring your domain knowledge to the scanner.

  • Quickly define custom payloads to test issues specific to your organization
  • Curate response patterns to flag and report findings across all collections
  • Easily share directives and validators with your team

Dig Into the Results​

Remediate discovered vulnerabilites and rescan to confirm the fix. Review scan partitions and observations to gain a deeper understanding of how your application is behaving. Make changes if you notice unexpected behavior.

If you have access to the application logs, we highly recommend reviewing the logs with the scan activity. This can give you insights into errors, events, or findings that were surfaced as a result of the scan activity.

Manually Verify Non-Automated Endpoints​

For endpoints that create human-reviewed events, send emails, or otherwise cause tedious human actions, we recommend that you initially omit these from automated fuzzing. Manual testing with source-code review is best to minimize noise.

If you still need to fuzz these endpoints, we recommend the following:

  • Ensure testing is done in a non-production environment that can easily be wiped or cleanly restored after testing.
  • Consider tagging requests or data with a unique identifier, such as a header or parameter, that would make it easier to track and clean up.