WhisperX tag archive

#security-scanner

This page collects WhisperX intelligence signals tagged #security-scanner. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-01 11:27:20 · GitHub Issues

1. WAST RedirectScanner Hardcodes 'evil.com', Flooding Real Domain with Uncontrolled Traffic

The WAST security scanner's RedirectScanner module is hardcoded to send all its test traffic to the real, publicly registered domain 'evil.com'. This design flaw forces every scan to generate live DNS lookups and HTTP redirect attempts to a third-party host outside the project's control, creating an uncontrolled extern...