Subscribe to the full blog feed using RSS
CounterStrings are an underused technique. Primarily because there are not a lot of tools that implement it. In this blog post I explain how you can use them from within your browser, and as a bonus, using them to find a bug in Github.
Q: Which is easier, being a QA engineer or a software developer? I’m terrible at coding and I’m debating on switching to being a QA automation engineer.
I use a variety of screenshot tools in my work and for sharing the images, animated gifs, movies and pretty much any file, I use CloudApp.
I often talk about automating tactically and strategically. When we automate tactically we do what it takes to get the job done for us. When we automate strategically we build for the long term.
The same is true for programming tools. We can start small and tactical and scale strategically. In this example I create a Counterstring tool.
Q: What is the best fuzzer (automated software testing tool) to find 0-days? Why?
0-day is a very broad statement.
I tend to use the payload fuzzers in BurpSuite and OWasp Zap Proxy, but these require me to identify the target that I’m testing, and the appropriate data scope and range to fuzz.
When getting rid of a browser, what are the advantages of using taskkill.exe over close method in Selenium? Quora
Q: When getting rid of a browser, what are the advantages of using taskkill.exe over close method in Selenium?
I can’t really think of any advantages to using taskkill.exe over a
quit method in Selenium.
The drivers are often noisy, i.e. they write a lot to the logs. At first glance it might look like an error is being reported, it isn’t really.
I like to write little bots from the console to help with with application and game automation. But when the variables and objects I need are created from within anonymous functions I can’t get access. In this post I will explain how to access them.