This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Trusting The Vulnerability Scanner: Danger of False Negative Sign
From OWASP
Description
This movie is to educate developers who put their entire trust on security/vulnerability scanners. False Negative means "Scanner says it doesn't find any X vulnerability". But there actually exists X vulnerability. Be sure to read "About Movie.txt" file.
Download:
http://yehg.net/lab/pr0js/files.php/trusting_the_vulnerability_scanner.zip