慣性聚合 高效追讀感興趣之博客、新聞、科技資訊
閱原文 以慣性聚合開啟

推薦訂閱源

博客园 - 司徒正美
V
V2EX
T
Tailwind CSS Blog
有赞技术团队
有赞技术团队
aimingoo的专栏
aimingoo的专栏
Apple Machine Learning Research
Apple Machine Learning Research
IT之家
IT之家
Blog — PlanetScale
Blog — PlanetScale
A
About on SuperTechFans
月光博客
月光博客
T
The Blog of Author Tim Ferriss
宝玉的分享
宝玉的分享
Martin Fowler
Martin Fowler
博客园 - 聂微东
The GitHub Blog
The GitHub Blog
V
Visual Studio Blog
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
Engineering at Meta
Engineering at Meta
GbyAI
GbyAI

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python)
吾造一安全扫描器,未尝发之,终成其事
SecURL · 2026-05-24 · via DEV Community

吾昔筑SecURL于半载之前,每夕苦此:检网之安,或得玄言壁立,或仅验一端。securityheaders.com验首部,SSL Labs验TLS,Mozilla Observatory稍广。然无有能一阅而尽览,且序其当先之修也。

吾遂为之。SecURL观URL,察HTTP之安全首部,TLS之配置,DMARC,SPF,DKIM,DNSSEC,第三方脚本之显露,cookie之标志,重定向之链,以及诸般。其予尔A至F之等,依严重性排名,并附OWASP之参考。黏贴URL,约三十秒得报。

扫描器自体运转甚佳。引擎亦稳固。然此项目滞留于一种境地,盖诸多旁支项目所终至者:技术可行,实未尝付诸实施。无营销之姿,无计费之制,于用户体验之弊,虽知之,屡延之,文书之存,惟存于心。

此乃未改之貌。


始觉修饬之弊,在于所忽之 UX。或视域有异,页底忽现素隙。导览之栏,为分鐽之钮所夺,遂有截断之患。近扫之录,无论 A 或 F,皆以碧蓝同色书等第。版号之徽于英豪处,显尽内建之文——核本、建碼、应用之版——于我则善,于众则扰。

Copilot助我速成诸修补。此等变改,初知其要,然寻正元、察亲体、调布局之往复,得行间之微言,则不辍而流连,不须破势索检。白隙乃一CSS之属,既得其所。标签截断者,移分享之钮出柔列,置导航上独为div耳。细事零星,然今应用之致,顿显精工。

营销之域(securl.online)亦需修整。比较之表其尾言"主动查验",与全域之释相悖,谓SecURL惟作被动之察——公应之查,无侵扰之事。此句若为细读者所察,必损信任。


今者,SecURL已实启而不仅试行。

用户新體驗之弊已除,且已發行。有推特賬號(@thisissecurl),時有發文。有Dev.to之存跡。有Product Hunt之履歷。有合宜之用戶體驗審查清單,俾未來部署,先經結構化檢查,方得發行。

此扫描器之能,非尽数之自由工具所能及。其检 email 之可信记录甚详——非惟察 DMARC 是否存,更辨其策令或置于隔离或拒收,审 SPF 之限定是否过宽,察 DKIM 之选择器是否可寻。其能侦测会话重放之工具及分析商于第三方脚本之表。其绘重定向之链,标安危于每跳。此等品级之制,悉化繁为简,使非安之人得而应之。

欲试之者:app.securl.online。免费,无需账户,约需三十秒。尤愿闻诸君扫描所得,若以为误者——引擎尚在调校,真实之反馈实为有用。