<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Appsec on IT Comparison</title><link>https://comparison.metacog.co.kr/tags/appsec/</link><description>Recent content in Appsec on IT Comparison</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 03 Aug 2026 04:32:55 +0900</lastBuildDate><atom:link href="https://comparison.metacog.co.kr/tags/appsec/index.xml" rel="self" type="application/rss+xml"/><item><title>Vulnerability vs Exploit: Weakness or Weapon</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-vulnerability-vs-exploit-weakness-or-weapon/</link><pubDate>Mon, 03 Aug 2026 04:32:55 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-vulnerability-vs-exploit-weakness-or-weapon/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;A vulnerability is a &lt;strong class="kw"&gt;flaw&lt;/strong&gt; in software, hardware, or configuration that could theoretically be abused, while an exploit is the actual &lt;strong class="kw"&gt;attack code&lt;/strong&gt; or technique that triggers that flaw to produce a specific outcome. The distinction matters because a system can carry thousands of vulnerabilities with no working exploit, while a single reliable exploit turns a theoretical risk into an active breach.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;rect x="60" y="70" width="200" height="220" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="2"/&gt;&lt;path d="M 160 70 L 145 130 L 175 160 L 150 200 L 170 240 L 155 290" style="stroke:var(--compare-a);fill:none" stroke-width="3"/&gt;&lt;text x="160" y="45" text-anchor="middle" style="fill:var(--compare-a)" font-size="20" font-weight="bold"&gt;Vulnerability&lt;/text&gt;&lt;text x="160" y="325" text-anchor="middle" style="fill:var(--secondary)" font-size="13"&gt;flaw in code / config&lt;/text&gt;&lt;text x="160" y="342" text-anchor="middle" style="fill:var(--secondary)" font-size="13"&gt;e.g. CWE-89, missing bounds check&lt;/text&gt;&lt;path d="M 275 180 L 400 180" style="stroke:var(--compare-b)" stroke-width="4"/&gt;&lt;polygon points="400,170 420,180 400,190" style="fill:var(--compare-b)"/&gt;&lt;text x="345" y="140" text-anchor="middle" style="fill:var(--compare-b)" font-size="20" font-weight="bold"&gt;Exploit&lt;/text&gt;&lt;text x="345" y="210" text-anchor="middle" style="fill:var(--secondary)" font-size="13"&gt;payload / PoC / technique&lt;/text&gt;&lt;text x="345" y="227" text-anchor="middle" style="fill:var(--secondary)" font-size="13"&gt;triggers the crack above&lt;/text&gt;&lt;rect x="430" y="70" width="150" height="220" rx="6" style="fill:none;stroke:var(--border)" stroke-width="2" stroke-dasharray="6,4"/&gt;&lt;text x="505" y="45" text-anchor="middle" style="fill:var(--primary)" font-size="16" font-weight="bold"&gt;Result&lt;/text&gt;&lt;text x="505" y="185" text-anchor="middle" style="fill:var(--content)" font-size="14"&gt;Compromise&lt;/text&gt;&lt;text x="505" y="205" text-anchor="middle" style="fill:var(--content)" font-size="14"&gt;(RCE, data leak,&lt;/text&gt;&lt;text x="505" y="225" text-anchor="middle" style="fill:var(--content)" font-size="14"&gt;privilege escalation)&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Vulnerability&lt;/th&gt;
&lt;th&gt;Exploit&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;What it is&lt;/td&gt;
&lt;td&gt;A latent flaw or weakness in design, code, or configuration&lt;/td&gt;
&lt;td&gt;A concrete piece of code, script, or technique that abuses a flaw&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Discovery method&lt;/td&gt;
&lt;td&gt;Found via code review, fuzzing, static/dynamic analysis, or audits&lt;/td&gt;
&lt;td&gt;Built by weaponizing a known vulnerability into a working trigger&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Prerequisite&lt;/td&gt;
&lt;td&gt;Requires nothing but the flaw&amp;rsquo;s existence in the system&lt;/td&gt;
&lt;td&gt;Requires an identified, reachable vulnerability to target&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lifecycle stage&lt;/td&gt;
&lt;td&gt;Introduced at design/coding time, persists until patched&lt;/td&gt;
&lt;td&gt;Created after a vulnerability is discovered, often much later&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Public tracking&lt;/td&gt;
&lt;td&gt;Cataloged with a CVE identifier and CWE weakness class&lt;/td&gt;
&lt;td&gt;Published as PoC code, Metasploit modules, or Exploit-DB entries&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Detection in the wild&lt;/td&gt;
&lt;td&gt;Identified by vulnerability scanners and SAST/DAST tools&lt;/td&gt;
&lt;td&gt;Identified by IDS/IPS signatures, EDR behavior, or WAF rules&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Mitigation&lt;/td&gt;
&lt;td&gt;Fixed by patching, input validation, or config hardening&lt;/td&gt;
&lt;td&gt;Blocked by runtime protections, signatures, or exploit mitigations (ASLR, DEP)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Risk measurement&lt;/td&gt;
&lt;td&gt;Scored theoretically via CVSS base/temporal metrics&lt;/td&gt;
&lt;td&gt;Measured by real-world impact and inclusion in CISA&amp;rsquo;s KEV list&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A vulnerability is a static &lt;strong class="kw"&gt;flaw&lt;/strong&gt;; an exploit is the active &lt;strong class="kw"&gt;trigger&lt;/strong&gt; that abuses it&lt;/li&gt;
&lt;li&gt;Vulnerabilities can sit &lt;strong class="kw"&gt;unexploited&lt;/strong&gt; for years; exploits require a working, reachable target&lt;/li&gt;
&lt;li&gt;Vulnerabilities are tracked by &lt;strong class="kw"&gt;CVE identifiers&lt;/strong&gt;; exploits circulate as &lt;strong class="kw"&gt;PoC code&lt;/strong&gt; or modules&lt;/li&gt;
&lt;li&gt;Patching closes the vulnerability; &lt;strong class="kw"&gt;runtime defenses&lt;/strong&gt; block the exploit itself&lt;/li&gt;
&lt;li&gt;CVSS scores the theoretical risk of a vulnerability; &lt;strong class="kw"&gt;KEV listing&lt;/strong&gt; confirms an exploit is used in the wild&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Vulnerability&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>CSRF vs XSS: Forged Requests or Injected Scripts</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-csrf-vs-xss-forged-requests-or-injected-scripts/</link><pubDate>Mon, 03 Aug 2026 04:27:16 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-csrf-vs-xss-forged-requests-or-injected-scripts/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;CSRF and XSS are both web attacks that abuse a victim&amp;rsquo;s trusted relationship with a site, but they exploit opposite ends of that trust. CSRF forges a request using the victim&amp;rsquo;s own &lt;strong class="kw"&gt;session cookie&lt;/strong&gt; without ever running attacker code in the browser, while XSS smuggles &lt;strong class="kw"&gt;injected script&lt;/strong&gt; into a vulnerable page so it executes directly inside the victim&amp;rsquo;s browser.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;text x="160" y="26" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--primary)"&gt;CSRF&lt;/text&gt;&lt;text x="480" y="26" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--primary)"&gt;XSS&lt;/text&gt;&lt;line x1="320" y1="40" x2="320" y2="345" style="stroke:var(--border)" stroke-width="1"/&gt;&lt;rect x="30" y="45" width="260" height="42" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="62" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Victim Browser&lt;/text&gt;&lt;text x="160" y="76" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;active session cookie&lt;/text&gt;&lt;rect x="30" y="112" width="260" height="42" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="129" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Attacker Site&lt;/text&gt;&lt;text x="160" y="143" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;forged auto-submit form&lt;/text&gt;&lt;rect x="30" y="179" width="260" height="42" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="196" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Target Server&lt;/text&gt;&lt;text x="160" y="210" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;e.g. bank / app backend&lt;/text&gt;&lt;rect x="30" y="246" width="260" height="42" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="263" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Action Executed&lt;/text&gt;&lt;text x="160" y="277" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;using victim's cookie&lt;/text&gt;&lt;line x1="160" y1="87" x2="160" y2="108" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;polygon points="154,104 166,104 160,113" style="fill:var(--compare-a)"/&gt;&lt;text x="200" y="100" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;visits page&lt;/text&gt;&lt;line x1="160" y1="154" x2="160" y2="175" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;polygon points="154,171 166,171 160,180" style="fill:var(--compare-a)"/&gt;&lt;text x="215" y="167" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;cookie auto-attached&lt;/text&gt;&lt;line x1="160" y1="221" x2="160" y2="242" style="stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;polygon points="154,238 166,238 160,247" style="fill:var(--compare-a)"/&gt;&lt;text x="205" y="234" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;no injected code&lt;/text&gt;&lt;rect x="350" y="45" width="260" height="42" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="62" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Vulnerable Site&lt;/text&gt;&lt;text x="480" y="76" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;renders unsanitized input&lt;/text&gt;&lt;rect x="350" y="112" width="260" height="42" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="129" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Injected &amp;lt;script&amp;gt;&lt;/text&gt;&lt;text x="480" y="143" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;runs in page's own origin&lt;/text&gt;&lt;rect x="350" y="179" width="260" height="42" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="196" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Victim Browser&lt;/text&gt;&lt;text x="480" y="210" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;executes attacker JS&lt;/text&gt;&lt;rect x="350" y="246" width="260" height="42" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="263" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Attacker Server&lt;/text&gt;&lt;text x="480" y="277" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;receives stolen data&lt;/text&gt;&lt;line x1="480" y1="87" x2="480" y2="108" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;polygon points="474,104 486,104 480,113" style="fill:var(--compare-b)"/&gt;&lt;text x="530" y="100" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;input reflected as code&lt;/text&gt;&lt;line x1="480" y1="154" x2="480" y2="175" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;polygon points="474,171 486,171 480,180" style="fill:var(--compare-b)"/&gt;&lt;text x="535" y="167" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;full DOM access&lt;/text&gt;&lt;line x1="480" y1="221" x2="480" y2="242" style="stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;polygon points="474,238 486,238 480,247" style="fill:var(--compare-b)"/&gt;&lt;text x="540" y="234" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;cookie exfiltrated&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;CSRF&lt;/th&gt;
&lt;th&gt;XSS&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Attack vector&lt;/td&gt;
&lt;td&gt;Forged cross-site request, e.g. an auto-submitting form or image tag on the attacker&amp;rsquo;s page that targets the victim site&lt;/td&gt;
&lt;td&gt;Malicious script injected into a vulnerable page&amp;rsquo;s HTML or JS output, often via unsanitized user input&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Trust exploited&lt;/td&gt;
&lt;td&gt;Server&amp;rsquo;s trust that any request carrying a valid session cookie came from the legitimate user&lt;/td&gt;
&lt;td&gt;Browser&amp;rsquo;s trust that all script served from the site&amp;rsquo;s origin is safe to execute&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Where the payload runs&lt;/td&gt;
&lt;td&gt;Nowhere on the victim&amp;rsquo;s browser beyond a normal HTTP request; the &amp;lsquo;payload&amp;rsquo; is the request itself&lt;/td&gt;
&lt;td&gt;Attacker&amp;rsquo;s JavaScript executes directly inside the victim&amp;rsquo;s browser, in the vulnerable site&amp;rsquo;s own origin&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Prerequisite for success&lt;/td&gt;
&lt;td&gt;Victim must have an active authenticated session with the target site when the forged request fires&lt;/td&gt;
&lt;td&gt;Vulnerable site must reflect, store, or render attacker-controlled input without proper sanitization or escaping&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Attacker capability&lt;/td&gt;
&lt;td&gt;Limited to whatever action the victim&amp;rsquo;s existing session is authorized to perform, like a transfer or settings change&lt;/td&gt;
&lt;td&gt;Broad: read cookies and localStorage, capture input, deface the page, or pivot into session hijacking&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Primary defense&lt;/td&gt;
&lt;td&gt;Anti-CSRF tokens, SameSite cookies, and origin or referer checks&lt;/td&gt;
&lt;td&gt;Output encoding, Content Security Policy, and strict input sanitization&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical impact scope&lt;/td&gt;
&lt;td&gt;A single forged action, bounded by what the target endpoint allows&lt;/td&gt;
&lt;td&gt;Potential full account takeover or persistent compromise if the injection is stored&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CSRF forges a request using the victim&amp;rsquo;s existing &lt;strong class="kw"&gt;session cookie&lt;/strong&gt;; XSS injects &lt;strong class="kw"&gt;attacker script&lt;/strong&gt; that runs inside the victim&amp;rsquo;s browser.&lt;/li&gt;
&lt;li&gt;CSRF requires no &lt;strong class="kw"&gt;code injection&lt;/strong&gt; into the target site, while XSS depends entirely on unsanitized input reaching the page.&lt;/li&gt;
&lt;li&gt;XSS can read and exfiltrate data straight from the DOM, whereas CSRF is limited to &lt;strong class="kw"&gt;blind requests&lt;/strong&gt; with no response visibility.&lt;/li&gt;
&lt;li&gt;&lt;strong class="kw"&gt;SameSite cookies&lt;/strong&gt; mitigate CSRF but do nothing against XSS, which is stopped primarily by &lt;strong class="kw"&gt;CSP&lt;/strong&gt; and output encoding.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;CSRF&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>SAST vs DAST: Static vs Dynamic Application Security Testing</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-sast-vs-dast-static-vs-dynamic-application-security-testing/</link><pubDate>Mon, 03 Aug 2026 04:19:31 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-sast-vs-dast-static-vs-dynamic-application-security-testing/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;SAST scans an application&amp;rsquo;s &lt;strong class="kw"&gt;source code&lt;/strong&gt; at rest to catch insecure patterns before the app ever runs, while DAST attacks a &lt;strong class="kw"&gt;running application&lt;/strong&gt; from the outside to find exploitable flaws in its live behavior. Teams use both because each catches vulnerability classes the other structurally cannot see.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;line x1="320" y1="20" x2="320" y2="340" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="4 4"/&gt;&lt;text x="150" y="40" text-anchor="middle" style="fill:var(--primary)" font-size="20" font-weight="bold"&gt;SAST&lt;/text&gt;&lt;text x="150" y="60" text-anchor="middle" style="fill:var(--secondary)" font-size="12"&gt;source code, no execution&lt;/text&gt;&lt;rect x="60" y="80" width="180" height="180" rx="6" style="fill:none;stroke:var(--border)" stroke-width="1.5"/&gt;&lt;text x="72" y="102" style="fill:var(--content)" font-size="11" font-family="monospace"&gt;function login(u,p) {&lt;/text&gt;&lt;text x="72" y="120" style="fill:var(--content)" font-size="11" font-family="monospace"&gt; const q =&lt;/text&gt;&lt;rect x="68" y="128" width="162" height="18" rx="3" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="72" y="141" style="fill:var(--content)" font-size="11" font-family="monospace"&gt; "SELECT..+p";&lt;/text&gt;&lt;text x="72" y="159" style="fill:var(--content)" font-size="11" font-family="monospace"&gt; db.exec(q);&lt;/text&gt;&lt;text x="72" y="177" style="fill:var(--content)" font-size="11" font-family="monospace"&gt;}&lt;/text&gt;&lt;circle cx="215" cy="137" r="16" style="fill:none;stroke:var(--compare-a)" stroke-width="2.5"/&gt;&lt;line x1="226" y1="148" x2="238" y2="160" style="stroke:var(--compare-a)" stroke-width="2.5" stroke-linecap="round"/&gt;&lt;text x="150" y="290" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;reads code, flags line 128&lt;/text&gt;&lt;text x="150" y="308" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;e.g. unsanitized SQL concat&lt;/text&gt;&lt;text x="490" y="40" text-anchor="middle" style="fill:var(--primary)" font-size="20" font-weight="bold"&gt;DAST&lt;/text&gt;&lt;text x="490" y="60" text-anchor="middle" style="fill:var(--secondary)" font-size="12"&gt;running app, black-box&lt;/text&gt;&lt;rect x="400" y="80" width="180" height="120" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="490" y="110" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;Live App&lt;/text&gt;&lt;text x="490" y="128" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;/login endpoint&lt;/text&gt;&lt;circle cx="490" cy="160" r="14" style="fill:none;stroke:var(--compare-b)" stroke-width="2"/&gt;&lt;path d="M484 160 L496 160 M490 154 L490 166" style="stroke:var(--compare-b)" stroke-width="2"/&gt;&lt;rect x="430" y="235" width="120" height="36" rx="5" style="fill:none;stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="490" y="258" text-anchor="middle" style="fill:var(--content)" font-size="10" font-family="monospace"&gt;POST u=' OR 1=1--&lt;/text&gt;&lt;path d="M490 205 L490 232" style="stroke:var(--compare-b)" stroke-width="1.5" marker-end="url(#arrow)"/&gt;&lt;path d="M460 235 Q 460 210 480 202" style="stroke:var(--compare-b);fill:none" stroke-width="1.5"/&gt;&lt;text x="490" y="300" text-anchor="middle" style="fill:var(--content)" font-size="12"&gt;sends live requests, observes response&lt;/text&gt;&lt;text x="490" y="318" text-anchor="middle" style="fill:var(--secondary)" font-size="11"&gt;e.g. auth bypass returned&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;SAST&lt;/th&gt;
&lt;th&gt;DAST&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;What it examines&lt;/td&gt;
&lt;td&gt;Source code, bytecode, or binaries at rest&lt;/td&gt;
&lt;td&gt;A running, deployed application from outside&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Access level&lt;/td&gt;
&lt;td&gt;White-box — full visibility into code internals&lt;/td&gt;
&lt;td&gt;Black-box — only sees inputs and outputs like an attacker&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;When in SDLC&lt;/td&gt;
&lt;td&gt;Early, during coding and in CI on every commit&lt;/td&gt;
&lt;td&gt;Later, once a build is deployed to a test or staging environment&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Environment needed&lt;/td&gt;
&lt;td&gt;None — analyzes files directly, no app needs to run&lt;/td&gt;
&lt;td&gt;A live, reachable instance of the application&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Vulnerability classes found&lt;/td&gt;
&lt;td&gt;Insecure code patterns: SQL string building, hardcoded secrets, unsafe deserialization&lt;/td&gt;
&lt;td&gt;Exploitable runtime behavior: auth bypass, injection responses, misconfigured headers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Language/stack dependency&lt;/td&gt;
&lt;td&gt;Tied to the language and framework being parsed&lt;/td&gt;
&lt;td&gt;Language-agnostic — probes over HTTP/HTTPS regardless of stack&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;False positive tendency&lt;/td&gt;
&lt;td&gt;Higher — flags patterns that may not be reachable or exploitable&lt;/td&gt;
&lt;td&gt;Lower — findings are confirmed by actual exploit attempts&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Remediation output&lt;/td&gt;
&lt;td&gt;Exact file and line number to fix&lt;/td&gt;
&lt;td&gt;Vulnerable URL, parameter, and request/response evidence&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SAST inspects &lt;strong class="kw"&gt;source code&lt;/strong&gt; without running it; DAST attacks a &lt;strong class="kw"&gt;live instance&lt;/strong&gt; without seeing its internals&lt;/li&gt;
&lt;li&gt;SAST fits early into &lt;strong class="kw"&gt;CI pipelines&lt;/strong&gt; per-commit; DAST needs a &lt;strong class="kw"&gt;deployed build&lt;/strong&gt; to test against&lt;/li&gt;
&lt;li&gt;SAST pinpoints the exact &lt;strong class="kw"&gt;line number&lt;/strong&gt;; DAST reports the vulnerable &lt;strong class="kw"&gt;endpoint&lt;/strong&gt; and payload&lt;/li&gt;
&lt;li&gt;SAST is prone to &lt;strong class="kw"&gt;false positives&lt;/strong&gt; from unreachable code paths; DAST confirms via &lt;strong class="kw"&gt;actual exploitation&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;SAST misses &lt;strong class="kw"&gt;runtime configuration&lt;/strong&gt; flaws that DAST catches, like missing security headers or session issues&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;SAST&lt;/strong&gt;&lt;/p&gt;</description></item></channel></rss>