WEBINAR
Compliant vs. Secure: A CISO and CEO Discuss How to Manage Real-World Risk
WEBINAR
Compliant vs. Secure: A CISO and CEO Discuss How to Manage Real-World Risk

Busra Demir

Busra is a former Lead Cobalt Core Pentester with a passion for offensive security research, capture the flag exercises, and certifications. She has currently completed her OSCE, OSCP, and OSWP certifications.

Anatomy of the Session Management Tests

March 19, 2021
Est Read Time: 6 min
Note: This article has been created in light of the OWASP standards and descriptions.
Cobalt Core Pentester Guides

A Pentester’s Guide to File Inclusion

February 19, 2021
Est Read Time: 4 min
Read the Pentester’s Guide to File Inclusion for key insights into this common vulnerability.
Cobalt Core Pentester Guides

A Pentester’s Guide to WebSocket Pentesting

February 5, 2021
Est Read Time: 4 min
What is WebSocket Hijacking? As OWASP states, the HTTP protocol only allows one request/response per TCP connection....
Pentester Guides Web Application Pentesting

A Pentester’s Guide to Code Injection

January 8, 2021
Est Read Time: 3 min
Learn about code injection vulnerabilities with the Pentester’s Guide to Code Injection.
Cobalt Core Pentester Guides

A Pentester's Guide to Server Side Template Injection (SSTI)

December 24, 2020
Est Read Time: 3 min
Server-side template injection is a vulnerability where the attacker injects malicious input into a template to execute commands on the server-side.
Cobalt Core Pentester Guides

A Pentester’s Guide to Command Injection

December 11, 2020
Est Read Time: 3 min
Get expert insights with a command injection tutorial with insights from pentesting experts at Cobalt, a Pentest as a Service (PtaaS) provider.
Pentester Guides

How to Execute an XML External Entity Injection (XXE)

November 26, 2020
Est Read Time: 4 min
What's XXE? An XML External Entity vulnerability is a type of attack against an application that parses XML input. This...
Pentester Guides

A Pentester’s Guide to Cross-Site Request Forgery (CSRF)

November 13, 2020
Est Read Time: 4 min
Cross-Site Request Forgery (CSRF) is an attack that forces an end user to execute unwanted actions on a web application...
Pentester Guides

A Pentester’s Guide to Cross-Site Scripting (XSS)

October 30, 2020
Est Read Time: 8 min
Examine a common security vulnerability, Cross-Site Scripting (XSS).
Pentester Guides