WEBINAR
Learn how tech company HeyJobs achieves a comprehensive AppSec testing program on a tight budget.
WEBINAR
Learn how tech company HeyJobs achieves a comprehensive AppSec testing program on a tight budget.

Pentester Guides (11)

How to Scope a Network Penetration Test: Tips from an Expert Pentester

During a network pentest engagement, time is of the essence. A penetration tester has a fixed amount of time, typically...
Oct 3, 2019
Est Read Time: 4 min

Is Your Serverless App Secure?

In the past few months, I’ve hosted several sessions on serverless security for serverless developers and DevOps folks....
Aug 6, 2019
Est Read Time: 4 min

How customer collaboration during a pentest can lead to finding a Remote Code Execution (RCE)

I was asked to share a blog post about a Remote Code Execution vulnerability that I identified in a past pentest....
Apr 9, 2019
Est Read Time: 2 min

From SSRF to Port Scanner

How to convert a SSRF vulnerability into a Port Scanner
Mar 18, 2019
Est Read Time: 4 min

.git — The Hidden Danger

Git is great versioning system that I am actively using while doing some development.
Dec 4, 2017
Est Read Time: 2 min

Kerberoast Attack Techniques

In this blog we will focus on Kerberoast attack techniques (Old Technique and New Technique).
Nov 1, 2017
Est Read Time: 5 min

Spear Phishing with Go Phish Framework

What is Spear Phishing?
Oct 17, 2017
Est Read Time: 5 min

UX-Friendly Enumeration Protection in Ruby on Rails

How to avoid revealing the existence of records to attackers in web applications, while keeping a good user experience...
May 23, 2017
Est Read Time: 4 min
    8 9 10 11 12