Skip to content
  • About
  • Our Services
  • Our Methodology
    • Attacks & Tests
    • Testing modes
  • Blog

Contact us

Have a question or comment? Submit your message through our contact form and a member of our team will get back to you within 24 hours.

Edit Content

    Blog

    • Home
    • Blog
    • Page 2
    White Box Testing

    Firestore White Box Security Review Checklist

    February 7, 2023 Michael Yermakov No comments yet

    Introduction Securing your application’s Firestore database is crucial for protecting sensitive data and maintaining user trust. Google Firestore, a scalable NoSQL cloud database, offers robust features for real-time data management, but securing it against threats requires careful attention. This article is designed to help developers and security professionals assess and strengthen their Firestore implementations. A […]

    Black Box Testing, Hacking

    Firestore Database – Black Box Security Testing Guide –  Go Beyond *.firebaseio.com/.json

    October 9, 2022 Michael Yermakov No comments yet

    Incentives Firestore security is an important topic for modern applications. Its wide usage and serverless architecture may cause security issues in the areas such as authentication, authorization, and data exposure. Especially they are exposed to data leakages, which may be caused by a non-serveless design approach. In a world of multi-tier applications, using a backend […]

    Black Box Testing, Hacking

    A Guide For Advanced Message Protected API Hacking Using Hackvertor and Burp (Part #2)

    November 16, 2021 Michael Yermakov No comments yet

    More up-to-date Hackvertor game-changer techniques, code examples, and tips for advanced penetration testing and bug bounty. Intro Hackvertor is a Burp extension that programmatically extends Burp capabilities, by allowing you to embed neat code logic directly into HTTP requests sent/proxies by Burp and its extensions. Similar to Postman pre-request scripts. Here, I will try to […]

    Black Box Testing, Hacking

    Advanced Testing Of Web Application With Custom Message Signing Using Hackvertor (Part #1)

    December 7, 2020 Michael Yermakov No comments yet

    Introduction Many of us have probably been faced with testing an application with custom HTTP request authentication or message signing. The requests from these applications can be proxied but they have built-in replay protection mechanisms in some form. As such, it isn’t possible to resend these requests outside of the application therefore making all external […]

    Hacking

    Firebase Applications – The Untold Attack Surface

    September 14, 2020 AppSec Labs No comments yet

    Introduction In this blogpost, we will review some of the basic components of a Firebase application from a Security Perspective and talk about common issues that don’t get enough attention. What is Firebase? Firebase is a complete backend as a service with many different features that we can plug straight into our applications. For example: There […]

    Hacking

    Understanding the Android clearTextTrafficPermitted Flag

    June 15, 2020 AppSec Labs No comments yet

    Introduction The cleartextTrafficPermitted flag is one of the options in Android’s Network Security Configuration file. The online documentation (https://developer.android.com/training/articles/security-config) explains that from Android 9 (API level 28) and higher, it will be set by default to false and it is intended to prevent insecure communication attempts using clear-text HTTP originating from Android applications. OK, so what does this […]

    Hacking

    A Taxonomy on Brute Force Attacks

    May 8, 2017 AppSec Labs No comments yet

    A brute force attack is a well-known technique of trial and error attempts used by attackers to gain access to unauthorized data. It can be leveraged against servers as an online attack and also against files as a local attack. The common denominator of all these types is that the same pattern is almost always […]

    Posts pagination

    Previous 1 2

    Search

    Categories

    • Black Box Testing (5)
    • Brute Force (5)
    • Code Review (1)
    • Hacking (8)
    • White Box Testing (4)

    Recent posts

    • Beyond the Password: Advanced Authentication Testing Techniques for Modern Applications
    • Web Services Testing
      Web Services Testing: Safeguarding Your Web Applications Against XXE Attacks
    • Software Security Testing
      The Ultimate Guide to Securing Applications Through Software Security Testing

    AppSec Labs offer rapid, modern security penetration testing, utilizing smart solutions to protect against evolving cyber threats.

    Features
    • Home
    Resources
    • Blog
    Company
    • About us
    Get in touch
    • Guy Nachum (CRO):
    • guy@appsec-labs.com
    • +972 52-433-9393
    • Sales:
    • sales@appsec-labs.com
    • General Requests:
    • info@appsec-labs.com

    © AppSec Labs 2024. All Rights Reserved.

    • Terms & Conditions
    • Privacy Policy