Home / Blog
Field notes from the engagements
Blog
What we find, how it is exploited, and what actually fixes it. Written by the people who ran the test.
Hacking
A Taxonomy on Brute Force Attacks
A brute force attack is a well-known technique of trial and error attempts used by attackers to gain access to unauthorized data. It can be leveraged against servers…
Read itApplication Security
Password Autocomplete vulnerability and a workaround solution
Until recently, it was trivial for developers to disable the “save you password” feature implemented by all major browsers. However, in the last years, browser vendors have begun…
Read itApplication Security
Case study – Open Redirect
Most of us are familiar with the ‘Open Redirect’ vulnerability; an OWASP top 10 vulnerability that takes advantage of a situation in which the application receives a parameter…
Read itMobile Security
Android Emulator Tricks
When performing security (or regular) tests on Android applications, we sometimes need to emulate or fake mobile data or actions; making/receiving calls, sending SMS or setting the exact…
Read itMobile Security
iOS: “I just snapshotted your credit card… I did it for you!”
Does your application have a page containing sensitive data such as personal or business information? Credit card numbers? Any financial or legal information? You should be aware that…
Read itApplication Security
Resident XSS – Reflected Becomes Stored Thanks to HTML5
HTML5 is the newest version of the HTML. It offers new features that enhance support for creating web applications that can interact with the user and his/her local data…
Read itApplication Security
X-Frame-Option is dead, long live Content Security Policy!
Clickjacking, (A.K.A UI Redress attack) is an attack in which an attacker utilizes multiple transparent or opaque layers in order to trick a client into clicking on a button or…
Read itTell us what the system does and what worries you.
If a penetration test is not what you need yet, we will say so.