A short, practical explanation of Server-Side Request Forgery, prompted by a finding in one of our engagements.
Why Message Queues Keep Failing Their Penetration Test
Every microservice shared one credential with publish and subscribe on every channel. One foothold, one forged message, and a refund was issued – with no authorization at all.
Rate Limiting: The Control Everyone Agrees On and Nobody Implements
A standard registration form with no limit on requests per minute. A bot fired tens of thousands, flooded the mail queue, and harvested hundreds of real usernames out of the API’s own answers.
Web Services Testing: Safeguarding Your Web Applications Against XXE Attacks
As organizations increasingly rely on web services, particularly SOAP-based services, ensuring robust security through meticulous Web Services Testing has become critical. One common and significant vulnerability in these services is XML External Entity (XXE) Injection. This guide will demonstrate how comprehensive Web Services Testing can identify and mitigate such risks. What is XML External Entity […]

