API Security
We Found an SSRF at a Client — What It Is, and Why It Matters
A short, practical explanation of Server-Side Request Forgery, prompted by a finding in one of our engagements.
Read itAPI Security
When the User Supplies the Regex: One Line That Took the API Down
An advanced search field let users filter with their own regular expression, passed straight into new Regex(userInput). One catastrophic-backtracking pattern locked every worker thread.
Read itAPI Security
Why Message Queues Keep Failing Their Penetration Test
Every microservice shared one credential with publish and subscribe on every channel. One foothold, one forged message, and a refund was issued - with no authorization at all.
Read itAPI Security
Rate Limiting: The Control Everyone Agrees On and Nobody Implements
A standard registration form with no limit on requests per minute. A bot fired tens of thousands, flooded the mail queue, and harvested hundreds of real usernames out…
Read itAPI Security
Web Services Testing: Safeguarding Your Web Applications Against XXE Attacks
As organizations increasingly rely on web services, particularly SOAP-based services, ensuring robust security through meticulous Web Services Testing has become critical. One common and significant vulnerability in these…
Read itTell us what the system does and what worries you.
If a penetration test is not what you need yet, we will say so.