
// technical blog
Technical blog
How the vulnerabilities we see most in our pentests actually work — and how to defend against them. Written by people who break applications for a living.
All articles
Security headers in practice: what each header protects and how to configure it
SSRF Bypasses: why each filter-evasion technique works
JWT, JWS, JWE, JWA and JWK: the difference between the JOSE acronyms
IDOR and Broken Access Control: how authorization breaks and how to lock it down
JWT vulnerabilities: alg none, algorithm confusion and weak secrets
SSTI: what Server-Side Template Injection is and how it becomes RCE
XSS, the definitive guide: reflected, stored, DOM-based and beyond
HTTP Request Smuggling: desyncing front-end and back-end
Web Cache Poisoning and Web Cache Deception: poisoning and tricking the cache
Race conditions in web apps: TOCTOU, limit-overrun and single-packet
Protecting web forms with CAPTCHA: what it solves and what it does not
User enumeration: when the form message reveals who has an account
SSRF: how Server-Side Request Forgery works and how to contain it
CSRF: how request forgery works and how to harden your forms
Clickjacking: how click hijacking works and how to defend against it
No articles match your search.

Need to go further?
We offer a complete white-label offensive security stack with Pentest, Scan and Social Engineering, delivered under your brand with specialist support.
Hire Intruder