DEV Community

# appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
39 CVEs in WebGoat. Only 36 Were Reachable.

39 CVEs in WebGoat. Only 36 Were Reachable.

1
Comments
10 min read
Week 8 Challenge: Build an Anti-XSS Escape Encoding Framework in Python

Week 8 Challenge: Build an Anti-XSS Escape Encoding Framework in Python

1
Comments
9 min read
Reducing False Positives in XSS Detection: Designing Confirmation-Based Scanners

Reducing False Positives in XSS Detection: Designing Confirmation-Based Scanners

Comments
3 min read
Week 6 Quiz Audit XSS Vulnerabilities

Week 6 Quiz Audit XSS Vulnerabilities

1
Comments
17 min read
SAST vs DAST vs (IAST/RASP): Quick AppSec Checklist

SAST vs DAST vs (IAST/RASP): Quick AppSec Checklist

6
Comments 3
1 min read
Two "Medium" Findings That Chain Into Full Infrastructure Compromise

Two "Medium" Findings That Chain Into Full Infrastructure Compromise

Comments
4 min read
Architectural Asymmetry in Authentication: Part 2 — Risk Before Context

Architectural Asymmetry in Authentication: Part 2 — Risk Before Context

3
Comments
2 min read
What We Learned Securing a SaaS Product with Automated DAST

What We Learned Securing a SaaS Product with Automated DAST

3
Comments
5 min read
Week 6 Scripting Challenge: Build a TLS Certificate Security Validator

Week 6 Scripting Challenge: Build a TLS Certificate Security Validator

Comments
46 min read
How to Attack a RAG System — and Why Your Security Scanner Won't Catch It

How to Attack a RAG System — and Why Your Security Scanner Won't Catch It

Comments 1
6 min read
Week 7 Scripting Challenge: JWT Token Validation

Week 7 Scripting Challenge: JWT Token Validation

3
Comments
21 min read
Why Modern AppSec Needs Location-Aware Security Testing

Why Modern AppSec Needs Location-Aware Security Testing

Comments
4 min read
🧭 Dominando el OWASP Top 10 (Edición 2025): El Plano de Seguridad para la Próxima Generación

🧭 Dominando el OWASP Top 10 (Edición 2025): El Plano de Seguridad para la Próxima Generación

Comments
4 min read
Fundamentos de AppSec: Protegiendo el Corazón de tus Aplicaciones

Fundamentos de AppSec: Protegiendo el Corazón de tus Aplicaciones

Comments
4 min read
🔐 AppSec desde los Protocolos: Cómo HTTP, Cookies y CORS Definen tu Superficie de Ataque

🔐 AppSec desde los Protocolos: Cómo HTTP, Cookies y CORS Definen tu Superficie de Ataque

Comments
3 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.