DEV Community

#infosec

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Why CIDS Looks at Behavior, Not Just Individual Requests

Why CIDS Looks at Behavior, Not Just Individual Requests

Comments
3 min read
CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel

CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel

Comments
6 min read
Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Comments
5 min read
RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

Comments
6 min read
Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials

Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials

Comments
6 min read
JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

Comments
5 min read
Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Comments
5 min read
Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Comments
5 min read
SAML XSW: Signatures That Validate the Wrong Element

SAML XSW: Signatures That Validate the Wrong Element

Comments
5 min read
JWT Algorithm Negotiation Is a Spec Design Flaw, Not a Library Bug

JWT Algorithm Negotiation Is a Spec Design Flaw, Not a Library Bug

Comments
5 min read
CORS Misconfiguration in APIs: Why Reflected Origin Plus Credentials Is the Dangerous Pattern, Not Wildcard

CORS Misconfiguration in APIs: Why Reflected Origin Plus Credentials Is the Dangerous Pattern, Not Wildcard

Comments
6 min read
Wayback Machine for OSINT: What Stayed Archived After Remediation

Wayback Machine for OSINT: What Stayed Archived After Remediation

Comments
5 min read
API SSRF: Allowlists Fail Because They Validate the URL, Not the Resolved IP

API SSRF: Allowlists Fail Because They Validate the URL, Not the Resolved IP

Comments
6 min read
XXE in Document-Processing APIs: The Attack Surface Nobody Hardens

XXE in Document-Processing APIs: The Attack Surface Nobody Hardens

Comments
5 min read
Working: CORS misconfigurations escape automated detection

Working: CORS misconfigurations escape automated detection

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.