Application security

OWASP Top 10 Deeper Dive - A8: Failure to Restrict URL Access

[highlight color="blue"]Interested in formal OWASP Top 10 Training? Check out our  OWASP Top 10 Training course OWASP Top 10 Training. [/highlight] Descripti

Web application testing with Arachni

What is Arachni? In very simple terms, Arachni is a tool that allows you to assess the security of web applications. [pkadzone zone="main_top"] [pka

OWASP Top 10 Deeper Dive – A5: Cross-Site Request Forgery (CSRF)

Description: Parsing the OWASP Top Ten with a closer look at Cross-Site Request Forgery (CSRF). No freely available or open source tools "automagically" discovers CSRF vulnerabilities; you have to step through the app as described above and test against locally installed vulnerable applications and devices unless you have explicit permission to test remote applications per an approved penetration testing engagement.

OWASP top 10 tools and tactics

A tool for each of the OWASP Top 10 to aid in discovering and remediating each of the Top Ten If you've spent any time defending web applications as a sec