Application security

What is an XXE attack?

XXE (XML External Entity attack) is now increasingly being found and reported in major web applications such as Facebook, PayPal, etc. For instance, a quick

Top 10 solutions to protect against DDoS attacks and increase security

According to statistics, 33% of businesses fall victim to DDoS attacks. It is almost impossible to predict such attacks. Some of them can be powerful and rea

Layer Seven DDoS Attacks

What is Layer 7? The process of sending and receiving data from one host to another, data encapsulation, is possible due to the existence of a seven layer pr

2017 OWASP A8 Update: Insecure Deserialization

Introduction 2017 saw a new addition to the Open Web Application Security Project’s (OWASP) Top Ten list of web application vulnerabilities — insecure deseri

2017 OWASP A7 Update: Cross-Site Scripting

Introduction For the past 15 years, the Open Web Application Security Project (OWASP) has helped organizations develop, purchase, and maintain trusted applic

2017 OWASP A3 Update: Sensitive Data Exposure

Introduction Si vis pacem, para bellum! This classic Latin quote by Vegetius translates to "If you want peace, prepare for war." As far as aphorisms goes, th

2017 OWASP A10 update: Insufficient logging & monitoring

Many critics of the Open Web Application Security Project (OWASP) Top Ten list view insufficient logging and monitoring, new on the list in 2017, as more of

2017 OWASP A9 Update: Using Components With Known Vulnerabilities

Introduction It does not take a rocket scientist to understand using components with known vulnerabilities is a very poor choice. While solving this issue ma

2017 OWASP A6 Update: Security Misconfiguration

The Open Web Application Security Project (OWASP) is a volunteer group whose goal is to build a more robust Internet. One of their flagship publications is t

2017 OWASP A4 Update: XML External Entities (XXE)

Extensible Markup Language External Entities (XXE) is currently ranked fourth on OWASP’s 2017 Top Ten list of application security risks. Extensible Markup L