Websecurify  / Blog
Research · Writing · Field notes
Websecurify — Blog

Research, techniques and field notes.

Writing from Websecurify on offensive security, tooling and the security of AI systems. 287 posts since 2008.

01
Latest — register of posts
P-287 → P-276
No.DateTitle
P-28714 Dec 2022Import Assets In Bulk

New feature released for SecApps Asset allows for bulk importing of multiple assets with a single operation. Import a list of asset names and associated types using the import dialog.

↗
P-28614 Dec 2022BountyPage Slack Integration

Websecurify is thrilled to announce full integration between BountyPage and Slack for improved messaging and notifications. This new feature allows for streamlining internal communications and ensures that team members are always informed about the status of bug bounty submissions. Sign up now to start using the Slack integration and improve your team's efficiency and transparency.

↗
P-28508 Nov 2022Launching BountyPage

BountyPage is an all-in-one platform that makes it easy to start and manage crowd-sourced vulnerability disclosure programs. It is an easy-to-use and accessible solution that enables you to launch a bug bounty program quickly and scale up over time.

↗
P-28407 Nov 2022Deprecating the Online Suite

This is an announcement of the deprecation of the SecApps Online Security testing suite.

↗
P-28305 Jun 2021Getting Started With Cohesion

Cohesion is a state of the art web application security testing toolkit designed to be scripted

↗
P-28205 Jun 2021Finding Secrets In Web Archives

In this tutorial we will show you a very simple technique on how to find secrets across many web pages

↗
P-28105 Jun 2021Finding Secrets In Travis CI

Quick tutorial how to find leaked API keys and credentials in TravisCI

↗
P-28005 Jun 20213rd-Party Due Diligence

To mitigate the exposure to 3rd-party risk, businesses must perform technical security due diligence.

↗
P-27928 Sept 2020GitHub Gist Recon

Finding github gists for security research and more.

↗
P-27815 Mar 2018Session Side Jacking

Implementing Firesheep 2.0 in AppBandit

↗
P-27714 Mar 2018How To Make a Password Cracker

Practical Bruteforce Attacks in Web Applications and Web Services

↗
P-27612 Mar 2018Fuzzing JSON Web Services

Simple guide how to fuzz JSON web services properly

↗