<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: sahil gupta</title>
    <description>The latest articles on DEV Community by sahil gupta (@sahil3112).</description>
    <link>https://dev.to/sahil3112</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F978689%2F02abafd7-54f0-4ec8-927b-28e9853e1404.jpeg</url>
      <title>DEV Community: sahil gupta</title>
      <link>https://dev.to/sahil3112</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/sahil3112"/>
    <language>en</language>
    <item>
      <title>🔥 LazyRecon: A Powerful Tool for Web Reconnaissance 🔥</title>
      <dc:creator>sahil gupta</dc:creator>
      <pubDate>Mon, 24 Apr 2023 13:30:00 +0000</pubDate>
      <link>https://dev.to/sahil3112/lazyrecon-a-powerful-tool-for-web-reconnaissance-4c5a</link>
      <guid>https://dev.to/sahil3112/lazyrecon-a-powerful-tool-for-web-reconnaissance-4c5a</guid>
      <description>&lt;p&gt;Today I am sharing a tool that I have been using for a while, which has helped me automate some tedious tasks of reconnaissance and information gathering of web applications. The tool is called LazyRecon, and it was developed by nahamsec, a well-known bug bounty hunter and security researcher.&lt;/p&gt;

&lt;p&gt;LazyRecon is a script that performs various subtasks such as subdomain enumeration, port scanning, and content discovery, and also grabs a screenshot of responsive hosts using different tools and techniques. It also generates interactive HTML report that you can use for further analysis or reporting. LazyRecon is fast and easy to use&lt;/p&gt;

&lt;p&gt;If you are interested in trying out LazyRecon, you can find it on &lt;a href="https://github.com/nahamsec/lazyrecon"&gt;GitHub link&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I hope you find this tool helpful. &lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--VX5ESxSh--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_66%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/noi8rp3gfql768v9g49d.gif" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--VX5ESxSh--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_66%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/noi8rp3gfql768v9g49d.gif" alt="Recon" width="800" height="513"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>security</category>
    </item>
    <item>
      <title>XML External Entity (XXE) Vulnerability - Part 3 (Local DTD Enumeration)</title>
      <dc:creator>sahil gupta</dc:creator>
      <pubDate>Thu, 22 Dec 2022 15:30:00 +0000</pubDate>
      <link>https://dev.to/sahil3112/xml-external-entity-xxe-vulnerability-part-3-local-dtd-enumeration-4jl6</link>
      <guid>https://dev.to/sahil3112/xml-external-entity-xxe-vulnerability-part-3-local-dtd-enumeration-4jl6</guid>
      <description>&lt;p&gt;Exploring how to enumerate local Document Type Definitions (DTDs) and exploit XML External Entity (XXE) vulnerabilities can be a great way to identify and exfiltrate sensitive files and data.&lt;/p&gt;


&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
      &lt;div class="c-embed__cover"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/12/xml-external-entity-xxe-part-3-local-dtd-enumeration.html" class="c-link s:max-w-50 align-middle" rel="noopener noreferrer"&gt;
          &lt;img alt="" src="https://res.cloudinary.com/practicaldev/image/fetch/s--J5PeDqXI--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKKYTjm3OiTthAsAvCWfQ3s5uOWEi3rr3Vd-yDW1MsHw-AnRhw5TSN_-O483eSWmoFhACheA6_K0RKx90h0yOlGKJ3czMf4czQoV5qc4KZi09kqYekMJyQAIBfAlSuVixJfi88mNRYUn9H5PSkAsOubkLmsIg79hPaTKA6vvBbge8hgcbcPxToj6NO5w/w1600/XML%2520External%2520Entity%2520%28XXE%29%2520-%2520Part%25203%2520%28Local%2520DTD%2520Enumeration%29%2520-%2520Header.webp" height="" class="m-0" width=""&gt;
        &lt;/a&gt;
      &lt;/div&gt;
    &lt;div class="c-embed__body"&gt;
      &lt;h2 class="fs-xl lh-tight"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/12/xml-external-entity-xxe-part-3-local-dtd-enumeration.html" rel="noopener noreferrer" class="c-link"&gt;
          XML External Entity (XXE) Vulnerability - Part 3 (Local DTD Enumeration)
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;p class="truncate-at-3"&gt;
          learn how to enumerate Local DTDs and exploit them to exfiltrate sensitive files and data
        &lt;/p&gt;
      &lt;div class="color-secondary fs-s flex items-center"&gt;
          &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://res.cloudinary.com/practicaldev/image/fetch/s--9kMCc23k--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogs.appsecworld.com/favicon.ico" width="16" height="16"&gt;
        blogs.appsecworld.com
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>webdev</category>
      <category>tutorial</category>
      <category>security</category>
      <category>xml</category>
    </item>
    <item>
      <title>Static Application Security Testing using SonarQube</title>
      <dc:creator>sahil gupta</dc:creator>
      <pubDate>Wed, 21 Dec 2022 15:30:00 +0000</pubDate>
      <link>https://dev.to/sahil3112/static-application-security-testing-using-sonarqube-1ie4</link>
      <guid>https://dev.to/sahil3112/static-application-security-testing-using-sonarqube-1ie4</guid>
      <description>&lt;p&gt;Learn how to use SonarQube to conduct Static Application Security Testing step-by-step, ensuring your codebase is secure and up-to-date with best practices.&lt;br&gt;
In this blog, I explained step by step process of how to set up SonarQube and conduct Static Application Security testing using SonarQube.&lt;br&gt;
&lt;/p&gt;
&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
      &lt;div class="c-embed__cover"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/12/static-application-security-testing-using-sonarqube.html" class="c-link s:max-w-50 align-middle" rel="noopener noreferrer"&gt;
          &lt;img alt="" src="https://res.cloudinary.com/practicaldev/image/fetch/s--xLKuNcE2--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitZUgKU2fbly1md-iV0IF46-Iycs05LDrMYBx6gJErELCrAMFotan_EnrPpZC7SDURI4m0W8_raD7uqmP31YEKcgtE1_ZXclYd7t5zJwbcTfCZyN3OHmH_cr85IEbYCct3qn-9Lyadwi6n5L0vY-7-s4lRdSESsbXQcnQBRKR1-hBrR08xqYX0NZvIxw/w1600/SAST.webp" height="" class="m-0" width=""&gt;
        &lt;/a&gt;
      &lt;/div&gt;
    &lt;div class="c-embed__body"&gt;
      &lt;h2 class="fs-xl lh-tight"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/12/static-application-security-testing-using-sonarqube.html" rel="noopener noreferrer" class="c-link"&gt;
          Static Application Security Testing using SonarQube
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;p class="truncate-at-3"&gt;
          set up SonarQube using docker and conduct Static Application Security testing using SonarQube
        &lt;/p&gt;
      &lt;div class="color-secondary fs-s flex items-center"&gt;
          &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://res.cloudinary.com/practicaldev/image/fetch/s--9kMCc23k--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogs.appsecworld.com/favicon.ico" width="16" height="16"&gt;
        blogs.appsecworld.com
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>webdev</category>
      <category>tutorial</category>
      <category>security</category>
      <category>testing</category>
    </item>
    <item>
      <title>XML External Entity (XXE) Vulnerability - Part 2 (XXE Basics)</title>
      <dc:creator>sahil gupta</dc:creator>
      <pubDate>Tue, 20 Dec 2022 15:57:00 +0000</pubDate>
      <link>https://dev.to/sahil3112/xml-external-entity-xxe-vulnerability-part-2-xxe-basics-23fd</link>
      <guid>https://dev.to/sahil3112/xml-external-entity-xxe-vulnerability-part-2-xxe-basics-23fd</guid>
      <description>&lt;p&gt;Learning the basics of XML External Entity (XXE) Vulnerability help to understand advanced concepts of XXE&lt;br&gt;
In the second part of the XXE vulnerability blog, I have explained the basic concept of XXE, like what XXE is and a basic example of XXE.&lt;br&gt;
&lt;/p&gt;
&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
      &lt;div class="c-embed__cover"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/12/xml-external-entity-xxe-part-2-xxe-basics.html" class="c-link s:max-w-50 align-middle" rel="noopener noreferrer"&gt;
          &lt;img alt="" src="https://res.cloudinary.com/practicaldev/image/fetch/s--_QXOcPHx--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHef8dcqZyO0upVwZ6g7TRykdkRZdoqOjzFequZIiKO_A7OEjeNrBcFYz7zsRoA5zF86Qy4AKtG47L50sN2GjbO_blt_Mb-UUR61yITN-gRocIFLb2juhrOrChLKnM-udNiuutQWBnbyjM2Rx6xY_dNXYHjHcZGVMFhCPV5xF2igb6IoOyJTAeJ__NvA/w1600/XML%2520External%2520Entity%2520%28XXE%29%2520-%2520Part%25202%2520%28XXE%2520Basics%29%2520-%2520Header.webp" height="" class="m-0" width=""&gt;
        &lt;/a&gt;
      &lt;/div&gt;
    &lt;div class="c-embed__body"&gt;
      &lt;h2 class="fs-xl lh-tight"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/12/xml-external-entity-xxe-part-2-xxe-basics.html" rel="noopener noreferrer" class="c-link"&gt;
          XML External Entity (XXE) Vulnerability - Part 2 (XXE Basics)
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;p class="truncate-at-3"&gt;
          learn about the basic concept of XXE, like what XXE is and a basic example of XXE
        &lt;/p&gt;
      &lt;div class="color-secondary fs-s flex items-center"&gt;
          &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://res.cloudinary.com/practicaldev/image/fetch/s--9kMCc23k--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogs.appsecworld.com/favicon.ico" width="16" height="16"&gt;
        blogs.appsecworld.com
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>webdev</category>
      <category>security</category>
      <category>tutorial</category>
      <category>xml</category>
    </item>
    <item>
      <title>XML External Entity (XXE) Vulnerability - Part 1 (XML Basics)</title>
      <dc:creator>sahil gupta</dc:creator>
      <pubDate>Mon, 19 Dec 2022 15:30:00 +0000</pubDate>
      <link>https://dev.to/sahil3112/xml-external-entity-xxe-vulnerability-part-1-xml-basics-1dk8</link>
      <guid>https://dev.to/sahil3112/xml-external-entity-xxe-vulnerability-part-1-xml-basics-1dk8</guid>
      <description>&lt;p&gt;XML External Entity (XXE) Vulnerability is an important security issue to understand. Knowing the basics of XML can help you identify and prevent potential risks associated with XXE attacks.&lt;br&gt;
In the first part of the XXE vulnerability blog, I have explained some basics concept of XML, like structure, DTD (Internal and External), and entity (Internal and External)&lt;/p&gt;


&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
      &lt;div class="c-embed__cover"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/12/xml-external-entity-xxe-part-1-xml-basics.html" class="c-link s:max-w-50 align-middle" rel="noopener noreferrer"&gt;
          &lt;img alt="" src="https://res.cloudinary.com/practicaldev/image/fetch/s--7isi9kDe--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgq4n0KmJrp-JCGdSwz3cdMSVmS2IjtoJK6sTA8ZIYy7bVXgNa2gtYTU0ZLORy6tbrlaihx0d69T7ALEj5sEowQaZuxzZlUnX8INo_qeb7jclOAgLPPveih64sqJ6QYH5nNHHg4_ApGM77AyYbWOHi6hPGhjrFLFRBOlMrD-EpVvTMkuPg-U4pjgUg5mg/w1600/xxe-1.webp" height="" class="m-0" width=""&gt;
        &lt;/a&gt;
      &lt;/div&gt;
    &lt;div class="c-embed__body"&gt;
      &lt;h2 class="fs-xl lh-tight"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/12/xml-external-entity-xxe-part-1-xml-basics.html" rel="noopener noreferrer" class="c-link"&gt;
          XML External Entity (XXE) Vulnerability - Part 1 (XML Basics)
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;p class="truncate-at-3"&gt;
          learn about some basics concept of XML, like structure, DTD (Internal and External), and entity (Internal and External)
        &lt;/p&gt;
      &lt;div class="color-secondary fs-s flex items-center"&gt;
          &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://res.cloudinary.com/practicaldev/image/fetch/s--9kMCc23k--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogs.appsecworld.com/favicon.ico" width="16" height="16"&gt;
        blogs.appsecworld.com
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>security</category>
      <category>webdev</category>
      <category>tutorial</category>
      <category>xml</category>
    </item>
    <item>
      <title>Vulnerability databases that we can use as part of software supply chain security</title>
      <dc:creator>sahil gupta</dc:creator>
      <pubDate>Wed, 07 Dec 2022 15:30:00 +0000</pubDate>
      <link>https://dev.to/sahil3112/vulnerability-databases-that-we-can-use-as-part-of-software-supply-chain-security-389m</link>
      <guid>https://dev.to/sahil3112/vulnerability-databases-that-we-can-use-as-part-of-software-supply-chain-security-389m</guid>
      <description>&lt;p&gt;Vulnerability databases play an important role in software supply chain security. Vulnerability databases contain information about known third-party components/libraries vulnerabilities. By leveraging multiple vulnerability databases, we can identify potential vulnerable third-party components used in software development and also remediate those issues quickly. &lt;/p&gt;

&lt;p&gt;Here is the list of free Vulnerability databases that we can use as part of software supply chain security.&lt;/p&gt;

&lt;p&gt;NVD (National Vulnerability Database): &lt;a href="https://nvd.nist.gov"&gt;https://nvd.nist.gov&lt;/a&gt;&lt;br&gt;
GitHub advisory: &lt;a href="https://github.com/advisories"&gt;https://github.com/advisories&lt;/a&gt;&lt;br&gt;
Google OSV: &lt;a href="https://osv.dev"&gt;https://osv.dev&lt;/a&gt;&lt;br&gt;
Snyk Vulnerability Database: &lt;a href="https://security.snyk.io"&gt;https://security.snyk.io&lt;/a&gt;&lt;br&gt;
SonaType OSS Index: &lt;a href="https://ossindex.sonatype.org"&gt;https://ossindex.sonatype.org&lt;/a&gt;&lt;/p&gt;


&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
      &lt;div class="c-embed__cover"&gt;
        &lt;a href="https://blogs.appsecworld.com/" class="c-link s:max-w-50 align-middle" rel="noopener noreferrer"&gt;
          &lt;img alt="" src="https://res.cloudinary.com/practicaldev/image/fetch/s--4w_R0iXw--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdT4sG6R8NRfhCCMmDt_DwcnxWoep6fnLXSAgeUOj19f0GFLljprDkTJTH-fuQetuTz5KxVjYei8eSX99Em_JUgssxzCh8mt2rH7WEnGm_5F9qnhA0-YZEjTxTqmkG900ONI1hgiXCcWrMrY1s4dnWgDs3zgVirhAsqaeO97Nn-ZOdsiPQZJiVrBp6xQ/w1600/OWASP%2520API%2520Security%2520Top%252010%2520%282%29.webp" height="" class="m-0" width=""&gt;
        &lt;/a&gt;
      &lt;/div&gt;
    &lt;div class="c-embed__body"&gt;
      &lt;h2 class="fs-xl lh-tight"&gt;
        &lt;a href="https://blogs.appsecworld.com/" rel="noopener noreferrer" class="c-link"&gt;
          Free Learning Resources for Application Security and Penetration Testing 
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;p class="truncate-at-3"&gt;
          Learning portal for Application Security and DevSecOps Engineers. It contains well-written and in-depth articles on Software Security and DevSecOps
        &lt;/p&gt;
      &lt;div class="color-secondary fs-s flex items-center"&gt;
          &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://res.cloudinary.com/practicaldev/image/fetch/s--9kMCc23k--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogs.appsecworld.com/favicon.ico" width="16" height="16"&gt;
        blogs.appsecworld.com
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>security</category>
      <category>devops</category>
    </item>
    <item>
      <title>Plugins that allow you to automate the Authentication and Authorization Security Testin</title>
      <dc:creator>sahil gupta</dc:creator>
      <pubDate>Tue, 06 Dec 2022 15:30:00 +0000</pubDate>
      <link>https://dev.to/sahil3112/plugins-that-allow-you-to-automate-the-authentication-and-authorization-security-testin-3pep</link>
      <guid>https://dev.to/sahil3112/plugins-that-allow-you-to-automate-the-authentication-and-authorization-security-testin-3pep</guid>
      <description>&lt;p&gt;Authentication and Authorization security testing is an Important Test Case for any web application penetration testing. Authentication ensures that only authorized users can access the application functionality and its resources, while authorization ensures that users are only granted access to the resources and functions that are appropriate for their level of authorization.&lt;/p&gt;

&lt;p&gt;Here are the Plugins that allow you to automate the Authentication and Authorization Security Testing.&lt;/p&gt;

&lt;p&gt;Autorize (For Burp Suite): &lt;/p&gt;
&lt;div class="ltag-github-readme-tag"&gt;
  &lt;div class="readme-overview"&gt;
    &lt;h2&gt;
      &lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--566lAguM--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://dev.to/assets/github-logo-5a155e1f9a670af7944dd5e12375bc76ed542ea80224905ecaf878b9157cdefc.svg" alt="GitHub logo"&gt;
      &lt;a href="https://github.com/Quitten"&gt;
        Quitten
      &lt;/a&gt; / &lt;a href="https://github.com/Quitten/Autorize"&gt;
        Autorize
      &lt;/a&gt;
    &lt;/h2&gt;
    &lt;h3&gt;
      Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
    &lt;/h3&gt;
  &lt;/div&gt;
  &lt;div class="ltag-github-body"&gt;
    
&lt;div id="readme" class="md"&gt;
&lt;h1&gt;
Autorize&lt;/h1&gt;
&lt;p&gt;Autorize is an automatic authorization enforcement detection extension for Burp Suite. It was written in Python by Barak Tawily, an application security expert. Autorize was designed to help security testers by performing automatic authorization tests. With the last release now Autorize also perform automatic authentication tests.&lt;/p&gt;
&lt;p&gt;&lt;a rel="noopener noreferrer nofollow" href="https://raw.githubusercontent.com/Quitten/Autorize/master/Autorizev1.3.png"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--uYCedjC9--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://raw.githubusercontent.com/Quitten/Autorize/master/Autorizev1.3.png" alt="alt tag"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h1&gt;
Installation&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;Download Burp Suite (obviously): &lt;a href="http://portswigger.net/burp/download.html" rel="nofollow"&gt;http://portswigger.net/burp/download.html&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Download Jython standalone JAR: &lt;a href="http://www.jython.org/download.html" rel="nofollow"&gt;http://www.jython.org/download.html&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Open burp -&amp;gt; Extender -&amp;gt; Options -&amp;gt; Python Environment -&amp;gt; Select File -&amp;gt; Choose the Jython standalone JAR&lt;/li&gt;
&lt;li&gt;Install Autorize from the BApp Store or follow these steps:&lt;/li&gt;
&lt;li&gt;Download the Autorize.py file.&lt;/li&gt;
&lt;li&gt;Open Burp -&amp;gt; Extender -&amp;gt; Extensions -&amp;gt; Add -&amp;gt; Choose Autorize.py file.&lt;/li&gt;
&lt;li&gt;See the Autorize tab and enjoy automatic authorization detection :)&lt;/li&gt;
&lt;/ol&gt;
&lt;h1&gt;
User Guide - How to use?&lt;/h1&gt;
&lt;ol&gt;
&lt;li&gt;After installation, the Autorize tab will be added to Burp.&lt;/li&gt;
&lt;li&gt;Open the configuration tab (Autorize -&amp;gt; Configuration).&lt;/li&gt;
&lt;li&gt;Get your low-privileged user authorization token header (Cookie / Authorization) and copy it into the…&lt;/li&gt;
&lt;/ol&gt;
&lt;/div&gt;
  &lt;/div&gt;
  &lt;div class="gh-btn-container"&gt;&lt;a class="gh-btn" href="https://github.com/Quitten/Autorize"&gt;View on GitHub&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;br&gt;
Access Control Testing add-on (For OWASP ZAP): &lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
    &lt;a href="https://www.zaproxy.org/docs/desktop/addons/access-control-testing/" rel="noopener noreferrer"&gt;
      zaproxy.org
    &lt;/a&gt;
&lt;/div&gt;



&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
      &lt;div class="c-embed__cover"&gt;
        &lt;a href="https://blogs.appsecworld.com/" class="c-link s:max-w-50 align-middle" rel="noopener noreferrer"&gt;
          &lt;img alt="" src="https://res.cloudinary.com/practicaldev/image/fetch/s--4w_R0iXw--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdT4sG6R8NRfhCCMmDt_DwcnxWoep6fnLXSAgeUOj19f0GFLljprDkTJTH-fuQetuTz5KxVjYei8eSX99Em_JUgssxzCh8mt2rH7WEnGm_5F9qnhA0-YZEjTxTqmkG900ONI1hgiXCcWrMrY1s4dnWgDs3zgVirhAsqaeO97Nn-ZOdsiPQZJiVrBp6xQ/w1600/OWASP%2520API%2520Security%2520Top%252010%2520%282%29.webp" height="" class="m-0" width=""&gt;
        &lt;/a&gt;
      &lt;/div&gt;
    &lt;div class="c-embed__body"&gt;
      &lt;h2 class="fs-xl lh-tight"&gt;
        &lt;a href="https://blogs.appsecworld.com/" rel="noopener noreferrer" class="c-link"&gt;
          Free Learning Resources for Application Security and Penetration Testing 
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;p class="truncate-at-3"&gt;
          Learning portal for Application Security and DevSecOps Engineers. It contains well-written and in-depth articles on Software Security and DevSecOps
        &lt;/p&gt;
      &lt;div class="color-secondary fs-s flex items-center"&gt;
          &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://res.cloudinary.com/practicaldev/image/fetch/s--9kMCc23k--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogs.appsecworld.com/favicon.ico" width="16" height="16"&gt;
        blogs.appsecworld.com
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>security</category>
      <category>webdev</category>
    </item>
    <item>
      <title>OWASP API Security Top 10 API6:2019 Mass Assignment with Example</title>
      <dc:creator>sahil gupta</dc:creator>
      <pubDate>Fri, 02 Dec 2022 15:30:00 +0000</pubDate>
      <link>https://dev.to/sahil3112/owasp-api-security-top-10-api62019-mass-assignment-with-example-511j</link>
      <guid>https://dev.to/sahil3112/owasp-api-security-top-10-api62019-mass-assignment-with-example-511j</guid>
      <description>&lt;p&gt;Mass Assignment vulnerability leads to an attack that occurs when an attacker is able to send data to an API that is then used to automatically populate multiple fields in the system. This can be used to bypass security controls, change data, or perform other malicious actions.&lt;/p&gt;

&lt;p&gt;In this blog, I have explained about the OWASP API Security Top 10 API6:2019 Mass Assignment with Example.&lt;/p&gt;


&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
      &lt;div class="c-embed__cover"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/11/owasp-api-security-top-10-api6-2019-mass-Assignment.html" class="c-link s:max-w-50 align-middle" rel="noopener noreferrer"&gt;
          &lt;img alt="" src="https://res.cloudinary.com/practicaldev/image/fetch/s--4w_R0iXw--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdT4sG6R8NRfhCCMmDt_DwcnxWoep6fnLXSAgeUOj19f0GFLljprDkTJTH-fuQetuTz5KxVjYei8eSX99Em_JUgssxzCh8mt2rH7WEnGm_5F9qnhA0-YZEjTxTqmkG900ONI1hgiXCcWrMrY1s4dnWgDs3zgVirhAsqaeO97Nn-ZOdsiPQZJiVrBp6xQ/w1600/OWASP%2520API%2520Security%2520Top%252010%2520%282%29.webp" height="" class="m-0" width=""&gt;
        &lt;/a&gt;
      &lt;/div&gt;
    &lt;div class="c-embed__body"&gt;
      &lt;h2 class="fs-xl lh-tight"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/11/owasp-api-security-top-10-api6-2019-mass-Assignment.html" rel="noopener noreferrer" class="c-link"&gt;
          OWASP API Security Top 10 API6:2019 Mass Assignment with Example
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;p class="truncate-at-3"&gt;
          learn about the OWASP API Security Top 10 API6:2019 Mass Assignment, its impact, an example, and remediation.
        &lt;/p&gt;
      &lt;div class="color-secondary fs-s flex items-center"&gt;
          &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://res.cloudinary.com/practicaldev/image/fetch/s--9kMCc23k--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogs.appsecworld.com/favicon.ico" width="16" height="16"&gt;
        blogs.appsecworld.com
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>security</category>
      <category>api</category>
      <category>webdev</category>
      <category>opensource</category>
    </item>
    <item>
      <title>Cloud Storage Security</title>
      <dc:creator>sahil gupta</dc:creator>
      <pubDate>Thu, 01 Dec 2022 15:30:00 +0000</pubDate>
      <link>https://dev.to/sahil3112/cloud-storage-security-aib</link>
      <guid>https://dev.to/sahil3112/cloud-storage-security-aib</guid>
      <description>&lt;p&gt;Organizations heavily use Cloud storage to store sensitive data. However, if access control settings are not properly configured or the storage key is leaked, then data may be exposed to unauthorized individuals. &lt;br&gt;
This could lead to the leakage of sensitive data, data being tampered with, or unauthorized access to cloud storage systems.&lt;/p&gt;

&lt;p&gt;Here are the tools to identify cloud buckets URLs and Storage Keys in Web Application responses &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Burp-AnonymousCloud:&lt;/strong&gt; Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities.&lt;br&gt;
(&lt;a href="https://github.com/portswigger/anonymous-cloud"&gt;https://github.com/portswigger/anonymous-cloud&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Cloud Storage Tester:&lt;/strong&gt; This extension can identify and test S3 buckets as well as Google Storage buckets and Azure Storage containers for common misconfiguration issues.&lt;br&gt;
(&lt;a href="https://portswigger.net/bappstore/04adbe101f544c88b2497a9a25ffaab4"&gt;https://portswigger.net/bappstore/04adbe101f544c88b2497a9a25ffaab4&lt;/a&gt;)&lt;/p&gt;


&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
      &lt;div class="c-embed__cover"&gt;
        &lt;a href="https://blogs.appsecworld.com/" class="c-link s:max-w-50 align-middle" rel="noopener noreferrer"&gt;
          &lt;img alt="" src="https://res.cloudinary.com/practicaldev/image/fetch/s--4w_R0iXw--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdT4sG6R8NRfhCCMmDt_DwcnxWoep6fnLXSAgeUOj19f0GFLljprDkTJTH-fuQetuTz5KxVjYei8eSX99Em_JUgssxzCh8mt2rH7WEnGm_5F9qnhA0-YZEjTxTqmkG900ONI1hgiXCcWrMrY1s4dnWgDs3zgVirhAsqaeO97Nn-ZOdsiPQZJiVrBp6xQ/w1600/OWASP%2520API%2520Security%2520Top%252010%2520%282%29.webp" height="" class="m-0" width=""&gt;
        &lt;/a&gt;
      &lt;/div&gt;
    &lt;div class="c-embed__body"&gt;
      &lt;h2 class="fs-xl lh-tight"&gt;
        &lt;a href="https://blogs.appsecworld.com/" rel="noopener noreferrer" class="c-link"&gt;
          Free Learning Resources for Application Security and Penetration Testing 
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;p class="truncate-at-3"&gt;
          Learning portal for Application Security and DevSecOps Engineers. It contains well-written and in-depth articles on Software Security and DevSecOps
        &lt;/p&gt;
      &lt;div class="color-secondary fs-s flex items-center"&gt;
          &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://res.cloudinary.com/practicaldev/image/fetch/s--9kMCc23k--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogs.appsecworld.com/favicon.ico" width="16" height="16"&gt;
        blogs.appsecworld.com
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>security</category>
      <category>webdev</category>
      <category>cloud</category>
      <category>aws</category>
    </item>
    <item>
      <title>OWASP API Security Top 10 API5:2019 Broken Function Level Authorization with an Example</title>
      <dc:creator>sahil gupta</dc:creator>
      <pubDate>Wed, 30 Nov 2022 15:30:00 +0000</pubDate>
      <link>https://dev.to/sahil3112/owasp-api-security-top-10-api52019-broken-function-level-authorization-with-an-example-i3c</link>
      <guid>https://dev.to/sahil3112/owasp-api-security-top-10-api52019-broken-function-level-authorization-with-an-example-i3c</guid>
      <description>&lt;p&gt;A flaw in the design or implementation of an API that allows a user to bypass intended access controls, such as authentication or authorization checks. This can occur when the API does not properly enforce the intended security controls or when it fails to properly check the user's permissions before allowing them to access the API&lt;/p&gt;

&lt;p&gt;In this blog, I have explained about the OWASP API Security Top 10 API5:2019 Broken Function Level Authorization with an Example.&lt;/p&gt;


&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
      &lt;div class="c-embed__cover"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/11/owasp-api-security-top-10-api5-2019-broken-function-level-authorization.html" class="c-link s:max-w-50 align-middle" rel="noopener noreferrer"&gt;
          &lt;img alt="" src="https://res.cloudinary.com/practicaldev/image/fetch/s--Qlng57TJ--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgdMPwGC0eIGlg2Xhm8qvePHW5dsdOVMora6-VCTVQ8Mm0Vgdivx-Pd7PHKbPiG6AAs-PzSzh7migE4GvRpfitRyqPh0kx369sqSmTTe_-T5uRT-ywcppLmqWHEr3LUPLHU9alw44kuWxtgw_hYNv5E7nhs3uN0OBFs09G1GCplGmzqL5v8EewhrtFqzA/w1600/OWASP%2520API%2520Security%2520Top%252010%2520%281%29.webp" height="" class="m-0" width=""&gt;
        &lt;/a&gt;
      &lt;/div&gt;
    &lt;div class="c-embed__body"&gt;
      &lt;h2 class="fs-xl lh-tight"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/11/owasp-api-security-top-10-api5-2019-broken-function-level-authorization.html" rel="noopener noreferrer" class="c-link"&gt;
          OWASP API Security Top 10 API5:2019 Broken Function Level Authorization with Example
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;p class="truncate-at-3"&gt;
          learn about the OWASP API Security Top 10 API5:2019 Broken Function Level Authorization, its impact, an example, and remediation.
        &lt;/p&gt;
      &lt;div class="color-secondary fs-s flex items-center"&gt;
          &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://res.cloudinary.com/practicaldev/image/fetch/s--9kMCc23k--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogs.appsecworld.com/favicon.ico" width="16" height="16"&gt;
        blogs.appsecworld.com
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>webdev</category>
      <category>security</category>
      <category>opensource</category>
      <category>api</category>
    </item>
    <item>
      <title>Content Security Policy (CSP)</title>
      <dc:creator>sahil gupta</dc:creator>
      <pubDate>Tue, 29 Nov 2022 15:30:00 +0000</pubDate>
      <link>https://dev.to/sahil3112/content-security-policy-csp-4bpg</link>
      <guid>https://dev.to/sahil3112/content-security-policy-csp-4bpg</guid>
      <description>&lt;p&gt;Content Security Policy (CSP) is a security measure that can be implemented through a Content-Security-Policy response header or equivalent  element. It allows developers to restrict the sources from which resources, such as JavaScript, CSS, images, files, etc., are loaded. CSP can be an effective defense against some types of attacks, such as cross-site scripting (XSS) and Clickjacking.&lt;/p&gt;

&lt;p&gt;Here are the tools that can help you to audit and generate CSP&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CSP-evaluator:&lt;/strong&gt; &lt;a href="https://csp-evaluator.withgoogle.com/"&gt;https://csp-evaluator.withgoogle.com/&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;CSP Auditor:&lt;/strong&gt; &lt;a href="https://portswigger.net/bappstore/35237408a06043e9945a11016fcbac18"&gt;https://portswigger.net/bappstore/35237408a06043e9945a11016fcbac18&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;Content Security Policy (CSP) Generator Chrome extension:&lt;/strong&gt; &lt;a href="https://chrome.google.com/webstore/detail/content-security-policy-c/ahlnecfloencbkpfnpljbojmjkfgnmdc"&gt;https://chrome.google.com/webstore/detail/content-security-policy-c/ahlnecfloencbkpfnpljbojmjkfgnmdc&lt;/a&gt; &lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Content Security Policy (CSP) Generator Firefox extension:&lt;/strong&gt; &lt;a href="https://addons.mozilla.org/en-US/firefox/addon/csp-generator/"&gt;https://addons.mozilla.org/en-US/firefox/addon/csp-generator/&lt;/a&gt;&lt;/p&gt;


&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
      &lt;div class="c-embed__cover"&gt;
        &lt;a href="https://blogs.appsecworld.com/" class="c-link s:max-w-50 align-middle" rel="noopener noreferrer"&gt;
          &lt;img alt="" src="https://res.cloudinary.com/practicaldev/image/fetch/s--4w_R0iXw--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdT4sG6R8NRfhCCMmDt_DwcnxWoep6fnLXSAgeUOj19f0GFLljprDkTJTH-fuQetuTz5KxVjYei8eSX99Em_JUgssxzCh8mt2rH7WEnGm_5F9qnhA0-YZEjTxTqmkG900ONI1hgiXCcWrMrY1s4dnWgDs3zgVirhAsqaeO97Nn-ZOdsiPQZJiVrBp6xQ/w1600/OWASP%2520API%2520Security%2520Top%252010%2520%282%29.webp" height="" class="m-0" width=""&gt;
        &lt;/a&gt;
      &lt;/div&gt;
    &lt;div class="c-embed__body"&gt;
      &lt;h2 class="fs-xl lh-tight"&gt;
        &lt;a href="https://blogs.appsecworld.com/" rel="noopener noreferrer" class="c-link"&gt;
          Free Learning Resources for Application Security and Penetration Testing 
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;p class="truncate-at-3"&gt;
          Learning portal for Application Security and DevSecOps Engineers. It contains well-written and in-depth articles on Software Security and DevSecOps
        &lt;/p&gt;
      &lt;div class="color-secondary fs-s flex items-center"&gt;
          &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://res.cloudinary.com/practicaldev/image/fetch/s--9kMCc23k--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogs.appsecworld.com/favicon.ico" width="16" height="16"&gt;
        blogs.appsecworld.com
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>security</category>
      <category>webdev</category>
      <category>tooling</category>
    </item>
    <item>
      <title>OWASP API Security Top 10 API4:2019 Lack of Resources &amp; Rate Limiting With an Example</title>
      <dc:creator>sahil gupta</dc:creator>
      <pubDate>Sun, 27 Nov 2022 19:18:42 +0000</pubDate>
      <link>https://dev.to/sahil3112/owasp-api-security-top-10-api42019-lack-of-resources-rate-limiting-with-an-example-54gm</link>
      <guid>https://dev.to/sahil3112/owasp-api-security-top-10-api42019-lack-of-resources-rate-limiting-with-an-example-54gm</guid>
      <description>&lt;p&gt;Improper configuration of resources and rate limiting can lead to attackers being able to overload a system with re``quests, causing APIs to fail or become unresponsive. Rate and resource limiting are measures that can be taken to help mitigate this risk. It involves limiting the number of requests that a user can make in a given period of time. This can prevent attackers from being able to send a large number of requests and overwhelm the system.&lt;/p&gt;

&lt;p&gt;In this blog, I have explained about the OWASP API Security Top 10 API4:2019 Lack of Resources &amp;amp; Rate Limiting With an Example.&lt;/p&gt;


&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
      &lt;div class="c-embed__cover"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/11/owasp-api-security-top-10-api-2019-lack-of-resources-and-rate-limiting.html" class="c-link s:max-w-50 align-middle" rel="noopener noreferrer"&gt;
          &lt;img alt="" src="https://res.cloudinary.com/practicaldev/image/fetch/s--schCF61j--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQVXbfp5KT7Do8NG4ji_lsatn8b80yAzTQb_P6ClywUr--lzPeokadopu1nVczVRmvpsoAvi0YCKnVycSqwGyu9PudNRK5mlkZoPjA0AyZbWQ4Qi1nR3Xj1YgvgJf1lZBBzO6nheEx5rA65-u33bzpQQo5eZZPSjmz2XweWrZRay0NsFnAU7YTNB0zJA/w1600/OWASP%2520API%2520Security%2520Top%252010.webp" height="" class="m-0" width=""&gt;
        &lt;/a&gt;
      &lt;/div&gt;
    &lt;div class="c-embed__body"&gt;
      &lt;h2 class="fs-xl lh-tight"&gt;
        &lt;a href="https://blogs.appsecworld.com/2022/11/owasp-api-security-top-10-api-2019-lack-of-resources-and-rate-limiting.html" rel="noopener noreferrer" class="c-link"&gt;
          OWASP API Security Top 10 API4:2019 Lack of Resources &amp;amp; Rate Limiting With Example
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;p class="truncate-at-3"&gt;
          learn about the OWASP API Security Top 10 API4:2019 Lack of Resources &amp;amp; Rate Limiting, its impact, an example, and remediation.
        &lt;/p&gt;
      &lt;div class="color-secondary fs-s flex items-center"&gt;
          &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://res.cloudinary.com/practicaldev/image/fetch/s--9kMCc23k--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_880/https://blogs.appsecworld.com/favicon.ico" width="16" height="16"&gt;
        blogs.appsecworld.com
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;


</description>
      <category>security</category>
      <category>api</category>
      <category>webdev</category>
      <category>opensource</category>
    </item>
  </channel>
</rss>
