DEV Community

Davi profile picture

Davi

404 bio not found

Location Brazil Joined Joined on  github website
Your S3 Bucket Might Be Public Right Now. We'll Tell You First.

Your S3 Bucket Might Be Public Right Now. We'll Tell You First.

Comments
3 min read
API Security Testing: OWASP Top 10 for APIs

API Security Testing: OWASP Top 10 for APIs

Comments
5 min read
Threat Intelligence 101: From Raw Data to Actionable Insights

Threat Intelligence 101: From Raw Data to Actionable Insights

Comments
5 min read
Web Application Reconnaissance: Mapping the Attack Surface

Web Application Reconnaissance: Mapping the Attack Surface

Comments
7 min read
JWT Security: How Misconfigured Tokens Expose Your APIs

JWT Security: How Misconfigured Tokens Expose Your APIs

Comments
7 min read
GitHub OSINT: What Developers Expose Without Realizing It

GitHub OSINT: What Developers Expose Without Realizing It

Comments
6 min read
Capital One 2019: SSRF, AWS IMDS, and 106 Million Exposed Records

Capital One 2019: SSRF, AWS IMDS, and 106 Million Exposed Records

Comments
6 min read
TLS Certificate Analysis: What Your SSL Config Reveals

TLS Certificate Analysis: What Your SSL Config Reveals

Comments
6 min read
Kubernetes Attack Surface: What Exposed APIs and Misconfigured RBAC Reveal

Kubernetes Attack Surface: What Exposed APIs and Misconfigured RBAC Reveal

Comments
5 min read
Email Header Analysis: What SMTP Metadata Reveals About Infrastructure and Identity

Email Header Analysis: What SMTP Metadata Reveals About Infrastructure and Identity

Comments
6 min read
Passive DNS: The Infrastructure History That Reveals Origin, Movement, and Campaign

Passive DNS: The Infrastructure History That Reveals Origin, Movement, and Campaign

Comments
5 min read
Subdomain Takeover: When an Abandoned CNAME Becomes an Attack Vector

Subdomain Takeover: When an Abandoned CNAME Becomes an Attack Vector

Comments
5 min read
BOLA, Mass Assignment, and Rate Limit Bypass: Three Tests Every API Fails

BOLA, Mass Assignment, and Rate Limit Bypass: Three Tests Every API Fails

Comments
5 min read
BGP and ASN Mapping: The Routing Table as an Honest Infrastructure Map

BGP and ASN Mapping: The Routing Table as an Honest Infrastructure Map

Comments
5 min read
Shodan, Censys, and FOFA: How Internet Scanners Already Mapped Your Attack Surface Before Your First Firewall Rule

Shodan, Censys, and FOFA: How Internet Scanners Already Mapped Your Attack Surface Before Your First Firewall Rule

Comments
5 min read
DNS Rebinding: Your Browser as an Unauthenticated Internal Proxy

DNS Rebinding: Your Browser as an Unauthenticated Internal Proxy

Comments
6 min read
OAuth 2.0: redirect_uri, Open Redirect, and PKCE — Observable Pre-conditions Before Exploitation

OAuth 2.0: redirect_uri, Open Redirect, and PKCE — Observable Pre-conditions Before Exploitation

Comments
6 min read
Exposed Buckets: How S3, GCS, and Azure Blob Are Passively Discovered and Exploited

Exposed Buckets: How S3, GCS, and Azure Blob Are Passively Discovered and Exploited

Comments
6 min read
Server-Side Template Injection: How to Identify the Engine and Escalate to RCE

Server-Side Template Injection: How to Identify the Engine and Escalate to RCE

Comments
6 min read
The WebSocket Upgrade Boundary: The Authentication Blind Spot API Scanners Never Find

The WebSocket Upgrade Boundary: The Authentication Blind Spot API Scanners Never Find

Comments
7 min read
Insecure Deserialization in APIs: How to Detect It Without Source Code Access

Insecure Deserialization in APIs: How to Detect It Without Source Code Access

Comments
5 min read
Why API Key Rotation Solves the Wrong Problem

Why API Key Rotation Solves the Wrong Problem

Comments
5 min read
Server-Side Prototype Pollution: From JSON Body to RCE via Node.js Gadget Chains

Server-Side Prototype Pollution: From JSON Body to RCE via Node.js Gadget Chains

Comments
6 min read
Command Injection in APIs: Parameters That Reach ImageMagick, wkhtmltopdf, and ffmpeg

Command Injection in APIs: Parameters That Reach ImageMagick, wkhtmltopdf, and ffmpeg

Comments
5 min read
Path Traversal in APIs: Parameter Semantics, ZIP Slip, and Encoding Bypass

Path Traversal in APIs: Parameter Semantics, ZIP Slip, and Encoding Bypass

Comments
5 min read
JWT Algorithm Confusion: RS256 to HS256, Psychic Signatures, and alg:none on Production APIs

JWT Algorithm Confusion: RS256 to HS256, Psychic Signatures, and alg:none on Production APIs

Comments
6 min read
BOPLA: Why APIs Return Fields They Should Not and How to Detect It

BOPLA: Why APIs Return Fields They Should Not and How to Detect It

Comments
5 min read
HTTP Host Header in APIs: Reset Poisoning, Routing SSRF, and Cache Poisoning

HTTP Host Header in APIs: Reset Poisoning, Routing SSRF, and Cache Poisoning

Comments
5 min read
Business Logic in E-Commerce APIs: Price Manipulation, Negative Quantity, and Coupon Abuse

Business Logic in E-Commerce APIs: Price Manipulation, Negative Quantity, and Coupon Abuse

Comments
6 min read
API Login Is the Soft Target: Why Every Browser Defense Is Structurally Absent at the API Authentication Layer

API Login Is the Soft Target: Why Every Browser Defense Is Structurally Absent at the API Authentication Layer

Comments
4 min read
Working: HTTP parameter pollution attacks APIs because WAFs evaluate one parameter value while frameworks execute a different one

Working: HTTP parameter pollution attacks APIs because WAFs evaluate one parameter value while frameworks execute a different one

Comments
5 min read
IDOR and BOLA: Why Object-Level Access Control Is Hard to Audit and Easy to Exploit

IDOR and BOLA: Why Object-Level Access Control Is Hard to Audit and Easy to Exploit

Comments
4 min read
SSRF in APIs: Six URL-Accepting Parameter Types and the IMDSv1/IMDSv2 Decision That Determines Severity

SSRF in APIs: Six URL-Accepting Parameter Types and the IMDSv1/IMDSv2 Decision That Determines Severity

Comments
5 min read
Working: Prototype Pollution in Node.js APIs Is a Process-Wide Trust Failure, Not a Library Bug

Working: Prototype Pollution in Node.js APIs Is a Process-Wide Trust Failure, Not a Library Bug

Comments
5 min read
VITE_ Is a Promotion Operator: How Build Pipelines Ship Server-Side Secrets to the Browser

VITE_ Is a Promotion Operator: How Build Pipelines Ship Server-Side Secrets to the Browser

Comments
5 min read
Web Cache Deception Against APIs: CDNs Cache What Backends Serve Privately

Web Cache Deception Against APIs: CDNs Cache What Backends Serve Privately

Comments
6 min read
Working: Math.random() Is Not Your Friend: PRNG Prediction and Timing Attacks in API Tokens

Working: Math.random() Is Not Your Friend: PRNG Prediction and Timing Attacks in API Tokens

Comments
5 min read
SAML XSW: Signatures That Validate the Wrong Element

SAML XSW: Signatures That Validate the Wrong Element

Comments
5 min read
Three Signal Channels Leak Valid Account Lists Before Authentication Completes: Status Code, Response Body, and Timing

Three Signal Channels Leak Valid Account Lists Before Authentication Completes: Status Code, Response Body, and Timing

Comments
5 min read
CVE-2024-55591: How an Auth Bypass Became an Internet-Scale Firewall Takeover

CVE-2024-55591: How an Auth Bypass Became an Internet-Scale Firewall Takeover

Comments
5 min read
HTTP/2 Rapid Reset: How the Protocol Amplifies DoS Against API Gateways

HTTP/2 Rapid Reset: How the Protocol Amplifies DoS Against API Gateways

Comments
5 min read
API Key Rotation Leaves Three Records Untouched: Git History, Access Logs, and the Attacker Who Watched the Fix Commit

API Key Rotation Leaves Three Records Untouched: Git History, Access Logs, and the Attacker Who Watched the Fix Commit

Comments
5 min read
Webhook Signature Bypass: When the Receiver Skips the HMAC Check

Webhook Signature Bypass: When the Receiver Skips the HMAC Check

Comments
5 min read
Exposed OpenAPI Specs: A Complete Attack Map Before the First Request

Exposed OpenAPI Specs: A Complete Attack Map Before the First Request

Comments
5 min read
HTTP Verb Tampering in REST APIs: When OPTIONS and HEAD Bypass Access Control

HTTP Verb Tampering in REST APIs: When OPTIONS and HEAD Bypass Access Control

Comments
5 min read
JWT aud Claim Bypass: Cross-Service Token Reuse in Microservice Architectures

JWT aud Claim Bypass: Cross-Service Token Reuse in Microservice Architectures

Comments
6 min read
Terraform State Files: Your Entire Infrastructure Credential Inventory in One Plaintext File

Terraform State Files: Your Entire Infrastructure Credential Inventory in One Plaintext File

Comments
5 min read
Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials

Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials

Comments
6 min read
Working: OTel Spans Are Secret Stores — How Distributed Traces Leak Bearer Tokens to Anyone With Observability Access

Working: OTel Spans Are Secret Stores — How Distributed Traces Leak Bearer Tokens to Anyone With Observability Access

Comments
4 min read
Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Comments
5 min read
API Key Scope Validation Failures: When 'Read-Only' Is a Documentation Claim, Not a Backend Constraint

API Key Scope Validation Failures: When 'Read-Only' Is a Documentation Claim, Not a Backend Constraint

Comments
5 min read
Server-Sent Events Security: How EventSource Breaks Your API Authentication Model

Server-Sent Events Security: How EventSource Breaks Your API Authentication Model

Comments
4 min read
API Gateway Path Normalization Bypass: When HAProxy Sees /admin and Your App Sees /admin

API Gateway Path Normalization Bypass: When HAProxy Sees /admin and Your App Sees /admin

Comments
5 min read
GraphQL APQ Registration Bypasses Query Allowlists and Introspection Controls

GraphQL APQ Registration Bypasses Query Allowlists and Introspection Controls

Comments
5 min read
RAG Poisoning Is a Supply Chain Attack, Not a Prompt Injection Variant

RAG Poisoning Is a Supply Chain Attack, Not a Prompt Injection Variant

Comments
4 min read
Open-Source LLMs Are Unverified Dependencies: The Model Backdoor Gap npm Already Solved

Open-Source LLMs Are Unverified Dependencies: The Model Backdoor Gap npm Already Solved

Comments
5 min read
AI Agents Are eval(userInput) With Extra Steps

AI Agents Are eval(userInput) With Extra Steps

Comments
5 min read
AI Agent Long-Term Memory Is an Unguarded Database: How Poisoning Attacks Survive Across Sessions

AI Agent Long-Term Memory Is an Unguarded Database: How Poisoning Attacks Survive Across Sessions

Comments
5 min read
Agent Identity Spoofing in Multi-Agent Systems: Your Orchestrator Has No Idea Who It Is Talking To

Agent Identity Spoofing in Multi-Agent Systems: Your Orchestrator Has No Idea Who It Is Talking To

Comments
5 min read
JSON, CSV, and YAML Are Not Safe Formats for AI Agents: They Are Attack Vectors

JSON, CSV, and YAML Are Not Safe Formats for AI Agents: They Are Attack Vectors

Comments
5 min read
loading...