Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
infosec
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel
Rxkov
Rxkov
Rxkov
Follow
Sep 6
CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It
Rxkov
Rxkov
Rxkov
Follow
Sep 6
JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It
#
authentication
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked
Rxkov
Rxkov
Rxkov
Follow
Sep 6
RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked
#
api
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page
Rxkov
Rxkov
Rxkov
Follow
Sep 6
Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page
#
authentication
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
CVE-2024-55591: How an Auth Bypass Became an Internet-Scale Firewall Takeover
Rxkov
Rxkov
Rxkov
Follow
Sep 6
CVE-2024-55591: How an Auth Bypass Became an Internet-Scale Firewall Takeover
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
GraphQL APQ Registration Bypasses Query Allowlists and Introspection Controls
Rxkov
Rxkov
Rxkov
Follow
Sep 6
GraphQL APQ Registration Bypasses Query Allowlists and Introspection Controls
#
api
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
GraphQL in Production: Introspection, Alias Batching, and Rate Limit Bypass on Real APIs
Rxkov
Rxkov
Rxkov
Follow
Sep 6
GraphQL in Production: Introspection, Alias Batching, and Rate Limit Bypass on Real APIs
#
api
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
Subdomain Takeover Severity Comes From Security Context, Not the Exploit Mechanism
Rxkov
Rxkov
Rxkov
Follow
Sep 6
Subdomain Takeover Severity Comes From Security Context, Not the Exploit Mechanism
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
GraphQL's Six Default Attack Surfaces
Rxkov
Rxkov
Rxkov
Follow
Sep 6
GraphQL's Six Default Attack Surfaces
#
api
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
XXE in APIs: Discovering Hidden XML Acceptance and Exfiltrating Data via OOB
Rxkov
Rxkov
Rxkov
Follow
Sep 6
XXE in APIs: Discovering Hidden XML Acceptance and Exfiltrating Data via OOB
#
api
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
OAuth 2.0 redirect_uri Bypass: The 5-Condition Matrix That Determines Exploitability
Rxkov
Rxkov
Rxkov
Follow
Sep 6
OAuth 2.0 redirect_uri Bypass: The 5-Condition Matrix That Determines Exploitability
#
authentication
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
GraphQL as Attack Surface: Introspection, Batching, and Schema Enumeration
Rxkov
Rxkov
Rxkov
Follow
Sep 6
GraphQL as Attack Surface: Introspection, Batching, and Schema Enumeration
#
api
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
CT Logs for OSINT: Map Subdomains and Infrastructure Without Sending a Single Packet
Rxkov
Rxkov
Rxkov
Follow
Sep 6
CT Logs for OSINT: Map Subdomains and Infrastructure Without Sending a Single Packet
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
CT Logs: Your Infrastructure Inventory Is Public Before DNS Propagates
Rxkov
Rxkov
Rxkov
Follow
Sep 6
CT Logs: Your Infrastructure Inventory Is Public Before DNS Propagates
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
5 min read
Working: API file upload defenses fail because validator fragmentation across upload paths leaves one path always unprotected
Rxkov
Rxkov
Rxkov
Follow
Sep 6
Working: API file upload defenses fail because validator fragmentation across upload paths leaves one path always unprotected
#
api
#
cybersecurity
#
infosec
#
security
Comments
Add Comment
6 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account