DEV Community

#infosec

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel

CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel

Comments
6 min read
JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

Comments
5 min read
RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

Comments
6 min read
Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Comments
5 min read
CVE-2024-55591: How an Auth Bypass Became an Internet-Scale Firewall Takeover

CVE-2024-55591: How an Auth Bypass Became an Internet-Scale Firewall Takeover

Comments
5 min read
GraphQL APQ Registration Bypasses Query Allowlists and Introspection Controls

GraphQL APQ Registration Bypasses Query Allowlists and Introspection Controls

Comments
5 min read
GraphQL in Production: Introspection, Alias Batching, and Rate Limit Bypass on Real APIs

GraphQL in Production: Introspection, Alias Batching, and Rate Limit Bypass on Real APIs

Comments
6 min read
Subdomain Takeover Severity Comes From Security Context, Not the Exploit Mechanism

Subdomain Takeover Severity Comes From Security Context, Not the Exploit Mechanism

Comments
6 min read
GraphQL's Six Default Attack Surfaces

GraphQL's Six Default Attack Surfaces

Comments
5 min read
XXE in APIs: Discovering Hidden XML Acceptance and Exfiltrating Data via OOB

XXE in APIs: Discovering Hidden XML Acceptance and Exfiltrating Data via OOB

Comments
6 min read
OAuth 2.0 redirect_uri Bypass: The 5-Condition Matrix That Determines Exploitability

OAuth 2.0 redirect_uri Bypass: The 5-Condition Matrix That Determines Exploitability

Comments
6 min read
GraphQL as Attack Surface: Introspection, Batching, and Schema Enumeration

GraphQL as Attack Surface: Introspection, Batching, and Schema Enumeration

Comments
6 min read
CT Logs for OSINT: Map Subdomains and Infrastructure Without Sending a Single Packet

CT Logs for OSINT: Map Subdomains and Infrastructure Without Sending a Single Packet

Comments
5 min read
CT Logs: Your Infrastructure Inventory Is Public Before DNS Propagates

CT Logs: Your Infrastructure Inventory Is Public Before DNS Propagates

Comments
5 min read
Working: API file upload defenses fail because validator fragmentation across upload paths leaves one path always unprotected

Working: API file upload defenses fail because validator fragmentation across upload paths leaves one path always unprotected

Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.