-
Recent Posts
Recent Comments
Archives
Categories
- Access Control Flaws
- Authentication Flaws
- Backdoors
- Blind SQL Injection
- Bypass Client Side Validation
- Cache Poisoning
- Client Side Filtering Attacks
- Client-Side Attacks
- Cross Site Request Forgery
- Cross Site Scripting
- Cross Site Tracing Attacks
- Cryptographic Attacks
- Data Layer Access Control
- Denial of Service
- DOM Based XSS
- Encoding
- Fail Open Authentication
- File Handling Vulnerabilities
- Hidden Fields
- HTTP Splitting
- Improper Error Handling
- Injection Flaws
- Insecure Client Storage
- Insecure Login
- JSON Injection
- Log Spoofing
- Multi-Level Logon
- Numeric SQL Injection
- Password Recovery Attack
- Reflected XSS
- Remote Admin Attacks
- Same Origin Policy Protection
- Session Hijacking
- Silent Transactions Attack
- SOAP Request
- Spoofing Cookies
- SQL Injection
- Stored XSS
- String SQL Injection
- Thread Safety Problems
- Uncategorized
- Weak Authentication
- WSDL Scanning
- XML Injection
- XPATH Injection
Meta
Author Archives: Joseph McCray Jr.
WAVSEP – Web Application Vulnerability Scanner Evaluation Project
I have to admit that I really think this is a good idea. Shay Chen (@sectooladdict) has put together a project to evaluate Web Application Vulnerability scanners. He calls it WAVSEP. The project is currently being hosted on Google code. … Continue reading
Cross Site Scripting – So what?
Ok – so I decided to put in a few things about Cross Site Scripting. I wanted to give you enough information to be able to both understand XSS, and more importantly do it against a modern application protected by … Continue reading
Posted in Cross Site Scripting
Tagged dom-based xss, filter evasion, reflected xss, stored xss
Leave a comment
Advaned SQL Injection Presentation
I did this talk a few years ago before I started Strategic Security. I love the subject of SQL Injection, I’ve spoken on it a lot and people often ask me for my slides. If you’d like my slides you … Continue reading
Posted in SQL Injection
Tagged blind sql injection, ids evasion, sql injection, union sql injection, WAF bypass
Leave a comment
Metasploit JSP Shells
The Strategic Security rookies are hard at work. This is one of many blog posts that you’ll be seeing from them. I hope you enjoy it, and if you find technical errors in it please let me know so I … Continue reading
Welcome to Web App Pentest
I really hope that people will enjoy and learn from this website. For me as a Network Penetration Tester for several years it was REALLY hard to transition to doing web application penetration tests. I really didn’t have a strong … Continue reading
Posted in Uncategorized
Leave a comment