The OWASP Top 10 details critical risks associated with web application security and is the defacto standard for web app security.
Tag: infosec
Include Command Strings – Penetration Test Reporting Tips
A good pentest report is supposed to be a teaching tool that provides the folks on the receiving end with information that makes it possible for them to do a lot of the same things we did. Here are a few reasons why we want them to do that.
Hire an Editor – Penetration Test Reporting Tips
If you really, honestly, and truly want to take your reports to the next level, hire an editor.
Report As You Go – Penetration Test Reporting Tips
If what you did does not show up in your pentest report, it didn’t happen. So how do you make sure your report captures everything you did? (First in a series of posts.)
Digital Reconnaissance & Recon Tools
The old adage, “knowledge is power,” is true in general, but in infosec, knowledge is mission critical. Luckily, there are a lot of tools to make recon easier.
Thoughts About Diversity
Diversity is one of the buzzwords of the day. But what does it really mean and why does it matter?
A G33k Goes To DEFCON
Day of Shecurity sent me to DEF CON 26. I had a wonderful time, did some cool things, and have already made plans to attend DEF CON 27. If you want the full details, keep reading…