Skip to content
Security field notes

Understand the bug. See the exploit. Ship the fix.

Practical guides to real-world web vulnerabilities, written by the team building the scanner that finds them.

Browse by topic

Injection

Untrusted input changes the meaning of a query, command or template.

19 posts
Browse 7 topics in Injection

Client-side & redirects

The victim's own browser and trust boundaries are turned against them.

9 posts
Browse 3 topics in Client-side & redirects

Server-side requests & parsers

The server is coerced into fetching or parsing something it shouldn't.

10 posts
Browse 3 topics in Server-side requests & parsers

Files, objects & APIs

Paths, serialized objects and API schemas leak more than intended.

12 posts
Browse 3 topics in Files, objects & APIs

Latest posts