Web application security: missing HTTP headers as a business risk

Web application security: missing HTTP headers as a business risk

HTTP headers and web application security: an underrated layer of defence Discussions around web application security typically focus on backend logic, authentication, WAFs or vulnerability assessments. However, there is a layer that rarely receives attention, despite...
Session fixation explained: Hidden web application security risk

Session fixation explained: Hidden web application security risk

Session fixation: An underestimated threat Session fixation rarely receives the same level of attention as vulnerabilities such as XSS or SQL injection. The reason is simple: it’s less visible, harder to understand, and does not present itself as a classic break-in....
What Does an Ethical Hacker Do? | Business-Focused Guide

What Does an Ethical Hacker Do? | Business-Focused Guide

What does an ethical hacker do? – And why it is a business question Spoiler: an ethical hacker – aka pentester – is not sitting in a dark basement wearing a black hoodie. Even if Hollywood has done a remarkably good job convincing us otherwise. So what does an ethical...