DEV Community

#infosec

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Comments
5 min read
CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel

CSWSH: Four Major WebSocket Frameworks Default to Vulnerable While Attackers Get a Bidirectional Channel

Comments
6 min read
Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Comments
5 min read
JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

Comments
5 min read
Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Webhook Producers Are SSRF by Default: Seven CVEs the Security Guides Don't Mention

Comments
5 min read
SAML XSW: Signatures That Validate the Wrong Element

SAML XSW: Signatures That Validate the Wrong Element

Comments
5 min read
Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials

Postman's Secret Variables Are Not Secret: How Public Workspaces Expose 4,000+ Live Credentials

Comments
6 min read
RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

RBAC Blocks the Wrong Layer: Mass Assignment Exploits the Fields Authorization Never Checked

Comments
6 min read
Wayback Machine for OSINT: What Stayed Archived After Remediation

Wayback Machine for OSINT: What Stayed Archived After Remediation

Comments
5 min read
JWT Algorithm Negotiation Is a Spec Design Flaw, Not a Library Bug

JWT Algorithm Negotiation Is a Spec Design Flaw, Not a Library Bug

Comments
5 min read
Working: CORS misconfigurations escape automated detection

Working: CORS misconfigurations escape automated detection

Comments
5 min read
XXE in Document-Processing APIs: The Attack Surface Nobody Hardens

XXE in Document-Processing APIs: The Attack Surface Nobody Hardens

Comments
5 min read
API SSRF: Allowlists Fail Because They Validate the URL, Not the Resolved IP

API SSRF: Allowlists Fail Because They Validate the URL, Not the Resolved IP

Comments
6 min read
CORS Misconfiguration in APIs: Why Reflected Origin Plus Credentials Is the Dangerous Pattern, Not Wildcard

CORS Misconfiguration in APIs: Why Reflected Origin Plus Credentials Is the Dangerous Pattern, Not Wildcard

Comments
6 min read
Subdomain Takeover Severity Comes From Security Context, Not the Exploit Mechanism

Subdomain Takeover Severity Comes From Security Context, Not the Exploit Mechanism

Comments
6 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.