MOST POPULAR VIDEOS

LATEST BLOG POSTS

Maintaining Session States in .NET Apps With Burp

During a recent web app test, I encountered a situation when I would be randomly logged out of the application when running sqlmap. I wasn't manipulating any of the session cookies and the logouts happened at random times. I needed a way to detect when I got logged...

Capturing SQL Server User Hash with SQLi

On a recent external web app pen test, I found a possible SQL injection vulnerability using the Burp Scanner. One of the tests triggered an A record lookup for the Burp Collaborator server. In the screenshot below, we can see the test that triggered the finding....

Getting a Handle on Large Parameter Sets

During a recent web app engagement, I wanted to run some of the Burp Scanner automated checks, but I was confronted with several issues. First, this particular application did not respond kindly to manipulation of the session cookies. The application and its single...

WEBCASTS

MOST POPULAR SLIDES

 

 

 

 

 

 

 

 

GET THE LATEST

Sign up for the latest resources from Red Siege.