Company-related Passwords

  1. We have a company named “Hooli”
  2. We enforced a default…

What is Account Takeover?

Testing for Username/Email Enumeration

  • through Login Error Message Discrepancy
  • through Forgot/Reset Password Functionality
  • through Registration Form
  • through Response Time Discrepancy
  • through Response Size Discrepancy
  • through Account Lockout Message

Testing for Vulnerable Components

  • Vulnerable Libraries/Server/Proxy/Frameworks
  • Vulnerable WAF
  • Using Wappalyzer Extension

What is Clickjacking?

#1 — You are passionate about it

  1. Train your employees about security awareness. Humans represent the weakest links that attackers take advantage of, that’s why…

What is Denial-of-Service?

Types of Denial-of-Service (DoS) Attacks

What is a Penetration Test?

What is CSRF?

