Unsafe FileSystem Resource Release
Attackers can leave the application in an unresponsive state such as denial of service causing customers to wait for a long time. #InfoSec#CyberSecurity
The code is the heart of a software and will tell a lot when a hacker gets his hands on it. Why would you not run security static code analysis on your own source code ?
Insecure Comparison - Type Name
Attackers can inject malicious types despite of a validation which takes type name into consideration.#CyberSecurity#Applicationsecurity
It’s @attackflow next on stage 🎪. CEO Caner tells us how he is developing application software security so developers can find weaknesses & threats as they code 💻 #DemoDay
The real-time #DevOps application security vulnerability checker and "mentor" from @AttackFlow, all the way from Turkey! @CylonLab#DemoDay https://t.co/V7649ZTcBg
AttackFlow, a leading software security and analysis company, becomes Gold Sponsor of #NOPcon ! Thanks @attackflow for supporting the largest hacker event in Turkey
Ransomware developers distribute their malicious software from your web application by exploiting Open Redirect vulnerabilities. Want to learn more? https://t.co/3GqjUFtbd8
Do CI tools stop you because of application security? Why don't you eliminate false positive while developing? Drop us a message if you wonder! https://t.co/8SHK5xyNru
Writable Public Static Fields
Attackers may be able to modify a public static field changing the state of public static fields are accessible by the client code. Moreover, the value of these fields can also be changed by malicious client code according to their advantage.
Hibernate SQL Injection
The attacker can inject unauthorized partial SQL query strings and steal data, such as user passwords, or run unauthorized commands on database server. This can lead to total ownage of database and other servers in the corporate environment. #InfoSec
Insecure Database Administrative Mechanism
The attacker can execute direct sql commands on the remote database that application uses leading to sensitive information theft or total system ownage. #InfoSec#InputValidation#CyberSecurity
https://t.co/WUPG5N4sdd