Just finished BadBank, an intentionally vulnerable Flask banking app for AppSec practice.
Exploited SQLi, XSS, CSRF, IDOR & Broken Access Control, then documented secure fixes.
Open source → https://t.co/LB9WvIwb5v
#AppSec#OWASP#CyberSecurity#Flask
Your SquidScan reports just got an order of magnitude better!
Along with your holistic scan report, a new KPI dashboard is now included in your output!
All scans, past present and future have been updated to include this. So, if you have a past scan go check it out!
Here's a live example from the Etsy Bug bounty https://t.co/Lm6ULHeFAi
Hey everyone, we would like to let you know that there is going to be an OWASP meet up in Brno on 30th of June. Grab your tickets here https://t.co/AB49slw1qK. Ping us if you have a (lightning) talk! Cheers.
Are you taking part in the Etsy bug bounty? Here's some free recon!
Squid Scan is great at detecting and scanning graphql for introspection and this one is a good example
https://t.co/slLr7hqXLc
the last class of the ethical hacking internship was held and we taught the students IOT PENETRATION TESTING we explored how IoT devices communicate using MQTT, a lightweight messaging protocol designed for efficient device-to-device communication, unlike traditional HTTP-based communication.
Through hands-on practical sessions, we also demonstrated how MQTT environments can become vulnerable to unauthorized access, data interception, and device manipulation when security controls are poorly configured.
The session highlighted the importance of secure MQTT deployment, including proper authentication, encryption, and access control mechanisms, in protecting IoT ecosystems from cyber threats.
#CyberSecurity #IoT #MQTT #EthicalHacking #NetworkSecurity #InformationSecurity #CyberAwareness #PenetrationTesting
@Anastasis_King Good reminder that most real-world Wi-Fi issues come from misconfiguration, not just “weak encryption.” Router defaults and exposed management interfaces are still heavily underestimated attack surfaces.
@Squid_Sec The best recon tools are the ones that disappear into your workflow. Kick off scans, monitor progress anywhere, and come back when the data is ready. Nice work.