TCH SH ShiftLeftSec Blind Server Side Request Forgery — A Portswigger We have already looked at Server-Side Request Forgery (SSRF) and found that exploitation usually relied on one key advantage: visibility…
TCH SH ShiftLeftSec The use of an Open Redirect in Server Side Request Forgery (SSRF) — A Portsw In previous articles, we’ve already covered what Server-Side Request Forgery (SSRF) is. In this post, we’ll look at how open redirects can…
TCH SH ShiftLeftSec Automating ZAP for CI/CD — an MVP If you’ve read my other articles, you’ll know that I think highly of OWASP ZAP, but one question comes up again and again: whats the best…