Pentest IoT: 10 hardware & software tests Internet of Things security is a current topic, however penetration testing on connected devices are far from being a widespread practice. Most manufa... 24.04 IoT
Social Engineering: Experience feedback! We are regularly conducting social engineering penetration tests for our clients.Our pentesters (security experts) tried various techniques, scenarios... 04.04 Phishing & Social Engineering
What does a penetration test vs a vulnerability scanner bring? The first one and the second are said to be the best allies of CISO (and in general people in charge of IT security). There are though two different t... 31.01 Applications
What R.O.I for a Security Audit? It is a question that we often hear. Unfortunately Sorry, we don’t have a ready made formula to reveal. The return on investment of a pentest is compl... 28.11 Applications
Protect yourself from CSRF attacks with the SameSite cookie attribute What is a Cross Site Request Forgery Attack? The CSRF is an attack that forces an end user to perform unwanted actions and without noticing on a web a... 18.10 Applications
Administration Interfaces: The Underestimated Weakness Administration interface, back-office, dashboard, admin panel… several names for the same thing: the place where organizations manage their data, supe... 11.07 Applications
Understanding the Web Vulnerability Server-Side Request Forgery (1/2) We often think that a firewall restrictive enough protects the access to non-open services. We also believe that only a compromise machine can gi... 15.05 Applications
7 Questions to Ask Yourself Before Doing a Penetration Test Security is essential, and you agree with that. You want indeed to do a penetration test (or pentest) on your solution soon… Here are 7 question... 02.05 Applications
Recon Audit: Which Information About Your Company Can Be Found Online? “All the success of an operation lies in its preparation”, Sun Tzu. Already true in the 6th century BC, this maxim remains true in the 21st century. A... 11.04 Applications
GDPR: Technical Security Measures Updated Dec 1. 2020 More than 2 years after the GDPR came into force (May 25, 2018), sanctions have been pronounced by several data protection authori... 13.03 Applications
How to Assess Security Flaws Risk? After a security audit, you have been notified flaws. Critical, important, medium: do you know how this is assessed? We describe here our methodology,... 27.02 Applications
Phishing: How to identify suspicious emails? Phishing evolved a lot. Whereas fraudulent email was before easily detected by its obvious spelling mistakes and its exaggerated request or threats (i... 13.02 Phishing & Social Engineering