OWASP API Top 10 for Dummies — Part #2Welcome back to our blog series on the OWASP API Top 10! This is continued from Part I. If you haven’t read the first part, check it out…Nov 27, 202216Nov 27, 202216Get an email whenever Inon Shkedy publishes.SubscribeBy signing up, you will create a Medium account if you don’t already have one. Review our Privacy Policy for more information about our privacy practices.Medium sent you an email at to complete your subscription.
Log4Shell — Simple Techincal Explanation of the ExploitLast week’s Log4Shell vulnerability is a dramatic example of how modern applications, interconnected services and pervasive APIs can…Dec 17, 202177Dec 17, 202177
Hacking your mind — Mindfulness Journey from a hacker perspectiveIntroSep 23, 20211791Sep 23, 20211791
31 Tips — Advanced Bug Bounty & PentestingTo welcome Blackhat & Defcon conferences, we published a daily tip on Bug Bounty & AppSec during the month of July 2021.Aug 23, 2021242Aug 23, 2021242
Behind the Scenes of SAST — The Challenges of Code ScanningI love the idea behind Static Application Security Testing (SAST) tools — they aim to create a utopian world clean from application…Apr 19, 202173Apr 19, 202173
Behind the Scenes of DAST — How do Security Scanners Work ?The idea behind Dynamic Applications Security Testing (DAST) is pretty clever — a tool that simulates a human penetration tester. With the…Mar 16, 202138Mar 16, 202138
Modern Application Security — Good and Bad NewsThis is the second article in a 2-part blog series. In the previous article, we talked about the major changes in application development…Aug 26, 20208Aug 26, 20208
Modern Application Security — What are Modern Applications?What are Modern Applications?Aug 26, 20208Aug 26, 20208
Published inInfoSec Write-ups31 Tips — API Security & PentestingTo welcome the new year, we published a daily tip on API Security during the month of January 2020.Feb 4, 20201Feb 4, 20201
Published inSalt SecurityWhat Moving To the Bay Area Taught Me About Loving My Pentesting ToolsLet’s talk for a moment about love, relationships and commitment…Dec 6, 20181Dec 6, 20181
Published inSalt SecurityAPI Protection — What You Need To Know In The New API EconomyTechnology is constantly evolving. We’ve seen this in recent years in the way applications are developed (e.g. CI/CD), delivered (e.g…Nov 14, 2018Nov 14, 2018
Studying APK reverse engineering by breaking the anonymity of BlindSpot appBlindSpot is an Israeli app that provides anonymous chat features, and was founded by Dor Refaeli (Bar Refaeli’s brother)Jan 8, 20183Jan 8, 20183
Export InjectionThis article will talk about a new server side vulnerability that I discovered in the PDF export process. Many servers are still…Jan 4, 20181Jan 4, 20181