1.

Try to bypassing by changing the content-type header of the file you are uploading. 2. Try to bypassing by adding a valid extension before the execution extension (file name) 3. Try to bypassing by ...

Continue Reading
API4:2019: Lack of Resources and Rate Limiting A lack of resources or rate limiting can lead to a denial-of-service (DoS) attack.

A DoS attack occurs when an attacker sends more requests than the system can handle, causing it to crash or become unavailable for legitimate users. The most common way to perform a DoS attack is by s ...

Continue Reading
The API Economy is here, get on board 1:25PM–1:50PM Stage The Rise of the API-led Business Model – How to build a successful business with APIs? 1:50PM–2:15PM Stage How to create an effective and sustainable Open Banking strategy for your bank? Paula D’Alessandro De Oliveira, Head of Digital Transformation at KBC Group NV/SA.

KBC Bank N.V., Brussels Office, Belgium.  Head of Digital Transformation since 2016.  Previously she was in charge of the Innovation Lab (2014-2016) and before that she was responsible for the Mobil ...

Continue Reading
SOAtest + OWASP ZAP = DAST for functional tests.

Parasoft SOAtest now features the ability to closely integrate dynamic application security testing (DAST) for APIs into your functional test suites, and DAST also integrates seamlessly with Parasoft ...

Continue Reading
The most important thing to remember is that the “best” way to do anything in software development depends on your situation.

You can use any of these techniques, or you can combine them with each other and/or with other techniques. The key is not to get stuck in a rut where you think there’s only one right way of doing thi ...

Continue Reading
The current state of the game is that we have a working prototype, but it’s not ready for prime time.

We need to do more work on it before we can release a playable version. We're going to be doing some playtesting at PAX East this weekend and will hopefully get some useful feedback from players ther ...

Continue Reading
I’m a big fan of the new features in C# 6.

0, but I don’t think they should be used until you understand how they work and what their limitations are. I was recently asked to give an introductory talk on some of the new features in C# 6.0 at ...

Continue Reading
API8:2019 Broken Access Control APIs are often designed with the assumption that all users have access to all resources, which is not always true.

By exploiting this issue, attackers can gain access to other users’ resources and/or administrative functions. API9:2019 Insufficient Logging & Monitoring Insufficient logging and monitoring of ...

Continue Reading

Back to Main

Subscribe for the latest news: