Research & Insights

Security
Blog

Research, vulnerability analysis, and field notes from our security team.

Featured Web Security December 18, 2024 · 12 min read

Race Conditions in Modern Web Applications: From Theory to Exploitation

Race conditions are among the most underappreciated vulnerabilities in web applications. We walk through real-world exploitation techniques using Burp Suite's parallel requests — from coupon abuse to account takeover — and explain why traditional rate limiting doesn't help.

MK
Mohsin K.
· Read article →
MobileHigh Severity

Hardcoded Firebase API Keys: What Attackers Can Actually Do With Them

Beyond just reading the key — a practical guide to abusing misconfigured Firebase Security Rules to enumerate users, exfiltrate data, and send authenticated requests.

MK
Dec 10, 2024
8 min
CloudAWS

Chaining IAM Misconfigurations to Full AWS Account Takeover

A walkthrough of how three "low-severity" IAM findings chain together into a complete account compromise — and why your cloud pentester needs to think in attack graphs, not individual findings.

MK
Nov 28, 2024
15 min
Web SecurityIDOR

Beyond Sequential IDs: Finding IDOR in GUIDs and Hashed References

Developers think GUIDs make IDOR impossible. We break down the patterns that still leak predictability — API responses that cross-reference IDs, mass assignment, and leaked references in logs.

MK
Nov 14, 2024
10 min
Tools

Building a Python Firebase Security Automation Tool for VAPT Engagements

How we built a reusable Python tool to automate Firebase security rule testing, unauthenticated API key abuse checks, and database exposure validation during mobile app assessments.

MK
Oct 30, 2024
18 min
NetworkActive Directory

From Zero to Domain Admin: A Realistic Internal Pentest Walkthrough

A sanitized case study of a full internal network assessment — initial foothold via LLMNR poisoning, Kerberoasting, lateral movement with CME, and Golden Ticket persistence.

MK
Oct 15, 2024
22 min
Web SecurityGraphQL

GraphQL Security Testing: Introspection, Batching Attacks, and Authorization Flaws

GraphQL's flexibility creates unique security challenges. We cover the full attack surface: introspection enumeration, alias batching for rate-limit bypass, field-level access control gaps, and injection via directives.

MK
Sep 28, 2024
14 min

Security Research in Your Inbox

New articles, vulnerability writeups, and security tool releases — delivered occasionally, never spammy.

No spam. Unsubscribe anytime.