By Tim Medin SANS Instructor & Counter Hack Engineer Meteor is a game-changing framework for rapid software development and is the top-rated web framework on Github. Meteor offers a number of benefits including offering real-time applications by default. With its greatbenefits, we are likely to see more Meteor applications... ...And you should know how to … Continue reading Mining Meteor
By Joshua Wright For the past few years I've been invited to speak at the SANS HackFest conference. This is a great opportunity for me to present new research and useful pen testing techniques to a hungry audience. It's also a highly competitive event among speakers. Each year my stuff needs to be bigger and … Continue reading Ghost in the Droid: Reverse Engineering Android Apps
We're delighted to announce a new Twitter-based contest here with a fantastic prize. And, participating in this one is really easy. Check it out! SANS Pen Test HackFest Summit & Training is coming back for another year of exciting hands-on learning opportunities in Crystal City, VA, November 2-9! We throw everything we've got into … Continue reading SANS HackFest Twitter Contest!
[Editor's Note: Chris Dale is an amazing gentleman. He finds Cross-Site Scripting (XSS) flaws in the most interesting and wonderful places. In this article, Chrisshares some insights into his methods and how he applied them in finding a zero-day XSS flaw associated with Microsoft Asure. Good reading! -Ed.] By Chris Dale Earlier in 2016, I … Continue reading Azure 0day Cross-Site Scripting with Sandbox Escape
How the latest update to iOS 10 will dramatically improve Android security At the Apple WWDC conference in June, Ivan Krstic, Apple Head of Security Engineering & Architecture, made a bold declaration: "At the end of 2016, Apple will make ATS mandatory for all developers who hope to submit their apps to the App Store." … Continue reading iOS 10 is Apple's Gift to Android Users