Stratum Security Blog
Sign in Subscribe

appsec

A collection of 2 posts
Route 53 as Pentest Infrastructure
exfiltration

Route 53 as Pentest Infrastructure

Use of DNS infrastructure is a staple of blind application testing and data exfiltration. Both of these scenarios are applicable in most pentest engagements, but building engagement specific DNS infrastructure can be a pain. Now with so many cloud providers available, can we make deployment of this infrastructure easier? Enter
17 Oct 2018 5 min read
Journey into WebSockets Authentication/Authorization
websockets

Journey into WebSockets Authentication/Authorization

One subject that is often mentioned in talks about WebSockets security, is how WebSockets does not implement authentication/authorization in the protocol. This might not be as familiar because when the original research was done, there were not many applications using WebSockets. I wanted to demonstrate what this pattern looks
13 Jun 2016 5 min read
Page 1 of 1
Stratum Security Blog © 2025
Powered by Ghost