Read this first: what belongs here, and what does not
This is the place for the conversation around the work — the question you would otherwise ask three people in a DM, the technique you are not sure generalises, the scope dispute y…
2 comments →Techniques, tooling, dead ends and scope disputes — asked and answered by the people testing and the people fixing. Anyone signed in can post.
This is the place for the conversation around the work — the question you would otherwise ask three people in a DM, the technique you are not sure generalises, the scope dispute y…
2 comments →Every mobile engagement starts with someone telling me the app is pinned so the traffic is not interesting. It is always interesting. Pinning stops a passive observer. It does not…
1 comment →Every team I test has learned to check ownership on GET /orders/:id. Almost none of them check it on the thing the order links to. The pattern I keep finding: The second endpoint…
3 comments →Reported a subdomain takeover on a host that was in scope when I tested. Two days later the scope page no longer lists that wildcard, and triage has closed the report as out of sc…
3 comments →Unpopular opinion after a year of this: my best findings have not come from a scanner. They have come from reading the product's own release notes and asking what had to change un…
2 comments →IMDSv2 has been the default on new instances for a while now, and it genuinely helps. But defaults only apply to what is new. Anything that predates the change, anything restored…
1 comment →Habit that has made me measurably better: as soon as I am reasonably sure something is a bug, I open the report and write the summary. Before the full chain works. Two things happ…
1 comment →Any endpoint that checks a limit and then acts on it is worth two requests fired together. Coupon redemption, withdrawal, invite acceptance, vote casting. The check and the write…
No comments →