Hello all, I wanted to share some Codename SCNR scripting kung-fu with you. This is something you can use post-scan,...
A story of curiosity, experimentation, development, million euro deal, fraudsters, abandonment and revitalization.
From the inception of the F/OSS Arachni WebAppSec scanner to the opening of Ecsypno’s doors with its flagship product Codename SCNR.
Some very interesting technology was presented a few days ago in the following articles: Following the data: Taint-tracing in the...
New products and their terminology can be daunting, especially when it has to do with architectural things. To take care...
In our previous article we discussed data-flow tracing, i.e. following a piece of data as it travels through the JS...
Frustratingly enough, something fishy is going on with an input you're manually checking but you can't quite put your finger...
Say you need to do a manual pentest on a web application with a lot of client-side code, like a...
So, suppose we're preparing a manual penetration test of a web application; wouldn't it be nice to be able to...