Professionally Evil Insights

Welcome to the Professionally Evil Insights blog by Secure Ideas! In this digital playground, we unravel the complex world of information security with a touch of fun. Our expert-led content ranges from deep-dives into penetration testing to explorations of hardware hacking. Whether you're curious about Secure Ideas or passionate about cybersecurity, this blog is your quick, enlightening, and entertaining guide into the captivating world of information security.

Welcome aboard!

    Waving the White Flag: Why InfoSec should stop caring about HTTPOnly
    As a company that is constantly working with our penetration testing clients on understanding where ...
    Continue Reading
    Proxying HTTPS Traffic with Burp Suite
    The Problem For newcomers to application penetration testing, a reasonably common question is How ...
    Continue Reading
    Getting Started API Penetration Testing with Insomnia
    In our blog series on Better API Penetration Testing with Postman we discussed using Postman as the ...
    Continue Reading
    Better API Penetration Testing with Postman – Part 4
    This is the final part of this series on putting together a better API testing tool-chain. In Part ...
    Continue Reading
    Better API Penetration Testing with Postman – Part 3
    In Part 1 of this series, we got started with Postman and generally creating collections and ...
    Continue Reading
    Better API Penetration Testing with Postman – Part 2
    In Part 1 of this series, I walked through an introduction to Postman, a popular tool for API ...
    Continue Reading
    Better API Penetration Testing with Postman - Part 1
    This is the first of a multi-part series on testing with Postman. I originally planned for it to be ...
    Continue Reading
    Three C-Words of Web App Security: Part 3 – Clickjacking
    This is the third and final part in this three-part series, Three C-Words of Web Application ...
    Continue Reading
    Twelve Days of XSSmas
    This series of daily mini-posts, running from December 12, 2018 to December 24, 2018, is intended ...
    Continue Reading
    Three C-Words of Web App Security: Part 2 – CSRF
    This is the second in a three-part series, Three C-Words of Web Application Security. I wrote a ...
    Continue Reading
    Three C-Words of Web App Security: Part 1 - CORS
    For those less versed in web applications and how they’ve evolved, I wrote a sort of prologue to ...
    Continue Reading

    Never miss a professionally evil update!