Professionally Evil Insights
Welcome to the Professionally Evil Insights blog by Secure Ideas! In this digital playground, we unravel the complex world of information security with a touch of fun. Our expert-led content ranges from deep-dives into penetration testing to explorations of hardware hacking. Whether you're curious about Secure Ideas or passionate about cybersecurity, this blog is your quick, enlightening, and entertaining guide into the captivating world of information security.
Welcome aboard!
Professionally Evil Insights listing page
          
          Testing | 
          
          Training | 
          
          QA | 
          
          web penetration testing | 
          
          penetration testing | 
          
          application security | 
          
          OWASP | 
          
          web application security | 
          
          methodology | 
          
          OWASP Top 10
          
        
        
        
          Web applications play a vital role in delivering dynamic content to users. To achieve this, developers often utilize server-side templates, which provide a powerful and consistent way to generate dynamic web pages. However, along with this power comes the risk of Server-Side Template Injection ...
        
        
          Continue Reading
          
            
          
        
      Never miss a Professionally Evil update!
Introducing SamuraiWTF 5.3: A Powerhouse for Web App Pen Testing
              
              
              Testing  | 
              
              Training  | 
              
              samuraiWTF  | 
              
              web penetration testing  | 
              
              application security  | 
              
              professionally evil  | 
              
              Secure Ideas  | 
              
              hacking  | 
              
              OWASP  | 
              
              Project 
              
                
            
            
            
              We are thrilled to announce the release of SamuraiWTF (Web Training Framework) version 5.3! This ...
            
            
              
              Continue Reading
              
              
                
              
            
          ZAPmas Feedback
              
              
              Testing  | 
              
              open source  | 
              
              web penetration testing  | 
              
              OWASP  | 
              
              mobile application  | 
              
              web application security  | 
              
              API 
              
                
            
            
            
              Sometimes Christmas comes early, and in this case for me it was the publication of the Twelve Days ...
            
            
              
              Continue Reading
              
              
                
              
            
          Twelve Days of ZAPmas - Day 11 - ZAP impressions from a Burp user
              It probably seems a bit odd to do this on Day 11 and not at the end of the series, but I have one ...
            
            
              
              Continue Reading
              
              
                
              
            
          Twelve Days of ZAPmas - Day 10 - Manual Web App Testing Unproxied
              Most of the time, proxying the browser doesn’t present any sort of trouble. You should be able to ...
            
            
              
              Continue Reading
              
              
                
              
            
          Twelve Days of ZAPmas - Day 4 - Fuzzing for Injection
              I briefly introduced fuzzing earlier in the series, citing it as the second primitive upon which ...
            
            
              
              Continue Reading
              
              
                
              
            
          Twelve Days of ZAPmas - Day 1 - Setting Up ZAP
              This holiday season, I’m going to run down some of the ins and outs of working with OWASP Zed ...
            
            
              
              Continue Reading
              
              
                
              
            
          Coming Soon - Twelve Days of ZAPmas
              In December of 2018, I published a twelve-day series of cross-site scripting tips, tricks, and ...
            
            
              
              Continue Reading
              
              
                
              
            
          Quick Bites Ep 4 - Let's Talk About SSRF, Baby!
              Let’s talk about you and (application) secur-i-ty! Let’s talk about all the good things and the bad ...
            
            
              
              Continue Reading
              
              
                
              
            
          ViewState XSS: What's the Deal?
              
              
              Testing  | 
              
              developers  | 
              
              QA  | 
              
              security  | 
              
              testers  | 
              
              web penetration testing 
              
                
            
            
            
              As penetration testers, there are many different technologies that we have to be familiar with. The ...
            
            
              
              Continue Reading
              
              
                
              
            
          Testing ASP.Net WebForms: Request Method Validation
              As a professional penetration tester, there are many features of an application that are similar ...
            
            
              
              Continue Reading
              
              
                
              
            
          SamuraiWTF 2.0? What happened to 1.0?
              
              
              security  | 
              
              2.0  | 
              
              open source  | 
              
              testers  | 
              
              releases  | 
              
              web penetration testing 
              
                
            
            
            
              So the SamuraiWTF project have released the first few release candidates for the formal 2.0 ...
            
            
              
              Continue Reading
              
              
                
              
            
          
  Has contents: true
  
    Total pages: 1
    Current page: 1