AppCheck Security Blog

Introduction to... Deserialisation Vulnerabilities

Deserialisation vulnerabilities were introduced to the OWASP Top 10 in 2017, nudging out Cross-Site Request Forgery (CSRF), based on the increasing prevalence and impact of deserialisation attacks reported in an industry survey. But what are deserialisation vulnerabilities, how do they occur, why did the threat from them suddenly increase in recent years, and what can be done to protect your organisation from this vulnerability?

read more

Introduction to... Deserialisation Vulnerabilities

Deserialisation vulnerabilities were introduced to the OWASP Top 10 in 2017, nudging out Cross-Site Request Forgery (CSRF), based on the increasing prevalence and impact of deserialisation attacks reported in an industry survey. But what are deserialisation vulnerabilities, how do they occur, why did the threat from them suddenly increase in recent years, and what can be done to protect your organisation from this vulnerability?

Read more

Tales of Terror [Readers Beware]

Read more

Server-Side Request Forgery (SSRF) & the Cloud Resurgence

So what exactly is SSRF? How does it work, why is it more prevalent in 2020, and how can we protect against it?

Read more

Web App Security: Why So Hard?

Action... Mystery... Intrigue...
What does AppCheck's latest have in store? Click for more...

Read more

A COVID Christmas: Protecting Your Critical Ecommerce Assets

In this article we will address the current situation, how hackers can exploit your websites, what you can do to protect yourself and where AppCheck comes in as an automated penetration testing tool to make sure you’re not leaving yourself vulnerable.

Read more

Webinar: Why Web Application Security Should be Job Number One

We will provide a high-level overview of why web app security is important with case studies into recent hacks before looking at how you as a business can help mitigate these attacks with practical advice.

Read more

WebSocket Security - Cross-Site Hijacking (CSWSH)

In this article we are going to take a look at one of the newer technologies used in modern web applications, the “WebSockets” that were standardized by the Internet Engineering Task Force (IETF) in 2011.

Read more

Insecure Direct Object Reference

Insecure Direct Object Reference, is a common web application vulnerability that allows an attacker to bypass mis-configured logical access controls and access sensitive data.
In this article, we will step through looking at what IDOR is, how it can often be introduced as a vulnerability, how an attacker is able to exploit it, and how to defend against it.

Read more

CyberWhite Interviews our Head of Development

CyberWhite sat down with our Head of Development, Graham Bacon, to discuss all things AppCheck.

Read more

Single Page Applications (SPA)

Essentially a SPA is a client-side dynamic web application that makes a full HTML page load initially but thereafter responds to all DOM events initiated by actions such as clicking on links by dynamically rewriting the current web page, rather than the default method in a traditional “multi-page” web application of the browser loading entire new pages.

Read more