Forem

# appsec

Application security topics beyond the web, including mobile and desktop applications.

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Week 8 Challenge: Build an Anti-XSS Escape Encoding Framework in Python

Week 8 Challenge: Build an Anti-XSS Escape Encoding Framework in Python

1
Comments
9 min read
How to Attack a RAG System — and Why Your Security Scanner Won't Catch It

How to Attack a RAG System — and Why Your Security Scanner Won't Catch It

Comments
6 min read
Reducing False Positives in XSS Detection: Designing Confirmation-Based Scanners
Cover image for Reducing False Positives in XSS Detection: Designing Confirmation-Based Scanners

Reducing False Positives in XSS Detection: Designing Confirmation-Based Scanners

Comments
3 min read
Week 6 Quiz Audit XSS Vulnerabilities

Week 6 Quiz Audit XSS Vulnerabilities

1
Comments
17 min read
SAST vs DAST vs (IAST/RASP): Quick AppSec Checklist
Cover image for SAST vs DAST vs (IAST/RASP): Quick AppSec Checklist

SAST vs DAST vs (IAST/RASP): Quick AppSec Checklist

6
Comments 3
1 min read
Two "Medium" Findings That Chain Into Full Infrastructure Compromise
Cover image for Two "Medium" Findings That Chain Into Full Infrastructure Compromise

Two "Medium" Findings That Chain Into Full Infrastructure Compromise

Comments
4 min read
Architectural Asymmetry in Authentication: Part 2 — Risk Before Context

Architectural Asymmetry in Authentication: Part 2 — Risk Before Context

3
Comments
2 min read
What We Learned Securing a SaaS Product with Automated DAST

What We Learned Securing a SaaS Product with Automated DAST

3
Comments
5 min read
Week 6 Scripting Challenge: Build a TLS Certificate Security Validator

Week 6 Scripting Challenge: Build a TLS Certificate Security Validator

Comments
46 min read
Week 7 Scripting Challenge: JWT Token Validation

Week 7 Scripting Challenge: JWT Token Validation

3
Comments
21 min read
Why Modern AppSec Needs Location-Aware Security Testing
Cover image for Why Modern AppSec Needs Location-Aware Security Testing

Why Modern AppSec Needs Location-Aware Security Testing

Comments
4 min read
🧭 Dominando el OWASP Top 10 (Edición 2025): El Plano de Seguridad para la Próxima Generación
Cover image for 🧭 Dominando el OWASP Top 10 (Edición 2025): El Plano de Seguridad para la Próxima Generación

🧭 Dominando el OWASP Top 10 (Edición 2025): El Plano de Seguridad para la Próxima Generación

Comments
4 min read
Fundamentos de AppSec: Protegiendo el Corazón de tus Aplicaciones
Cover image for Fundamentos de AppSec: Protegiendo el Corazón de tus Aplicaciones

Fundamentos de AppSec: Protegiendo el Corazón de tus Aplicaciones

Comments
4 min read
🔐 AppSec desde los Protocolos: Cómo HTTP, Cookies y CORS Definen tu Superficie de Ataque
Cover image for 🔐 AppSec desde los Protocolos: Cómo HTTP, Cookies y CORS Definen tu Superficie de Ataque

🔐 AppSec desde los Protocolos: Cómo HTTP, Cookies y CORS Definen tu Superficie de Ataque

Comments
3 min read
OWASP Cornucopia is publishing it’s darkest secrets!
Cover image for OWASP Cornucopia is publishing it’s darkest secrets!

OWASP Cornucopia is publishing it’s darkest secrets!

5
Comments 1
5 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.