Security Resources
βK
- Penetration Testing Tricks
- Secure Code Explain
- Application-level Denial of Service (DoS)
- Broken Function Level Authorization
- Clickjacking
- Cross-origin resource sharing (CORS) Misconfiguration
- Cross-Site Request Forgery (CSRF)
- Disabled TLS Certificate Validation
- DOM Cross-Site-Scripting (XSS)
- GraphQL Introspection and Query Depth Abuse
- Hardcoded Credentials
- Host Header Injection
- HSTS not Implemented
- HTTP Response Header Injection (CRLF)
- HttpOnly Flag not set
- Insecure Deserialization in Python (Pickle)
- Insecure direct object references (IDOR)
- Insecure Password Reset – Token Exposed in Response
- Insecure Password Storage
- Insecure Randomness in Security Tokens
- Insufficient Account Lockout Policy
- Java Deserialization
- JWT Authentication Bypass
- LDAP Injection
- LLM01: Prompt Injection
- LLM02: Sensitive Information Disclosure
- LLM03: Supply Chain Vulnerabilities in AI Systems
- LLM04: Data and Model Poisoning
- LLM05: Improper Output Handling
- LLM06: Excessive Agency in AI Agents
- LLM07: System Prompt Leakage
- LLM08: Vector and Embedding Weaknesses
- LLM09: Misinformation and Overreliance
- LLM10: Unbounded Consumption
- Local File Inclusion
- Log Injection
- Mass Assignment
- Missing Content-Security-Policy Header
- Missing Rate Limiting on APIs
- Missing Session Expiry and Logout Invalidation
- NoSQL Injection
- Open Redirection
- Prototype Pollution
- Race Condition (TOCTOU)
- Reflected Cross-Site-Scripting (XSS)
- Regular Expression Denial of Service (ReDoS)
- Remote Code Execution (RCE)
- Remote File Inclusion (RFI)
- Secure Cookie not set
- Sensitive Data Stored in Browser Storage
- Server-Side Request Forgery (SSRF)
- Server-side template injection (SSTI)
- Session Fixation
- SQL Injection
- Stored Cross-Site-Scripting (XSS)
- Unrestricted File Upload
- Use of Weak Cryptographic Algorithms
- Verbose Error Messages and Stack Trace Disclosure
- Weak Password Policy
- XPath Injection
- XXE Injection
- Zip Slip (Insecure Archive Extraction)
- Security Resources
- Vulnerability Explain
- Cross-Site-Scripting (XSS)
- Server-Side Request Forgery (SSRF)
- SQL Injection
- Insecure Direct Object References (IDOR)
- XML External Entity (XXE) Injection
- Remote Code Execution (RCE) and Command Injection
- Local File Inclusion (LFI) and Path Traversal
- Insecure Deserialization
- Open Redirection
- Authentication and JWT Bypass
- Server-Side Template Injection (SSTI)
- Remote File Inclusion (RFI)
- NoSQL Injection
- LDAP and XPath Injection
- CRLF Injection and HTTP Response Splitting
- Host Header Injection
- HTTP Request Smuggling
- Broken Access Control
- Session Fixation
- Clickjacking
- CORS Misconfiguration
- Unrestricted File Upload
- Security Misconfiguration
- Sensitive Data Exposure and Insecure Cryptographic Storage
- Business Logic and Race Condition Vulnerabilities
- GraphQL Security
- API Security and Mass Assignment
- Subdomain Takeover
- Prototype Pollution
- Web Cache Poisoning
- Vulnerable and Outdated Components
- Application-level Denial of Service (DoS)
- AI, LLM, MCP and Agent Security
- AI Security Testing Methodology
- LLM Threat Modeling and Attack Surface Mapping
- Prompt Injection and Jailbreak Testing
- Indirect Prompt Injection and RAG Security Testing
- LLM Data Leakage, Model Extraction and Tenant Isolation
- Insecure LLM Output Handling
- AI Agent Security Testing
- Agent Memory Poisoning, Multi-Agent and Loop Attacks
- MCP Security Testing Guide
- MCP Tool Poisoning, Shadowing and Rug Pull Attacks
- MCP Server Hardening and Supply Chain Security
- AI Security Testing Tools
- Security Roadmap
- FREE – Security Courses/Resources
- Home
- Security Resources
- Penetration Testing Tricks