September 12, 2018

Handy tool to check CSP

https://blog.thomasorlita.cz/vulns/google-csp-evaluator/

Useful to defenders and attackers (bug bounty hunters?) alike.

September 1, 2018

Sec tools: Should you buy or build?

Are you contemplating buying a security blinky box that will solve your problem? Could the team build something similar from scratch or re-using open source components? Valid dilemma.

This should help. Especially the analysis of steps #2, #3 and #4.