Platform Services Our Work Blog Docs Contact
Live Demo
TOPICS & CATEGORIES

Articles by Category

methodology

5 Articles
Understanding Pentesting: Why It's Essential for Securing Your Business
Understanding Pentesting: Why It's Essential for Securing Your Business

What is Penetration Testing: A “pen-test,” also referred to as a penetration test, simulates a cyber-attack on a computer system, network, or web application...

Danish Bhat
Danish Bhat Mar 14, 2023
When to Conduct a Penetration Test: Timing is Key
When to Conduct a Penetration Test: Timing is Key

Organizations use penetration testing, also known as “pen testing” or “ethical hacking” as a crucial security measure to find and fix security vulnerabilities in...

Waseem Lone
Waseem Lone Mar 8, 2023
Understanding Penetration Testing: Types, Methodology, and Best Practices
Understanding Penetration Testing: Types, Methodology, and Best Practices

introduction Penetration testing, also referred to as “pentesting,” is a technique for assessing the security of a computer network, web application, or other system...

Danish Bhat
Danish Bhat Feb 27, 2023
Understanding the Process: A Guide to Penetration Testing Phases
Understanding the Process: A Guide to Penetration Testing Phases

Penetration testing, also referred to as “pen testing” or “ethical hacking,” is a technique for assessing a computer system’s, network’s, or web application’s security...

Waseem Lone
Waseem Lone Feb 23, 2023
SNAPSEC - Our Methodology
SNAPSEC - Our Methodology

As a cybersecurity and penetration testing company, it is important for us to have a clear and thorough methodology in place to ensure the...

Snapsec Team
Snapsec Team Mar 1, 2020

VAPT

6 Articles
Importance of Regular Security Assessments
Importance of Regular Security Assessments

Protecting sensitive data and systems has become a top priority for organisations of all sizes in today’s interconnected world. It is crucial to routinely...

Danish Bhat
Danish Bhat Apr 5, 2023
Understanding Pentesting: Why It's Essential for Securing Your Business
Understanding Pentesting: Why It's Essential for Securing Your Business

What is Penetration Testing: A “pen-test,” also referred to as a penetration test, simulates a cyber-attack on a computer system, network, or web application...

Danish Bhat
Danish Bhat Mar 14, 2023
When to Conduct a Penetration Test: Timing is Key
When to Conduct a Penetration Test: Timing is Key

Organizations use penetration testing, also known as “pen testing” or “ethical hacking” as a crucial security measure to find and fix security vulnerabilities in...

Waseem Lone
Waseem Lone Mar 8, 2023
Understanding Penetration Testing: Types, Methodology, and Best Practices
Understanding Penetration Testing: Types, Methodology, and Best Practices

introduction Penetration testing, also referred to as “pentesting,” is a technique for assessing the security of a computer network, web application, or other system...

Danish Bhat
Danish Bhat Feb 27, 2023
Understanding the Process: A Guide to Penetration Testing Phases
Understanding the Process: A Guide to Penetration Testing Phases

Penetration testing, also referred to as “pen testing” or “ethical hacking,” is a technique for assessing a computer system’s, network’s, or web application’s security...

Waseem Lone
Waseem Lone Feb 23, 2023
SNAPSEC - Our Methodology
SNAPSEC - Our Methodology

As a cybersecurity and penetration testing company, it is important for us to have a clear and thorough methodology in place to ensure the...

Snapsec Team
Snapsec Team Mar 1, 2020

cyberattacks

4 Articles
regreSSHion: Unauthenticated Remote Code Execution Vulnerability in OpenSSH Server
regreSSHion: Unauthenticated Remote Code Execution Vulnerability in OpenSSH Server

The Threat Research Unit at qualys has found a critical Remote Unauthenticated Code Execution (RCE) vulnerability in the OpenSSH server (sshd) on glibc-based Linux...

Snapsec Team
Snapsec Team Jul 2, 2024
AI in cyberattack lifecycle
AI in cyberattack lifecycle

Network defenders and the cybersecurity industry must move their focus from the network’s edges and endpoints to the network’s interior. Inside the network, IT...

Mubashir Paray
Mubashir Paray Oct 31, 2022
AI in Cybersecurity
AI in Cybersecurity

Not only has the number of cyberattacks increased significantly over the last few decades, but they have also become more sophisticated. As a result,...

Snapsec Team
Snapsec Team Oct 31, 2022
Why Are Small Businesses Interesting Targets For Cybercriminals
Why Are Small Businesses Interesting Targets For Cybercriminals

You might think great businesses are more threatened by data breaches and cyber attacks than small businesses. They do, but that’s not the case...

Snapsec Team
Snapsec Team Feb 26, 2021

businesses

1 Articles
Why Are Small Businesses Interesting Targets For Cybercriminals
Why Are Small Businesses Interesting Targets For Cybercriminals

You might think great businesses are more threatened by data breaches and cyber attacks than small businesses. They do, but that’s not the case...

Snapsec Team
Snapsec Team Feb 26, 2021

article

8 Articles
We Hacked Larksuite For 1 month and Here is what we found
We Hacked Larksuite For 1 month and Here is what we found

Almost a year back in March 2020 shuffling our private invites stock to crash into a program worthy of our time and excitement. In...

Snapsec Team
Snapsec Team Sep 4, 2022
How did we Found Log4shell on Agorapulse
How did we Found Log4shell on Agorapulse

Log4j is a logging framework for Java applications. It is a popular choice for developers looking for a simple and flexible logging solution. However,...

Snapsec Team
Snapsec Team Sep 1, 2022
Attacking Rate Limit Protection in Modern Web Apps
Attacking Rate Limit Protection in Modern Web Apps

What is rate-limiting? Well, Rate limiting is a process of limiting requests received by the networking device. It is used to control network traffic....

Danish Bhat
Danish Bhat Mar 9, 2022
Attacking 2FA in Modern Web Apps
Attacking 2FA in Modern Web Apps

You might be familiar with the annoying OTPS or other authentication tokens delivered right after you log into your favorite site. This article will...

Danish Bhat
Danish Bhat Mar 7, 2022
Attacking CORS Misconfigurations in Modern Web Apps
Attacking CORS Misconfigurations in Modern Web Apps

If you are a developer, you already know that it’s nearly impossible to keep every resource in one place. It’s expensive (because everything has...

Adnan Shah
Adnan Shah Mar 1, 2022
A Hacker Mindset
A Hacker Mindset

Whenever the word hacker strikes your ears your mind will always conjure up a picture of a hoodie wearing computer genius with multiple screens...

Mubashir Paray
Mubashir Paray Feb 26, 2022
Abusing Business Logic of an Application to create backdoor in a form APP
Abusing Business Logic of an Application to create backdoor in a form APP

Working with a target having various access roles and functionalities always gives us goosebumps. This time it was a design flaw in the application...

Imran Parray
Imran Parray Jan 1, 2022
Attacking Access Control Models in Modern Web Apps
Attacking Access Control Models in Modern Web Apps

So far you may have come across various web applications where you were able to invite members with limited access to the information within...

Imran Parray
Imran Parray Sep 25, 2021

broken-access-control

4 Articles
We Hacked Larksuite For 1 month and Here is what we found
We Hacked Larksuite For 1 month and Here is what we found

Almost a year back in March 2020 shuffling our private invites stock to crash into a program worthy of our time and excitement. In...

Snapsec Team
Snapsec Team Sep 4, 2022
Attacking Business Logic issues in Modern Web Apps
Attacking Business Logic issues in Modern Web Apps

The complexity of the modern applications has increased exponentially in the past decade. Unfortunately, this has also increased the attacker surface and hence increased...

Abdul Basit
Abdul Basit Jan 20, 2022
Abusing Business Logic of an Application to create backdoor in a form APP
Abusing Business Logic of an Application to create backdoor in a form APP

Working with a target having various access roles and functionalities always gives us goosebumps. This time it was a design flaw in the application...

Imran Parray
Imran Parray Jan 1, 2022
Attacking Access Control Models in Modern Web Apps
Attacking Access Control Models in Modern Web Apps

So far you may have come across various web applications where you were able to invite members with limited access to the information within...

Imran Parray
Imran Parray Sep 25, 2021

general

6 Articles
10 reasons your Orginisation needs a penetration testing
10 reasons your Orginisation needs a penetration testing

A penetration test, colloquially known as a pen test or ethical hacking, is an authorized simulated cyberattack on a computer system, performed to evaluate...

Imran Parray
Imran Parray Apr 16, 2022
Attacking File Uploads in Modern Web Applications
Attacking File Uploads in Modern Web Applications

File sharing or simple file upload functionality is a widely used feature in web apps now a days. Any misconfiguration in this one feature...

Adnan Shah
Adnan Shah Apr 11, 2022
Spring4Shell: Everything you need to know.
Spring4Shell: Everything you need to know.

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific...

Imran Parray
Imran Parray Apr 2, 2022
Top 5 Cyber Attacks Of 2021
Top 5 Cyber Attacks Of 2021

Due to the growth of technologies around the world and their effects to our privacy, data security has also been an issue. In terms...

Waseem Lone
Waseem Lone Mar 26, 2022
Continuous Security Testing - Snapsec
Continuous Security Testing - Snapsec

According to Security Researchers, every code update/push to your production server or application may bring new vulnerabilities into action. Because every time a code...

Imran Parray
Imran Parray Mar 10, 2022
How data breaches effects your business and brand value
How data breaches effects your business and brand value

A data breach is a revenue-killing monster that no business wants to deal with. The cost of that nightmare starts right away and doesn’t...

Imran Parray
Imran Parray Jan 18, 2022

writeup

1 Articles
Attacking Business Logic issues in Modern Web Apps
Attacking Business Logic issues in Modern Web Apps

The complexity of the modern applications has increased exponentially in the past decade. Unfortunately, this has also increased the attacker surface and hence increased...

Abdul Basit
Abdul Basit Jan 20, 2022

mindset

1 Articles
A Hacker Mindset
A Hacker Mindset

Whenever the word hacker strikes your ears your mind will always conjure up a picture of a hoodie wearing computer genius with multiple screens...

Mubashir Paray
Mubashir Paray Feb 26, 2022

cors

1 Articles
Attacking CORS Misconfigurations in Modern Web Apps
Attacking CORS Misconfigurations in Modern Web Apps

If you are a developer, you already know that it’s nearly impossible to keep every resource in one place. It’s expensive (because everything has...

Adnan Shah
Adnan Shah Mar 1, 2022

2FA

1 Articles
Attacking 2FA in Modern Web Apps
Attacking 2FA in Modern Web Apps

You might be familiar with the annoying OTPS or other authentication tokens delivered right after you log into your favorite site. This article will...

Danish Bhat
Danish Bhat Mar 7, 2022

Attacking-Modern-Web-Apps

1 Articles
Attacking Rate Limit Protection in Modern Web Apps
Attacking Rate Limit Protection in Modern Web Apps

What is rate-limiting? Well, Rate limiting is a process of limiting requests received by the networking device. It is used to control network traffic....

Danish Bhat
Danish Bhat Mar 9, 2022

blog-post

3 Articles
Attacking File Uploads in Modern Web Applications
Attacking File Uploads in Modern Web Applications

File sharing or simple file upload functionality is a widely used feature in web apps now a days. Any misconfiguration in this one feature...

Adnan Shah
Adnan Shah Apr 11, 2022
Top 5 Cyber Attacks Of 2021
Top 5 Cyber Attacks Of 2021

Due to the growth of technologies around the world and their effects to our privacy, data security has also been an issue. In terms...

Waseem Lone
Waseem Lone Mar 26, 2022
Continuous Security Testing - Snapsec
Continuous Security Testing - Snapsec

According to Security Researchers, every code update/push to your production server or application may bring new vulnerabilities into action. Because every time a code...

Imran Parray
Imran Parray Mar 10, 2022

Continuous-security

1 Articles
Continuous Security Testing - Snapsec
Continuous Security Testing - Snapsec

According to Security Researchers, every code update/push to your production server or application may bring new vulnerabilities into action. Because every time a code...

Imran Parray
Imran Parray Mar 10, 2022

data-breaches

2 Articles
GoDaddy: Hackers stole customer information, installed malware in multi-year breach
GoDaddy: Hackers stole customer information, installed malware in multi-year breach

Web hosting provider GoDaddy recently disclosed a multi-year(possibly since 2020) security breach, which enabled attackers to install malware and steal source code related to...

Adnan Shah
Adnan Shah Feb 21, 2023
Top 5 Cyber Attacks Of 2021
Top 5 Cyber Attacks Of 2021

Due to the growth of technologies around the world and their effects to our privacy, data security has also been an issue. In terms...

Waseem Lone
Waseem Lone Mar 26, 2022

spring4shell

1 Articles
Spring4Shell: Everything you need to know.
Spring4Shell: Everything you need to know.

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific...

Imran Parray
Imran Parray Apr 2, 2022

attacking-modern-webapps

1 Articles
Attacking Authentication in Modern Web Applications
Attacking Authentication in Modern Web Applications

Authentication issues are easy to understand however they can sometimes prove the most critical ones because of the fact that authentication is the core...

Mubashir Paray
Mubashir Paray Apr 6, 2022

authentication

1 Articles
Attacking Authentication in Modern Web Applications
Attacking Authentication in Modern Web Applications

Authentication issues are easy to understand however they can sometimes prove the most critical ones because of the fact that authentication is the core...

Mubashir Paray
Mubashir Paray Apr 6, 2022

imran

2 Articles
Security Simplified - Open Redirect [Server Side]
Security Simplified - Open Redirect [Server Side]

Open redirection vulnerabilities arise when an application incorporates user-controllable data into the target of a redirection in an unsafe way. An attacker can construct...

Imran Parray
Imran Parray Oct 1, 2022
Attacking File Uploads in Modern Web Applications
Attacking File Uploads in Modern Web Applications

File sharing or simple file upload functionality is a widely used feature in web apps now a days. Any misconfiguration in this one feature...

Adnan Shah
Adnan Shah Apr 11, 2022

pentesting

1 Articles
10 reasons your Orginisation needs a penetration testing
10 reasons your Orginisation needs a penetration testing

A penetration test, colloquially known as a pen test or ethical hacking, is an authorized simulated cyberattack on a computer system, performed to evaluate...

Imran Parray
Imran Parray Apr 16, 2022

blog

1 Articles
10 reasons your Orginisation needs a penetration testing
10 reasons your Orginisation needs a penetration testing

A penetration test, colloquially known as a pen test or ethical hacking, is an authorized simulated cyberattack on a computer system, performed to evaluate...

Imran Parray
Imran Parray Apr 16, 2022

Security-Simplified

1 Articles
Security Simplified - Learn How To Find, Exploit and Mitigate Web Vulnerabilites.
Security Simplified - Learn How To Find, Exploit and Mitigate Web Vulnerabilites.

During our subtle technical experience of 7 years in Application security Industry we have often noticed that majority of the people who are into...

Imran Parray
Imran Parray May 30, 2022

web-sec

1 Articles
Security Simplified - Learn How To Find, Exploit and Mitigate Web Vulnerabilites.
Security Simplified - Learn How To Find, Exploit and Mitigate Web Vulnerabilites.

During our subtle technical experience of 7 years in Application security Industry we have often noticed that majority of the people who are into...

Imran Parray
Imran Parray May 30, 2022

dev

1 Articles
Security Simplified - Learn How To Find, Exploit and Mitigate Web Vulnerabilites.
Security Simplified - Learn How To Find, Exploit and Mitigate Web Vulnerabilites.

During our subtle technical experience of 7 years in Application security Industry we have often noticed that majority of the people who are into...

Imran Parray
Imran Parray May 30, 2022

XSS

2 Articles
Finding Multiple Security Issues on Agorapulse
Finding Multiple Security Issues on Agorapulse

Agorapulse provides everything an organization could possibly need for social media marketing, monitoring, and management. Agorapulse is a full-featured social media management platform. Some...

Snapsec Team
Snapsec Team Oct 24, 2022
Security Simplified - Reflected XSS
Security Simplified - Reflected XSS

Cross-site scripting (also known as XSS) is a web security vulnerability that allows an attacker to compromise the interactions that users have with a...

Imran Parray
Imran Parray May 31, 2022

security-simplified

1 Articles
Security Simplified - Reflected XSS
Security Simplified - Reflected XSS

Cross-site scripting (also known as XSS) is a web security vulnerability that allows an attacker to compromise the interactions that users have with a...

Imran Parray
Imran Parray May 31, 2022

tutorial

2 Articles
Security Simplified - Open Redirect [Server Side]
Security Simplified - Open Redirect [Server Side]

Open redirection vulnerabilities arise when an application incorporates user-controllable data into the target of a redirection in an unsafe way. An attacker can construct...

Imran Parray
Imran Parray Oct 1, 2022
Security Simplified - SQL Injection
Security Simplified - SQL Injection

What is SQL Injection SQL injection is a web security vulnerability that allows an attacker to interfere with the queries that an application makes...

Mubashir Paray
Mubashir Paray Jun 25, 2022

security-explained

1 Articles
Security Simplified - SQL Injection
Security Simplified - SQL Injection

What is SQL Injection SQL injection is a web security vulnerability that allows an attacker to interfere with the queries that an application makes...

Mubashir Paray
Mubashir Paray Jun 25, 2022

log4shell

1 Articles
How did we Found Log4shell on Agorapulse
How did we Found Log4shell on Agorapulse

Log4j is a logging framework for Java applications. It is a popular choice for developers looking for a simple and flexible logging solution. However,...

Snapsec Team
Snapsec Team Sep 1, 2022

uber

2 Articles
Lastpass Breach - Everything you need to know
Lastpass Breach - Everything you need to know

One of the largest online password manager with Over 25 million users as of 2020. LastPass suffered a massive data breach recently. The data...

Adnan Shah
Adnan Shah Dec 27, 2022
Uber Breach - Few Security Takeaways
Uber Breach - Few Security Takeaways

On 15 September, UBER acknowledged that it was responding to a “cybersecurity incident” and had contacted law authorities about the hack. An individual claiming...

Snapsec Team
Snapsec Team Sep 20, 2022

Privilege-escalation

1 Articles
Finding Multiple Security Issues on Agorapulse
Finding Multiple Security Issues on Agorapulse

Agorapulse provides everything an organization could possibly need for social media marketing, monitoring, and management. Agorapulse is a full-featured social media management platform. Some...

Snapsec Team
Snapsec Team Oct 24, 2022

Log4Shell

1 Articles
Finding Multiple Security Issues on Agorapulse
Finding Multiple Security Issues on Agorapulse

Agorapulse provides everything an organization could possibly need for social media marketing, monitoring, and management. Agorapulse is a full-featured social media management platform. Some...

Snapsec Team
Snapsec Team Oct 24, 2022

AI

2 Articles
AI in cyberattack lifecycle
AI in cyberattack lifecycle

Network defenders and the cybersecurity industry must move their focus from the network’s edges and endpoints to the network’s interior. Inside the network, IT...

Mubashir Paray
Mubashir Paray Oct 31, 2022
AI in Cybersecurity
AI in Cybersecurity

Not only has the number of cyberattacks increased significantly over the last few decades, but they have also become more sophisticated. As a result,...

Snapsec Team
Snapsec Team Oct 31, 2022

cybersecurity

4 Articles
CSRF Attacks - How to Find, Exploit and fix them
CSRF Attacks - How to Find, Exploit and fix them

Cross-site request forgery (also known as CSRF) is a web security vulnerability that allows an attacker to induce users to perform actions that they...

Snapsec Team
Snapsec Team Sep 21, 2023
The Future of Tech in Saudi Arabia: Maximizing Opportunities, Minimizing Risks
The Future of Tech in Saudi Arabia: Maximizing Opportunities, Minimizing Risks

The rapid growth of technology in Saudi Arabia is a double-edged sword. On one hand, it has the potential to bring new opportunities and...

Imran Parray
Imran Parray Sep 10, 2023
Local File Inclusion - Explained
Local File Inclusion - Explained

LFI stands for Local File Inclusion. LFI vulnerability in web app can trick application into loading arbitrary files from the server that are restricted....

Adnan Shah
Adnan Shah Mar 3, 2023
GoDaddy: Hackers stole customer information, installed malware in multi-year breach
GoDaddy: Hackers stole customer information, installed malware in multi-year breach

Web hosting provider GoDaddy recently disclosed a multi-year(possibly since 2020) security breach, which enabled attackers to install malware and steal source code related to...

Adnan Shah
Adnan Shah Feb 21, 2023

Pentest

1 Articles
Importance of Regular Security Assessments
Importance of Regular Security Assessments

Protecting sensitive data and systems has become a top priority for organisations of all sizes in today’s interconnected world. It is crucial to routinely...

Danish Bhat
Danish Bhat Apr 5, 2023

vulnerability-management

2 Articles
From Detection to Resolution: Streamlining the Vulnerability Management Lifecycle
From Detection to Resolution: Streamlining the Vulnerability Management Lifecycle

Vulnerabilities are inevitable in today’s digital landscape, making effective vulnerability management a critical aspect of maintaining a secure environment. From the moment a vulnerability...

Snapsec Team
Snapsec Team Aug 1, 2023
5 key features of our Vulnerability management system
5 key features of our Vulnerability management system

The Importance of Effective Vulnerability Management

Snapsec Team
Snapsec Team Jul 5, 2023

csm

1 Articles
5 key features of our Vulnerability management system
5 key features of our Vulnerability management system

The Importance of Effective Vulnerability Management

Snapsec Team
Snapsec Team Jul 5, 2023

CSM

1 Articles
From Detection to Resolution: Streamlining the Vulnerability Management Lifecycle
From Detection to Resolution: Streamlining the Vulnerability Management Lifecycle

Vulnerabilities are inevitable in today’s digital landscape, making effective vulnerability management a critical aspect of maintaining a secure environment. From the moment a vulnerability...

Snapsec Team
Snapsec Team Aug 1, 2023

saudi-arabia

1 Articles
The Future of Tech in Saudi Arabia: Maximizing Opportunities, Minimizing Risks
The Future of Tech in Saudi Arabia: Maximizing Opportunities, Minimizing Risks

The rapid growth of technology in Saudi Arabia is a double-edged sword. On one hand, it has the potential to bring new opportunities and...

Imran Parray
Imran Parray Sep 10, 2023

csrf

1 Articles
CSRF Attacks - How to Find, Exploit and fix them
CSRF Attacks - How to Find, Exploit and fix them

Cross-site request forgery (also known as CSRF) is a web security vulnerability that allows an attacker to induce users to perform actions that they...

Snapsec Team
Snapsec Team Sep 21, 2023

web-attacks

1 Articles
CSRF Attacks - How to Find, Exploit and fix them
CSRF Attacks - How to Find, Exploit and fix them

Cross-site request forgery (also known as CSRF) is a web security vulnerability that allows an attacker to induce users to perform actions that they...

Snapsec Team
Snapsec Team Sep 21, 2023

ssh

1 Articles
regreSSHion: Unauthenticated Remote Code Execution Vulnerability in OpenSSH Server
regreSSHion: Unauthenticated Remote Code Execution Vulnerability in OpenSSH Server

The Threat Research Unit at qualys has found a critical Remote Unauthenticated Code Execution (RCE) vulnerability in the OpenSSH server (sshd) on glibc-based Linux...

Snapsec Team
Snapsec Team Jul 2, 2024

0day

1 Articles
regreSSHion: Unauthenticated Remote Code Execution Vulnerability in OpenSSH Server
regreSSHion: Unauthenticated Remote Code Execution Vulnerability in OpenSSH Server

The Threat Research Unit at qualys has found a critical Remote Unauthenticated Code Execution (RCE) vulnerability in the OpenSSH server (sshd) on glibc-based Linux...

Snapsec Team
Snapsec Team Jul 2, 2024
Interactive Platform

See Snapsec in Action — Try the Live Suite

Discover how Snapsec continuously monitors attack surfaces, automates vulnerability management, and streamlines application security in real-time.

Instant Sandbox Attack Surface Discovery Continuous Scanning