top of page
What are CVE, CVSS, CWE scores?
CVE : CVE stands for Common Vulnerabilities and Exposures. In simple words it is a database of all the publicly disclosed cybersecurity...
Nov 19, 20241 min read
Ā
Ā
What is Hashing and its practical examples?
Hashing is the process of converting an input into a hash value, think of it like a secret code that can be easily translated one way,...
Nov 19, 20241 min read
Ā
Ā
What is symmetric and asymmetric encryption and what are the practical uses of the same?
In symmetric encryption, a single key is used which can encrypt plaintext into ciphertext as well as decrypt ciphertext into plaintext....
Nov 19, 20242 min read
Ā
Ā
Approach towards testing a login page, reset password/verify email
Following test cases can be applied on the Login page: Bruteforce the login using cluster bomb attack. (both username / password) Use...
Nov 18, 20241 min read
Ā
Ā
Privilege escalation practical example with mitigations.
In role based applications, a penetration tester should always ensure that he tests for privilege escalation. Let's take an example of a...
Nov 18, 20241 min read
Ā
Ā
How Would You Monitor and Log Cyber Security Events
Monitoring and Logging Security Events is crucial for understanding and responding to potential security threats. In order to Monitor and...
Nov 18, 20241 min read
Ā
Ā
What is vulnerability management? Explain the process
The vulnerability management process involves the objective to detect and mitigate vulnerabilities in the organization. It can be done...
Nov 18, 20244 min read
Ā
Ā
What are the authorization test cases?
1. Insecure Direct Object References (IDOR) : Imagine you have a web application where each user has an account page with a unique number...
Nov 18, 20246 min read
Ā
Ā
How will you test Forgot password functionality ? and what are common issues
Verify that the "Forgot Password" link/button is prominently displayed on the login page. Check that the user is directed to the correct...
Nov 18, 20241 min read
Ā
Ā
What are the tools to learn ethical hacking / Penetration testing?
Following are two tools for beginners that will help in testing websites and networks: Burp SuiteĀ Nmap Nessus OWASP ZAP JohnTheRipper...
Nov 18, 20241 min read
Ā
Ā
bottom of page
