ethicalhacker.ro logoethicalhacker.ro

Blog

Security insights, pentest techniques, and research.

Why CSP + Nonces Stop 90% of XSS in Modern Apps

2024-11
XSSCSPWeb Security

Content Security Policy with per-request nonces is the single highest-leverage XSS defence available to web apps today. Here is how it works and why scanners keep missing it.

Read more →

Abusing Misconfigured S3 Bucket Policies

2024-10
CloudAWSS3Pentest

S3 bucket misconfigurations are still among the most impactful cloud findings. This post walks through the most common policy mistakes, how attackers chain them, and what a correct policy looks like.

Read more →

From CVE to RCA: Pentest Reports That Drive Change

2024-09
ReportingPentest Methodology

Most pentest reports end up in a drawer. The ones that drive real remediation share a common structure: they connect technical findings to business risk and give developers something actionable to ship.

Read more →
Blog | ethicalhacker.ro