Maltek Solutions
  • Home
  • Blog
Sign in Subscribe

findings

Findings Series: Weak Password Policy

Findings Series: Weak Password Policy

Contents * Description * Classification * Examples * Remediation * References Description Applications and environments are often only as secure as their weakest user account password. To prevent initial compromise from occurring through account takeover, it is common to enforce complexity, length, and renewal requirements for passwords across an application or network. When these requirements
Graham O'Donnell, Mike Lisi 19 Oct 2023
Findings Series: Cross-Site Scripting (XSS)

Findings Series: Cross-Site Scripting (XSS)

Contents * Description * Classification * Examples * Remediation * References Description Cross-site scripting (XSS) is a code injection attack caused by improper input sanitization of user input in web applications. Attackers submit malicious input to a web application and run JavaScript functions that can dump cookies, hijack sessions, or even log keystrokes from a
Graham O'Donnell, Mike Lisi, Brodie Davis 12 Oct 2023
Findings Series: User Enumeration

Findings Series: User Enumeration

Contents * Description * Classification * Examples * Remediation * References Description User Enumeration occurs on web applications when there are discrepancies in responses received from the application when sending a valid versus invalid username. User enumeration is typically found in authentication and password reset processes. When an authentication attempt on a web application fails,
Graham O'Donnell, Mike Lisi 03 Oct 2023

Subscribe to Maltek Solutions

Don't miss out on the latest news. Sign up now to get access to the library of members-only articles.
  • Data & Privacy
  • Contact
©2024 Maltek Solutions, LLC