Blog

brackish

OWASP Top Ten – Injection

OWASP Top Ten – Injection Today’s entry in the OWASP Top Ten series is Injection. If we are going to call a vulnerability a classic,

Read More »

TutorTrac Multiple Stored XSS

TutorTrac Multiple Stored XSS Brackish researchers found authenticated stored cross-site-scripting (XSS) in TutorTrac version <= 4.2.170210. An authenticated attacker could utilize crafted input in several

Read More »

Credentials Gone Wild

If there is one thing that Brackish testers have seen a lot lately, it is default credentials. In five out of the last five engagements

Read More »