Contact us: info@tenendo.com

JNDI injection. JDBC

Preventing JNDI injection vulnerabilities by using a source code review is always a good idea.

Insecure deserialization

Insecure deserialization is when user-controllable data is deserialised by a website. This potentially enables an attacker to manipulate serialised ob…

Avoiding injection vulnerabilities

Injection attacks refer to a broad class of attack vectors. In an injection attack, an attacker supplies untrusted input to a program. This input gets…

Avoiding XSS injection vulnerabilities

In this section, we'll describe some general principles for preventing cross-site scripting vulnerabilities and ways of using various common technolog…

Avoiding Templates injection

The best way to prevent server-side template injection is to not allow any users to modify or submit new templates.

Avoiding other injections

Secure coding practices prescribe that spring expressions using dynamic values should be avoided.

Internal Adversary Simulation Case

The adversary simulation activity helped the client identify and remediate multiple issues with the on-premise infrastructure and vulnerabilities, cal…