Web App Assessments
Resources Blog

Web App Assessments

Keep up to date with the latest offensive security news, knowledge, and resources.
Self-Propagating XSS: When Widget Frameworks Become Worm Vectors in Multi-Tenant Platforms
Apr 29, 2026

Self-Propagating XSS: When Widget Frameworks Become Worm Vectors in Multi-Tenant Platforms

Discover how a self-propagating XSS worm exploits multi-tenant widget frameworks to autonomously spread across enterprise applications using legitimate API calls, bypassing CSP, evading audit trails, and surviving password changes.
Application Security Testing (AST): Technologies and Best Practices
Nov 27, 2024

Application Security Testing (AST): Technologies and Best Practices

Application security testing involves analyzing and evaluating software applications to identify vulnerabilities.
7 Types of Web Application Testing and Building a Testing Strategy
Nov 12, 2024

7 Types of Web Application Testing and Building a Testing Strategy

Web application testing involves evaluating an application to ensure its functionality, security, and usability meet the required standards before deployment.
WebQL: Using CodeQL To Conduct JavaScript Security Analysis Against Modern Web Applications
Sep 23, 2024

WebQL: Using CodeQL To Conduct JavaScript Security Analysis Against Modern Web Applications

Introducing WebQL, an automated JavaScript analysis tool that leverages CodeQL to identify and exploit vulnerabilities in modern web applications like SPAs and PWAs. By automating the extraction, beautification, and analysis of client-side code, WebQL enhances penetration testing by uncovering security issues obscured by modern development practices.
Introducing Security Testing in QA
Jan 10, 2024

Introducing Security Testing in QA

Fixing these vulnerabilities in production is more expensive than finding and fixing them earlier in the SDLC. One way that organizations can drive down the cost of vulnerability management is by integrating security testing into software quality assurance (QA) testing.
Surfacing the Invisible: A Guide to Web Application Attack Surface Management
Dec 05, 2023

Surfacing the Invisible: A Guide to Web Application Attack Surface Management

The top five web application-specific attack surface management opportunities Sprocket Security sees regularly.
1 2