SecureLayer7

1.6K posts

SecureLayer7 banner
SecureLayer7

SecureLayer7

@SecureLayer7

Quick, reliable Pentest as a Service, API Security Scanning, and Offensive Security to uncover vulnerabilities and strengthen security posture

Austin, Tx 参加日 Eylül 2014
20 フォロー中2.5K フォロワー
SecureLayer7
SecureLayer7@SecureLayer7·
As a pentest engagement leader, how do you usually react when you get a bloated, noisy pentest report?
English
1
0
1
244
SecureLayer7
SecureLayer7@SecureLayer7·
Join cybersecurity leaders for a fireside chat on spotting false positives in pentest reports, prioritizing real risks, and improving remediation workflows. Who Should Attend: CISOs, Security leaders, pentesters, and security teams. Register here - us06web.zoom.us/webinar/regist…
English
0
0
0
115
SecureLayer7
SecureLayer7@SecureLayer7·
We will continue expanding this list based on our experiences at SL7 and contributions from others until January 31, 2025, after which the list will be finalized. Feel free to submit pull requests!
English
0
0
1
80
SecureLayer7
SecureLayer7@SecureLayer7·
Updated: Top 2025 vulnerabilities you shouldn’t accept in a pentest report [DRAFT] Introducing three different sections: 1. Minor Infrastructure Information Exposure 2. Reporting Unexploitable Vulnerabilities 3. Problems Without Security-Related Impact github.com/securelayer7/n…
English
1
0
1
158
SecureLayer7 がリツイート
Seasides
Seasides@seasides_conf·
We extend our heartfelt gratitude to SecureLayer7 for being a Gold Sponsor of the Seasides Conference! Your invaluable support plays a vital role in fostering knowledge-sharing within the security community. Thank you, SecureLayer7 Sandeep Kamble , for championing this mission
Seasides tweet media
English
3
15
21
429
SecureLayer7
SecureLayer7@SecureLayer7·
@0xTib3rius Valid point - context is critical. and updated with this details Some browsers (Chrome) delay or throttle background requests in inactive tabs meaning keep-alive signals might not be sent on time. This could lead the session to persist longer than expected even with a timeout set
English
0
0
0
8
Tib3rius
Tib3rius@0xTib3rius·
Some of these are good. Some are questionable. There's a lot that really require context. For example, saying that long session timeouts "isn't a vulnerability; it's a design decision". Well, it *can* be a design decision. What if it's not? What if the developer used a bad default value? Pentesters shouldn't make assumptions about these things. Customers are perfectly capable of accepting the risk of findings in a report.
SecureLayer7@SecureLayer7

Top 2025 vulnerabilities you shouldn’t accept in a pentest report. Here is list! Looking for more such scenarios. github.com/securelayer7/n…

English
2
1
12
4.1K
SecureLayer7
SecureLayer7@SecureLayer7·
@albinowax You make a valid point! While a strict CSP can significantly reduce the risk of XSS, it isn't a foolproof solution. Especially with creative exploitation techniques like JSONP abuse, improperly sanitized data in inline event handlers, or compromised third-party scripts. REMOVED.
English
0
0
1
67
SecureLayer7
SecureLayer7@SecureLayer7·
We are expanding out project management team, adding more folks to manage the North American and Indian customer. Interested? Send us CV at job@securelayer7.net
English
0
0
0
117
SecureLayer7 がリツイート
Sandeep Kamble
Sandeep Kamble@SandeepL337·
PHP symlink exploit, anyone? 😅 Was checking PTaaS platform & saw one of our pentesters found an exploit allowing access to other tenants sensitive data on cloud hosting! linkedin.com/feed/update/ur…
English
0
2
3
469