Skip to main content

Explore our questions

1 vote
1 answer
1k views

Implications of accessing a web app via a VPN

26 votes
6 answers
99k views

Is there a way to download a PHP file without it being executed?

4 votes
2 answers
1k views

How to securely store 3rd party API keys directly on web server

2 votes
1 answer
49 views

Is it best practice to expose tenant login configurations via a public GET endpoint for Auth0?

1 vote
1 answer
356 views

How to isolate VMs with internet exposed websites on my home network?

0 votes
1 answer
54 views

Is this an effective scheme to store EEE key on browser client?

1 vote
3 answers
4k views

Prevent URL encoding on form submit

5 votes
1 answer
1k views

Google CSP Evaluator and style-src 'unsafe-inline'

2 votes
1 answer
5k views

Path Truncation not working in PHP while exploiting LFI

2 votes
1 answer
16k views

XSS in <span> where only < and > are encoded

1 vote
1 answer
287 views

How to prevent shopping cart alterations in another tab when paymentintent is already created?

0 votes
1 answer
205 views

Benefit of Parameter Map size validation in web application controller

2 votes
5 answers
1k views

Is OAuth more secure compared to API Keys

3 votes
2 answers
820 views

Benefits of placing WAF reverse proxy/transparent in front of web-based honeypots?

Browse more Questions