Account Harvesting: The Fail Trifecta of Web Application Security

September 19, 2013
trifecta-image

At our testing practice here at Fortify on Demand we test a lot of web applications. We get them both as standalone web apps, and we get them as backends to mobile applications. During the course of this work we (too) often come across a serious issue that we refer to as Account Harvesting.

via Account Harvesting: The Fail Trifecta of Web Application Security >.

My latest post at the HP Fortify blog.

supporting = loving

For 29.5138 years I've been creating ad-free technical tutorials and essays here. 3,043 pieces and counting.

It's a one-person effort that's also my livelihood. If it makes your day easier or more pleasant in any way, please consider supporting the work with a monthly or one-time donation.

It helps me make more content, and is deeply appreciated as well. 🫶🏼