Application Security Guides

In-depth references for the vulnerability classes I work with most, each covering attack surface, exploitation, and defense. Kept current with CVEs through 2026.

🎯 Complete Security Guide Hubs

Comprehensive Guide Collections

Each hub provides curated learning paths, cross-references, and comprehensive coverage of entire security domains.


Core Vulnerability Guides

🎯 Comprehensive XSS Guide

Context-aware payloads, filter/WAF/CSP bypasses, framework-specific exploits, DOM clobbering, polyglots, and real-world exploitation chains.

🎯 Comprehensive SSRF Guide

Attack surface mapping, cloud metadata extraction, bypass techniques, exploitation chains, and defense strategies.

🎯 Comprehensive SQL Injection Guide

Attack classes, database-specific payloads, blind techniques, WAF bypasses, ORM/NoSQL variants, and prevention methods.

🎯 Comprehensive CSRF Guide

Attack surface, exploitation techniques, SameSite and token bypasses, real-world chains, and detection/prevention.

🎯 Comprehensive IDOR Guide

Attack surface, enumeration patterns, BOLA techniques, real-world writeups, detection workflow, and prevention.

🎯 Comprehensive RCE Guide

Vulnerability classes, exploitation primitives, language-specific chains, real-world CVEs, and detection/prevention.

🎯 Comprehensive XXE Guide

Parser quirks, in-band and out-of-band exfiltration, parameter entity chains, file-format vectors, and hardening.

🎯 Comprehensive Deserialization Guide

Language-specific attack surface, gadget chain mechanics, real-world CVE chains, tools, and detection/prevention.

API & Application Security

🎯 Comprehensive API Security Guide

OWASP API Top 10 exploitation, authentication and authorization bypasses, rate limit evasion, real-world chains, and detection/prevention.

🎯 Comprehensive GraphQL Security Guide

Discovery, introspection, schema recovery, injection, authorization flaws, batching, DoS, subscriptions, and engine-specific quirks.

🎯 Comprehensive Authorization & Access Control Guide

Authorization models, bug classes, bypass techniques, real-world chains, and detection/prevention patterns for web and API testing.

Authentication & Identity Security

🎯 Comprehensive Authentication Guide

Protocols, mechanisms, vulnerabilities, exploitation techniques, and defense strategies. Covers traditional and modern authentication methods from enterprise to web applications.

🎯 Comprehensive JWT Security Guide

Algorithm confusion, signature bypass, library-specific issues, and secure implementation patterns. Covers detection methodologies and exploitation techniques.

🎯 Comprehensive SSTI Guide

Template engine vulnerabilities, exploitation techniques, payload development, framework-specific attacks, and defense strategies.

🎯 Comprehensive Session Management Guide πŸ†• New 2026

Comprehensive reference covering session security β€” Session lifecycle, token management, storage mechanisms, attack vectors, and defense strategies. Newly created with 2026 session CVEs from automated intelligence processing.

🎯 Comprehensive Business Logic Flaws Guide πŸ†• New 2026

Workflow bypass, race conditions, payment logic flaws, privilege escalation chains, and application context attacks. Covers 27 CVE discoveries.

AI & Emerging Technologies

🎯 Comprehensive AI / LLM Security Guide

Large Language Model and agentic AI system security, attack surface, exploitation techniques, real-world CVE chains, payloads, and layered detection/prevention.

Security Methodology & Techniques

🎯 Comprehensive Mobile Application Security Guide

Threat models, platform attack surface, reverse engineering, runtime instrumentation, bypass techniques, testing methodology, and defensive controls.

🎯 Comprehensive Python Security Guide

Dangerous APIs, deserialization pitfalls, framework-specific risks, supply chain attacks, LLM-era CVEs, static analysis tooling, and hardening patterns.

🎯 Comprehensive Fuzzing Guide

Fundamentals, coverage feedback, harness construction, corpus strategy, sanitizer usage, and the tool stack for web, binary, kernel, and API targets.

🎯 Comprehensive Recon Guide

Attack surface discovery, subdomain enumeration, live host probing, content discovery, JS mining, cloud asset hunting, automation, and continuous monitoring.

🎯 Comprehensive OSINT Guide

Methodology, collection disciplines, tooling, pivoting techniques, and operational security for intelligence gathering.

🎯 Comprehensive Secrets Management & Leakage Guide

Detection, remediation, and hardening with coverage of GitGuardian research, OWASP guidance, TruffleHog/Gitleaks, real-world breaches, and AI-era patterns.

Professional Tools & Career

🎯 Comprehensive Bug Bounty Hunting Guide

Methodology, platforms, reconnaissance pipelines, vulnerability hunting, exploit chaining, report writing, and career strategy.

🎯 Comprehensive Burp Suite Guide

Core tools, essential extensions, Bambdas and BChecks, Collaborator, macros and session handling, custom extension development, Burp AI, and real-world testing workflows.

🎯 Software Supply Chain Security Guide

Threat model across the SDLC, package-registry attack patterns, CI/CD hardening, artifact provenance and signing, SBOMs, dependency scanning, case studies, and defensive checklists.


Blog Posts by Topic

Server-Side Request Forgery (SSRF)

Cross-Site Scripting (XSS)

XML External Entity (XXE)

Memory Safety & Binary Security

Use After Free

Python Security

Core Security Concepts

Security Tools & Libraries

Advanced Topics

Tool Poisoning & Supply Chain

Security Research & Bug Bounty

Research Methodology

Tool Poisoning & Supply Chain

Security Tools & Techniques

Burp Suite

Fuzzing

OSINT & Reconnaissance

Secret Management

Talks & Presentations

Check out my speaking page for conference talks and presentations on these security topics.

Additional Resources

For curated security resources and tools, visit appsec.fyi - my collection of application security resources.


This guides index is continuously updated as I research and publish new security content. Each topic represents areas of active research and practical experience.