Field notes
Field notes
Working notes on offensive security: how we validate findings, the flaws we look for, and the evidence we attach to each one.
Proof-driven vulnerability validation
Scanners list what might be wrong. Kissaki attaches a reproducible proof to every finding it can prove, or it says nothing.
Broken authorization: BOLA and BFLA
BOLA and BFLA are the authorization flaws behind most API breaches. What they are, why scanners miss them, and how a working exploit proves each one.