Metasploit Module: Azure AD Login Scanner
New Metasploit Module: Azure AD Login Scanner

Raxis’ Matt Dunn has published another Metasploit module, this one describing a vulnerability in Azure’s[…]

Cross-Site Scripting: Filter Evasion & Sideloading Payloads
Cross-Site Scripting (XSS): Filter Evasion and Sideloading

In this second in a series, learn how to perform Cross-Site Scripting (XSS) attacks such[…]

Introduction to Cross-Site Scripting
Introduction to Cross-Site Scripting

This video covers the basics of cross-site scripting, including reflected, stored, and DOM-based XSS as[…]

2021 OWASP Top 10
OWASP Top 10: Broken Access Control

In this blog post, Raxis lead penetration tester Mark Fabian discusses broken access control and[…]

2021 OWASP Top 10
2021 OWASP Top 10 Focus: Injection Attacks

The latest draft of the OWASP Top 10 has been released. Though injection is now[…]

Nagios XI Stored Cross-Site Scripting (XSS): CVE-2021-38156
Nagios XI Stored Cross-Site Scripting (XSS): CVE-2021-38156

Nagios is open-source network and system monitoring software. Raxis’ Matt Dunn has discovered a cross-site[…]

Cookie Jar
Keep Your Cookies in the Cookie Jar: HttpOnly and Secure Flags

How can cookies be used against you? And how do you keep that from happening?[…]

PRTG Network Monitor Stored Cross-Site Scripting Vulnerability (CVE-2021-29643)
PRTG Network Monitor Stored Cross-Site Scripting Vulnerability (CVE-2021-29643)

Raxis lead penetration tester Matt Dunn uncovers a new vulnerability in the PRTG Network Monitor[…]

Matt Dunn Mathur
Meet the Team: Matt Mathur, Lead Penetration Tester

Meet Raxis lead penetration tester Matt Mathur, a cybersecurity professional with a passion for learning[…]

JavaScript Execution to Display User's Cookie in an Alert Box
ManageEngine Applications Manager Stored Cross-Site Scripting Vulnerability (CVE-2021-31813)

Raxis’ lead penetration tester Matt Dunn has discovered another ManangeEngine cross-site scripting (XSS) vulnerability, this[…]

Unescaped JavaScript Tags
ManageEngine Key Manager Plus Cross-Site Scripting Vulnerability (CVE-2021-28382)

Raxis’ Lead Penetration Tester Matt Dunn discovers another cross-site scripting vulnerability in Zoho’s MangeEngine Key[…]

Cross-Site Scripting Vulnerability in ManageEngine AD Self Service Plus (CVE-2021-27956)
Cross-Site Scripting Vulnerability in ManageEngine AD Self Service Plus (CVE-2021-27956)

Raxis lead penetration tester Matt Dunn has uncovered a new cross-site scripting vulnerability in Manage[…]