Web App

Blog Archive Tag

the exploit blog logo
The Exploit: Penetration Testing Insights From The Frontlines
Web App
  • OWASP Top 10

    OWASP Top 10 for 2025: What’s New in Web Application Security

    The OWASP Top 10 2025 for web applications release candidate was released last week. Take a look at which categories have moved as well as one new category.
    Raxis Research Team November 20, 2025
  • OWASP Top 10 for LLM Applications

    OWASP Top 10 for LLM Applications Penetration Testing

    Lead Penetration Tester Jason Taylor looks at OWASP’s Top 10 list for LLM applications for penetration testing as AI machine learning becomes prevalent.
    Jason Taylor July 15, 2025
  • OWASP Top 10

    OWASP Top 10: The Bedrock of an Application Penetration Test

    When performing web app, mobile app, and API penetration tests, we refer to the OWASP Top 10. Here we’ll discuss what that means and why it’s helpful.
    Adam Fernandez April 23, 2024
  • SQL Injection

    SQLi Series: An Introduction to SQL Injection for Penetration Testing

    Raxis’ Andrew Trexler explains what SQL Injection (SQLi) is and how to perform a simple exploit against a web app login page in penetration tests.
    Andrew Trexler April 9, 2024
  • Simultaneous Sessions

    Why We Take Simultaneous Sessions Seriously on Penetration Tests

    Raxis Lead Penetration Tester Matt Dunn explains why you simultaneous sessions is a significant finding on a penetration test.
    Raxis Research Team April 8, 2022
  • Web App Testing: Part Two

    What is Web App Pentesting? (Part Two)

    Lead penetration tester Matt Dunn continues his discussion about web application testing. In Part Two, Matt explains testing as an authenticated user vs. as an unauthenticated user.
    Raxis Research Team March 4, 2022