Cyber Security

Web site scanning without prior permission is very likely illegal, here’s why

It appears that there is a growing wave of SaaS utilities that will either scan websites and internet-based services for you or provide you with access to historical information on sites and services they have already scanned, often for a fee. Unfortunately, using such services can result in your seriously falling foul of the law Read more about Web site scanning without prior permission is very likely illegal, here’s why[…]

robots.txt Pen Test extension

Given that I’m seeing an increase in unauthorised, and essentially illegal, Pen Tests against business production instances, which only serve to: Test the firewalls around your production instance (rather than testing the application code directly), Put at serious risk the availability of the web service under ‘test’ by consuming resources that should be only used Read more about robots.txt Pen Test extension[…]

Continuous Pen Testing – Pros and Cons

It seems quite a few businesses are resorting to using 3rd parties to implement continuous pen testing for not only their own products but also for online services they also consume – this can be a very bad idea and lead to a false sense of security. In the face of it regularly scanning an Read more about Continuous Pen Testing – Pros and Cons[…]