Skip to content

Andres Rauschecker

How an Initial SQL Injection Led to Research on URL Normalization and mod_rewrite

The article explores how an SQL injection security analysis led to a more in-depth examination of URL normalization and the Apache mod_rewrite module. It explains how mod_rewrite can redirect different URL formats to uniform paths—a process that, however, poses security risks if not implemented correctly. Particular attention is given to the risk that inadequate normalization can create attack vectors, such as through double slashes or alternative encodings. The article offers technical insights and presents solutions for the secure configuration of rewrite rules.

5 errors in pentest results

Especially for companies that operate larger infrastructures, a pentest can often provide more insights than is typically assumed.

What to look for in pentests? Quality features explained.

Often, in discussions with new customers, we can see that the market of penetration testing services seems opaque

Attacked via SMS? Smishing examined

Introduction Almost everyone is familiar with the issue of spam: you receive e-mails telling you about unbeatable discounts,

CVE Quick Search: Implementing our own vulnerability database

Not only for penetration testing it is interesting to know, which vulnerabilities exist for a certain software product.

Automated cyber attacks: no system remains untouched

Independent of the size of a company or enterprise, everyone has to expect becoming a target of cyber