1st Annual TCM CTF Web Walkthroughs

1st Annual TCM CTF Web Walkthroughs

Overview On December 16, 2023, TCM Security held our first annual invitational CTF with the help of MetaCTF! Any student holding a current All-Access Membership at TCM Academy could take part in the CTF, which featured plenty of challenges! In this blog post,...
Learn AppSec Testing in 2024

Learn AppSec Testing in 2024

Overview Starting an Application Security (AppSec) testing career in 2024 can seem daunting given the vast landscape of content and resources. In this blog post we will demystify the journey, offering wisdom, practical advice, and resourceful tips help you out. This...
Avoid “OR 1=1” in SQL Injections

Avoid “OR 1=1” in SQL Injections

Overview Despite its popularity as an SQL injection example, we argue that “OR 1=1” presents more risks than rewards. It may work for login bypasses occasionally, but its reliability is questionable, and better alternatives exist. We explore the drawbacks,...
Password Managers and Guidelines: Mastering Your Passwords

Password Managers and Guidelines: Mastering Your Passwords

Overview TCM Security is continuing the  “Practical Cybersecurity Awareness” four-part series this week during Cybersecurity Awareness Month. Today we continue our four-part series with learning how to harness password managers for enhanced Digital Security.  Securing...
What is an Internal Penetration Test?

What is an Internal Penetration Test?

Introduction An internal penetration test is a simulated attack on a network or system conducted from within an organization’s internal network. The objective of an internal penetration test is to identify vulnerabilities and weaknesses in the network or system...