Application Security 101: Basics, Best Practices, & Challenges

Application Security 101: Basics, Best Practices, & Challenges

Today we will delve into the key concepts and principles of application security, providing a comprehensive overview for developers, IT professionals, and business leaders alike. Application security is a fundamental aspect of software development that can make or...
Access Approved: What Are Access Control Vulnerabilities?

Access Approved: What Are Access Control Vulnerabilities?

0. Overview Web applications actively facilitate business operations, allowing businesses to interact with customers, streamline processes, and deliver crucial services over the internet. Cyber attackers often focus on these applications because of their online...
How to Prepare for the PWPP Exam

How to Prepare for the PWPP Exam

Introduction The new Practical Web Pentest Professional (PWPP) certification is now available! In this article, we’ll talk about how to prepare for the exam. You won’t find any spoilers, but you will find some helpful tips for how best to prepare for and approach the...
1st Annual TCM CTF Web Walkthroughs

1st Annual TCM CTF Web Walkthroughs

Overview On December 16, 2023, TCM Security held our first annual invitational CTF with the help of MetaCTF! Any student holding a current All-Access Membership at TCM Academy could take part in the CTF, which featured plenty of challenges! In this blog post,...
Learn AppSec Testing in 2024

Learn AppSec Testing in 2024

Overview Starting an Application Security (AppSec) testing career in 2024 can seem daunting given the vast landscape of content and resources. In this blog post we will demystify the journey, offering wisdom, practical advice, and resourceful tips help you out. This...
Avoid “OR 1=1” in SQL Injections

Avoid “OR 1=1” in SQL Injections

Overview Despite its popularity as an SQL injection example, we argue that “OR 1=1” presents more risks than rewards. It may work for login bypasses occasionally, but its reliability is questionable, and better alternatives exist. We explore the drawbacks,...