Finding superhuman XSS polyglot payloads with Genetic Algorithms
The following article is a technical deep dive into how genetic algorithms can be leveraged to create superhuman XSS polyglot payloads.
Mon 01 March 2021
News and Updates of Week 8
This weeks is marked by multiple high profile data breaches affecting Cashalo, Npower, Kia, T-Mobile and Clubhouse.
Sun 28 February 2021
Ostorlab adds Web Security Scanning to its arsenal
Ostorlab is adding Web Security Scanner to its arsenal with novel approaches to vulnerability discovery.
Mon 15 February 2021
February 2021
We are pleased to announce a set of new improvements
Mon 01 February 2021
Release of a new analysis environment to aid manual assessment
New Analysis Environment with access to disassembly, decompiled source, call trace, function tagging and many other features.
Latest posts
Finding and Validating Hardcoded Keys and Secrets
Hardcoded secrets are easy to find and might open a gate to sensitive data or privileged access. This makes them a great target for Bug Bounty hunters and Attackers.
Fri 30 October 2020
Autonomous Security: Pushing Security Automation to the Next Level
The article introduces the term Autonomous Security
in the context of security scanning and defines 5 tiers of maturity.
Mon 26 October 2020
Two efficient features to continuously monitor mobile applications
Whether we are developing a mobile application or assessing its security, we need to continuously review it with every new release. Repetitively building the app, uploading the file, and creating a scan quickly becomes an annoyance. Ostorlab is excited to announce the introduction of two new features to ease the burden of testing your app.
Sat 24 October 2020
Create scans directly from the Android and iOS Store
Ostorlab now supports creating scans directly from Android Play Store and iOS App Store
Sun 16 August 2020
Changelog
View all changesAI-automated Attack surface, Privacy Analysis, Wordpress agent, and more.
Mon 20 January 2025
Advanced Search Query, API Endpoints, Tons of new detections, and more.
Mon 02 December 2024
HTTP2, Private Custom Checks, actively exploited CVE and much more.
Mon 07 October 2024