<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:thr="http://purl.org/syndication/thread/1.0">
    <title>CGISecurity - Website and Application Security News</title>
    <link rel="self" type="application/atom+xml" href="https://www.cgisecurity.com/atom.xml" />
    <link rel="alternate" type="text/html" href="https://www.cgisecurity.com/" />
    <id>tag:typepad.com,2003:weblog-1694854</id>
    <updated>2025-06-01T00:10:15-07:00</updated>
    <subtitle>All things related to website, database, SDL, and application security since 2000.
</subtitle>
    <generator uri="http://www.cgisecurity.com/">CGISecurity</generator>
    <entry>
        <title>Announcing SecTemplates.com release #6: Security Partner Program Pack v1</title>
        <link rel="alternate" type="text/html" href="https://www.cgisecurity.com/2025/06/announcing-sectemplatescom-release-6-security-partner-program-pack-v1.html" />
        <link rel="replies" type="text/html" href="https://www.cgisecurity.com/2025/06/announcing-sectemplatescom-release-6-security-partner-program-pack-v1.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a28883302e861027458200d</id>
        <published>2025-06-01T00:10:15-07:00</published>
        <updated>2025-06-01T00:12:45-07:00</updated>
        <summary>I have built several security partner programs at companies such as Box Inc. and Coinbase, with over 8 years of experience leading them. I have consistently observed the benefits of a partner-focused model versus a classical consultancy model within medium to large enterprises. I&#39;m pleased to announce our 6th program pack, the...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Announcements" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Papers" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Rant" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Research" />
        
        


    </entry>
    <entry>
        <title>Announcing SecTemplates.com release #5: Security Exception Program Pack 1.0</title>
        <link rel="alternate" type="text/html" href="https://www.cgisecurity.com/2024/09/announcing-sectemplatescom-release-5-security-exception-program-pack-10.html" />
        <link rel="replies" type="text/html" href="https://www.cgisecurity.com/2024/09/announcing-sectemplatescom-release-5-security-exception-program-pack-10.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a28883302c8d3bd483b200c</id>
        <published>2024-09-21T16:33:59-07:00</published>
        <updated>2024-09-21T16:33:59-07:00</updated>
        <summary>The goal of this release is to provide all the necessary resources to establish and set up a fully functioning security exceptions program at your company. - Robert Auger (@robertauger) In this pack, we cover: Security Exception Definitions: This document describes common terminology used in an exceptions process, outlines definitions for the...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Site News" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Vulns" />
        
        


    </entry>
    <entry>
        <title>Announcing SecTemplates.com release #4: Vulnerability Management Program Release Pack 1.0</title>
        <link rel="alternate" type="text/html" href="https://www.cgisecurity.com/2024/08/sectemplatescom-release-4-vulnerability-management-program-release-pack-10.html" />
        <link rel="replies" type="text/html" href="https://www.cgisecurity.com/2024/08/sectemplatescom-release-4-vulnerability-management-program-release-pack-10.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a28883302c8d3b7a920200c</id>
        <published>2024-08-05T10:36:35-07:00</published>
        <updated>2024-08-05T13:44:27-07:00</updated>
        <summary>I&#39;m pleased to announce our fourth release, the Vulnerability Management Program Pack. The goal of this release is to provide everything you&#39;d need to establish and setup a fully functioning vulnerability management program at your company. - Robert Auger (@robertauger) In this pack, we cover: Vulnerability Level Definitions: This document outlines vulnerability...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Site News" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Vulns" />
        
        


    </entry>
    <entry>
        <title>Announcing SecTemplates.com release #3: Bug bounty program pack 1.0 </title>
        <link rel="alternate" type="text/html" href="https://www.cgisecurity.com/2024/07/announcing-sectemplatescom-release-3-bug-bounty-program-pack-10-.html" />
        <link rel="replies" type="text/html" href="https://www.cgisecurity.com/2024/07/announcing-sectemplatescom-release-3-bug-bounty-program-pack-10-.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a28883302c8d3b8cedd200b</id>
        <published>2024-07-08T17:13:57-07:00</published>
        <updated>2024-07-08T17:53:36-07:00</updated>
        <summary>Introduction There are numerous considerations beyond selecting a provider, many of which are often overlooked in public documentation. The goal of the Bug Bounty Program pack is to help people quickly ramp up on the topic, providing them with the necessary information to begin their journey and ultimately launch a program. -...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Bug Bounty" />
        
        


    </entry>
    <entry>
        <title>Announcing SecTemplates.com release #2: External penetration testing program pack 1.0</title>
        <link rel="alternate" type="text/html" href="https://www.cgisecurity.com/2024/06/announcing-sectemplatescom-release-2-external-penetration-testing-program-pack-10.html" />
        <link rel="replies" type="text/html" href="https://www.cgisecurity.com/2024/06/announcing-sectemplatescom-release-2-external-penetration-testing-program-pack-10.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a28883302c8d3b7887c200b</id>
        <published>2024-06-24T13:23:03-07:00</published>
        <updated>2024-06-24T13:26:08-07:00</updated>
        <summary>In addition to CGISecurity I work on other side projects from time to time. Below is my second announcement from my latest project. Introduction I have built out several penetration testing programs, both internally and externally at companies such as eBay, Paypal, and Box to name a few. Before you have the...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Off Topic" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Papers" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Rant" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Site News" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Vendors" />
        
        


    </entry>
    <entry>
        <title>Announcing SecTemplates.com and the incident response program pack 1.0</title>
        <link rel="alternate" type="text/html" href="https://www.cgisecurity.com/2024/06/announcing-sectemplatescom-and-the-incident-response-program-pack-10.html" />
        <link rel="replies" type="text/html" href="https://www.cgisecurity.com/2024/06/announcing-sectemplatescom-and-the-incident-response-program-pack-10.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a28883302c8d3b36dc5200c</id>
        <published>2024-06-18T12:45:31-07:00</published>
        <updated>2024-06-18T12:47:00-07:00</updated>
        <summary>In addition to CGISecurity I work on other side projects from time to time. Below is an announcement about my latest project. Introduction I&#39;ve worked in the security industry for over 20 years and, during this time, have built and shaped many security programs. At every company I join, I find myself...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Incidents" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Papers" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Rant" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Site News" />
        
        


    </entry>
    <entry>
        <title>20 years of CGISecurity: What appsec looked like in the year 2000</title>
        <link rel="alternate" type="text/html" href="https://www.cgisecurity.com/2020/11/20-years-of-cgisecurity-what-has-changed-within-the-application-security-space.html" />
        <link rel="replies" type="text/html" href="https://www.cgisecurity.com/2020/11/20-years-of-cgisecurity-what-has-changed-within-the-application-security-space.html" thr:count="4" thr:updated="2020-12-07T15:58:58-08:00" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a288833026be425fdae200d</id>
        <published>2020-11-22T02:03:41-08:00</published>
        <updated>2020-11-30T20:57:13-08:00</updated>
        <summary>Just realized that 20 years have passed since I started this site to learn more about web security threats. What &#39;appsec&#39; looked like in 2000 OWASP didn&#39;t exist yet, nor did WASC Vulnerability disclosure was the wild west. Rain forest puppy (RFP) (that guy who discovered sqli) had just created the first...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Commentary" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Site News" />
        
        


    </entry>
    <entry>
        <title>My experience coleading purple team</title>
        <link rel="alternate" type="text/html" href="https://www.cgisecurity.com/2018/05/my-experiences-leading-purple-team.html" />
        <link rel="replies" type="text/html" href="https://www.cgisecurity.com/2018/05/my-experiences-leading-purple-team.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a2888330223c84dbbec200c</id>
        <published>2018-05-29T11:22:43-07:00</published>
        <updated>2018-05-29T13:00:43-07:00</updated>
        <summary>I&#39;ve been fortunate enough to manage a red team program for several years and since it&#39;s inception it has gone through many changes. What started out as adhoc engagements trying to see how far we could get/what problems we could find, turned into a mechanism to work more closely, and regularly with...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Blue Team" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Buzzwords" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Commentary" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Defense" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Forensics" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Purple Team" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Rant" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Red Team" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Research" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Vulns" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="blue team" />
        <category scheme="http://sixapart.com/ns/types#tag" term="blue teaming" />
        <category scheme="http://sixapart.com/ns/types#tag" term="purple team" />
        <category scheme="http://sixapart.com/ns/types#tag" term="purple teaming" />
        <category scheme="http://sixapart.com/ns/types#tag" term="red team" />
        <category scheme="http://sixapart.com/ns/types#tag" term="red teaming" />
        


    </entry>
    <entry>
        <title>oAuth nightmares talk</title>
        <link rel="alternate" type="text/html" href="https://www.cgisecurity.com/2017/05/oauth-nightmares-talk.html" />
        <link rel="replies" type="text/html" href="https://www.cgisecurity.com/2017/05/oauth-nightmares-talk.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a28883301b7c8fd7cd7970b</id>
        <published>2017-05-30T10:40:06-07:00</published>
        <updated>2017-05-30T10:40:06-07:00</updated>
        <summary>Two of my co workers have presented at HackMiami on flaws people implement in their oauth implementations. The talk summary is below &quot;OAuth is one of the most popular authorization frameworks in use today. All major platforms such as Google, Facebook, Box etc support it and you are probably thinking of implementing...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        
        


    </entry>
    <entry>
        <title>Extensive IOS hacking guide released by Security Innovation</title>
        <link rel="alternate" type="text/html" href="https://www.cgisecurity.com/2017/05/extensive-ios-hacking-guide-released-by-security-innovation.html" />
        <link rel="replies" type="text/html" href="https://www.cgisecurity.com/2017/05/extensive-ios-hacking-guide-released-by-security-innovation.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a28883301b7c8fa085a970b</id>
        <published>2017-05-19T09:35:53-07:00</published>
        <updated>2017-05-19T09:35:53-07:00</updated>
        <summary>Security Innovation has published a very extensive guide to IOS hacking that&#39;s worth checking out. Here&#39;s the table of contents 1. Setting Up iOS Pentest Lab.................. 5 1.1 Get an iOS Device...................5 1.2 Jailbreaking an iOS Device.................. 7 1.3 Installing Required Software and Utilities .................. 10 2. Acquiring iOS Binaries.................. 13 3....</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Development" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Forensics" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        
        


    </entry>
 
</feed>

<!-- ph=1 -->
