Rhino Security Labs

Technical Blog

Simplifying API Pentesting With Swagger Files

David Yesland

The current OpenAPI parsing and handling tools are not geared towards pentesting an API. We created Swagger-EZ to make getting up and running with API pentesting faster and less painful. The Github repository is here.
When auditing an API…

Gotta Watch ’em All: Pokémon Go Permissions

Three things you should know about OAuth

Prevent an embarrassing mobile app breach

Benjamin Caudill

News over the last year has been filled with stories of mobile applications leaking customer information and exposing businesses to lawsuits and bad PR. When a mobile app reaches critical mass and winds up on millions of phones around the…