Rhino Security Labs

Technical Blog

Simplifying API Pentesting With Swagger Files

David Yesland

The current OpenAPI parsing and handling tools are not geared towards pentesting an API. We created Swagger-EZ to make getting up and running with API pentesting faster and less painful. The Github repository is here.
When auditing an API…

Gotta Watch ’em All: Pokémon Go Permissions

iOS App Security (P1): Introduction

Three things you should know about OAuth

Benjamin Caudill

OAuth has made it easy for developers to build seamless integrations between their applications and other online services. It’s a great, open toolset used by both small developers and big dev teams in the Fortune 500. From a user…