Web Application


All blog articles on the subject of Web Application

Christian Birker

Published on 27.01.2023 in the category Software Security published.

What Could (Possibly) Go Wrong? - Designing Threat Modeling with a Card Game

To make the threat modeling process more playful, aramido developed a card game. This helps development teams with Security by Design. (read more)


Hannah Schneider

Published on 21.10.2021 in the category Web Application Security published.

The New OWASP Top 10 - 2021

The OWASP Top 10 - 2021 describes the ten most common security risks for web applications. They help developers implement applications securely. (read more)


Tristan Wagner

Published on 09.07.2020 in the category Security Advisories published.

Two Vulnerabilities in TeamBeam

aramido was able to identify two vulnerabilities in the data exchange platform TeamBeam. (read more)


Benjamin Pokrant

Published on 06.05.2020 in the category Security Advisories published.

HTML Injection Vulnerability in WordPress Plugin WPForms

A security vulnerability in the WordPress plugin WPForms allowed attacks via HTML injection. How does this vulnerability affect systems and how can it be closed? (read more)


Elisabeth Apicella

Published on 20.12.2018 in the category Security Advisories published.

Security Advisory: Three Findings at prescreen.io and jobbase.io

As aramido discovered, the cloud-based applicant management software of the company Prescreen had several security deficiencies. (read more)


Andreas Sperber

Published on 21.11.2018 in the category Web Application Security published.

What are the OWASP Top 10 - 2017?

The OWASP Top 10 - 2017 describes the ten most common security risks for web applications. They help developers implement applications securely. (read more)


Regina Okun

Published on 01.10.2018 in the category aramido published.

Understanding Hacker Attacks - A Workshop for Ethical Hackers

Full-day hacker workshop as a Capture The Flag (CTF game) in Jeopardy mode. How can I as an ethical hacker test my own applications? (read more)



Daniel Matesic

Published on 13.06.2018 in the category Web Application Security published.

52nd OWASP Meetup - Guided Hacking of a Web Application

At the 52nd OWASP Meetup, numerous security risks, including the OWASP Top 10, were illustrated through guided hacking of a web application. (read more)



Armin Harbrecht

Published on 03.03.2017 in the category Security Advisories published.

Multiple Vulnerabilities in the New CyberForum Portal

aramido found several security vulnerabilities on the CyberForum website. They show the typical dangers of websites with user-generated content. (read more)


Armin Harbrecht

Published on 06.02.2017 in the category Security Advisories published.

Security through Transparency – How We Disclose Security Vulnerabilities

The responsible disclosure of security vulnerabilities is a proven approach to making IT systems more secure for everyone. (read more)


Armin Harbrecht

Published on 05.01.2017 in the category Software Security published.

Secure Software Updates

How can I, as a software manufacturer, provide my users with secure updates? Learn about secure software update mechanisms. (read more)


Andreas Sperber

Published on 15.12.2016 in the category Web Application Security published.

Live-Hacking a Symfony application

Andreas Sperber from aramido is a guest at SensioLabs in Cologne on Dec 21, 2016. He hacks a Symfony app and shows what can be done for IT security. (read more)


Armin Harbrecht

Published on 14.11.2016 in the category Penetration Testing published.

How Much Does a Penetration Test Cost?

As penetration testers, we are often asked about the cost of a penetration test. The answer depends on several factors. (read more)


Andreas Sperber

Published on 01.08.2016 in the category Penetration Testing published.

What is a Penetration Test?

IT is an integral part of our lives. Hackers exploit vulnerabilities to profit. Penetration tests improve IT security. (read more)


Armin Harbrecht

Published on 19.07.2016 in the category Server Security published.

aramido Penetration Testing Offer Victim of a DDoS Attack?

In DDoS attacks, attackers specifically try to overload a web application. Our server logs suggested that we ourselves were affected. (read more)