It’s time to Hack Yourself First, with help from Pluralsight
Earlier this year I was doing my usual trick of browsing websites and writing about things that were readily observable with regards to some rather ordinary security practices. When I say “readily observable” I’m talking about things such as cookies not flagged as HttpOnly [https://www.troyhunt.com/2013/03/c-is-for-cookie-h-is-for-hacker.html] or SSL login forms embedded into HTTP pages [https://www.troyhunt.com/2013/06/the-security-futility-that-is-embedding.html]. This stuff is just so easy to...