PingSec

PingSec PingSec is a Cyber Security Consulting and Training services Organization, providing specialized cyber security services for IT assets.

If a JWT token uses "alg": "none" and the server accepts it without verifying the signature, what is the issue?A) Inform...
13/02/2026

If a JWT token uses "alg": "none" and the server accepts it without verifying the signature, what is the issue?

A) Information Disclosure
B) Broken Authentication
C) Cryptographic Misconfiguration
D) CSRF

๐Ÿ‘‡ Whatโ€™s your answer?

Which XSS type stores the malicious payload permanently in the server/database?A) Reflected XSSB) DOM-based XSSC) Stored...
12/02/2026

Which XSS type stores the malicious payload permanently in the server/database?

A) Reflected XSS
B) DOM-based XSS
C) Stored XSS
D) Blind XSS

๐Ÿ‘‰ Drop your answer ๐Ÿ‘‡

An application allows users to access their profile using:GET /api/user?id=1024If an attacker changes the ID to 1025 and...
11/02/2026

An application allows users to access their profile using:

GET /api/user?id=1024

If an attacker changes the ID to 1025 and successfully views another userโ€™s data, what vulnerability is this?

A) SQL Injection
B) Broken Authentication
C) Insecure Direct Object Reference (IDOR)
D) CSRF

Address

Noida
201301

Alerts

Be the first to know and let us send you an email when PingSec posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share