Open in app

Sign in

Write

Sign in

Chevon Phillip
Chevon Phillip

289 Followers

Home

About

Pinned

Building a Strong Foundation — How to Create and Maintain an Effective Application Security Program

As businesses increasingly rely on digital technologies and applications to support their operations and interact with customers, the need for adequate application security has never been greater. Unfortunately, many organizations need help to take control of their application-specific vulnerabilities and implement and maintain effective application security programs. According to a…

Application Security

2 min read

Building a Strong Foundation — How to Create and Maintain an Effective Application Security Program
Building a Strong Foundation — How to Create and Maintain an Effective Application Security Program
Application Security

2 min read


May 10

RCE due to Dependency Confusion — $5000 bounty!

Hey everyone! I’m back with another cool write-up about a bug bounty report I submitted to a private program on HackerOne. Guess what? I got a $5,000 reward and they took care of it in just 30 minutes! I won’t go into the nitty-gritty of dependency confusion since there are…

Appsec

2 min read

RCE due to Dependency Confusion — $5000 bounty!
RCE due to Dependency Confusion — $5000 bounty!
Appsec

2 min read


Apr 3

Blind XSS via SMS Support Chat — $1100 Bug Bounty!

Hello Hunters, This is a quick write-up on how my blind XSS payload executed within an internal support portal via an SMS support chat. This company (example.com) had a support site allowing users to submit a support ticket. You can create a support ticket in three ways: Email Support Phone…

Bug Bounty

1 min read

Blind XSS via SMS Support Chat — $1100 Bug Bounty!
Blind XSS via SMS Support Chat — $1100 Bug Bounty!
Bug Bounty

1 min read


Dec 15, 2022

Can ChatGPT and OpenAI Replace Application Security Engineers — Pros and Cons

As the world becomes increasingly reliant on technology and the internet, the need for skilled application security engineers to protect our online systems and data grows. But can chatbots and large language models, such as ChatGPT and OpenAI, replace the need for human application security engineers? On the one hand…

Application Security

3 min read

Can ChatGPT and OpenAI Replace Application Security Engineers — Pros and Cons
Can ChatGPT and OpenAI Replace Application Security Engineers — Pros and Cons
Application Security

3 min read


Dec 15, 2022

10 Ways to Keep Your Developers Happy and Secure — A Guide for Application Security Engineers

As an application security engineer, your job is to ensure the security of your company’s software and systems. But in order to do that effectively, you need to work closely with your team of developers. …

Application Security

3 min read

10 Ways to Keep Your Developers Happy and Secure — A Guide for Application Security Engineers
10 Ways to Keep Your Developers Happy and Secure — A Guide for Application Security Engineers
Application Security

3 min read


Dec 10, 2019

Sub-Domain Takeovers — How Can Companies Better Secure Their Assets? Part 1

An Ethical Hacker’s Perspective — Introduction Hi, my name is Chevon Phillip. I am a Security Researcher and Penetration Tester. In this article, I will explain what are sub-domain takeovers, how hackers can exploits these vulnerabilities by finding potential targets, and how companies should secure their assets from these types of vulnerabilities. What are Sub-Domains? For those of you…

Information Security

4 min read

Sub-Domain Takeovers — How can companies better secure their assets? Part 1
Sub-Domain Takeovers — How can companies better secure their assets? Part 1
Information Security

4 min read

Chevon Phillip

Chevon Phillip

289 Followers

Application Security Engineer. I helped secure top companies and organizations.

Following
  • cengkuru michael

    cengkuru michael

  • Ammar Ahmed

    Ammar Ahmed

  • Gökhan Güzelkokar

    Gökhan Güzelkokar

  • Sau Sheong

    Sau Sheong

  • Anton Chuvakin

    Anton Chuvakin

See all (198)

Help

Status

About

Careers

Blog

Privacy

Terms

Text to speech

Teams