PingSec

PingSec

Share

PingSec is a Cyber Security Consulting and Training services Organization, providing specialized cyber security services for IT assets.

13/02/2026

If a JWT token uses "alg": "none" and the server accepts it without verifying the signature, what is the issue?

A) Information Disclosure
B) Broken Authentication
C) Cryptographic Misconfiguration
D) CSRF

👇 What’s your answer?

12/02/2026

Which XSS type stores the malicious payload permanently in the server/database?

A) Reflected XSS
B) DOM-based XSS
C) Stored XSS
D) Blind XSS

👉 Drop your answer 👇

11/02/2026

An application allows users to access their profile using:

GET /api/user?id=1024

If an attacker changes the ID to 1025 and successfully views another user’s data, what vulnerability is this?

A) SQL Injection
B) Broken Authentication
C) Insecure Direct Object Reference (IDOR)
D) CSRF

Address


Noida
201301