Retest Is a Test, Not a Thank-You Email
Plan and perform a remediation retest that confirms the control outcome, not just the developer's patch note.
The teach A fix is a claim until a retest turns it into evidence. The tester's job is not to reward effort; it is to verify whether the risk is reduced. That means returning to the original exploit path and checking the security property that failed. Retesting works best when it is narrow but skeptical. Start with the original proof. Recreate the same preconditions: account role, object ID, network position, payload, or token state. Then retry the exploit. If it fails, ask why. Did the server enforce the control, or did the user interface simply hide a path? Did the…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in