20 years of CGISecurity: What appsec looked like in the year 2000


Just realized that 20 years have passed since I started this site to learn more about web security threats. What ‘appsec’ looked like in 2000 OWASP didn’t exist yet, nor did

Nobody even had the concept of a bug bounty. Most of us were scared we'd go to jail (myself included) for reporting vulns. There were no real web scanners (DAST) back then.

