Attacking and defending web applications — auth flaws, injection, client-side bugs, and the tooling to find them.