RSnake
-
Best typo domain ever com.com up for grabs:
8:46 AM Nov 20th
from web
-
Add spamming and scraping to the list of problems DNS Rebinding enables:
8:21 AM Nov 18th
from web
-
@ DNS Rebinding just keeps getting worse, doesn't it:
2:08 PM Nov 17th
from web
-
I covered quite a bit of DNS rebinding in the book. Same mitigatigations, different problems:
1:52 PM Nov 16th
from TweetDeck
-
@ @ DNS Rebinding Session Fixation More to come.
1:49 PM Nov 16th
from web
-
RT @: Randolf-Brooks Credit Union now supports depositing checks via iPhone pics of checks.
10:21 AM Nov 16th
from TweetDeck
-
@ RT @: My Defcon Talk with @ is up in video -- SlowLoris and SSLStrip demos
8:45 PM Nov 14th
from TweetDeck
-
@ right which you need to use some social engineering to exploit. XSS or redirects sent in email, etc.
2:37 PM Nov 14th
from TweetDeck
in reply to djtechnocrat
-
@ You'd have to ask the OWASP leadership, I guess. Good question.
2:34 PM Nov 14th
from TweetDeck
in reply to djtechnocrat
-
@ PCI is about protecting card data. Client side risks count. I do worry about removing info disclosure though, you're right.
2:28 PM Nov 14th
from TweetDeck
in reply to djtechnocrat
-
@ Definitely.
2:15 PM Nov 14th
from TweetDeck
in reply to djtechnocrat
-
@ post on ha.ckers.org. Twitter is too small to have a meaningful conv. It is based on fact. No FUD, just some TBDs.
2:15 PM Nov 14th
from TweetDeck
in reply to marcinw
-
@ yessir, that was my DefCon speech with Sam Bowne. My part was on Slowloris and the Iranian rebels.
1:53 PM Nov 14th
from TweetDeck
in reply to t3rmin4t0r
-
@ Yes, that was the first part of the convo. Damned 140 chars!
1:51 PM Nov 14th
from TweetDeck
in reply to djtechnocrat
-
@ Their bank and their QSA. That's how PCI works and does hold water assuming they still respect OWASP top 10.
1:16 PM Nov 14th
from TweetDeck
in reply to marcinw
-
@ yeah, well I thought it was only 2 rebinding ideas but I came up w/ a 3rd. I'll write some posts soon.
7:43 PM Nov 13th
from TweetDeck
in reply to tomaszmiklas
-
@ Dunno how their payment stuff works at all. You may be right but it's ultimately up to Google's bank and their QSA.
2:47 PM Nov 13th
from TweetDeck
in reply to marcinw
-
@ Oh, whoops, misread. got it. Well it wasn't me who built the list. Talk to the guys.
12:00 PM Nov 13th
from TweetDeck
in reply to mayscript
-
@ SQLi is a joke? That's a new one. Do you really believe that?
11:58 AM Nov 13th
from TweetDeck
in reply to mayscript
-
@ I have no idea what you're talking about. Google is a super neato advertizing empire.
8:27 AM Nov 13th
from TweetDeck
in reply to securityninja
|
|