Get short, timely messages from Dan Cornell.

Twitter is a rich source of instantly updated information. It's easy to stay updated on an incredibly wide variety of topics. Join today and follow @danielcornell.

Get updates via SMS by texting follow danielcornell to 40404 in the United States
Codes for other countries

Two-way (sending and receiving) short codes:
Country Code For customers of
Australia
  • 0198089488 Telstra
Canada
  • 21212 (any)
United Kingdom
  • 86444 Vodafone, Orange, 3, O2
Indonesia
  • 89887 AXIS, 3, Telkomsel
Ireland
  • 51210 O2
India
  • 53000 Bharti Airtel, Videocon
Jordan
  • 90903 Zain
New Zealand
  • 8987 Vodafone, Telecom NZ
United States
  • 40404 (any)

danielcornell

  1. Morale will continue until the beatings improve
  2. @falconsview I have hellacious NOLA cab stories. Mostly not being able to get one before 6am. Trouble when you have a 6am flight...
  3. @Wh1t3Rabbit Yes. We have two sorts of numbers: per-vuln for keyboard fix time & project compsition ratios: %fix, %validate, %deploy etc
  4. @Wh1t3Rabbit All of the projects we've done have -some- sort of central library for encoding/validation. Sometimes ESAPI, MS AntiXSS, custom
  5. @chriseng @jeremiahg So 40 hrs when averaged over all of it - not a horrible guess. But orgs need to tune model to their env.
  6. @chriseng @jeremiahg Also those were HARD SQLi But that is also only the keyboard time for fixes; didn't include testing, validation, etc
  7. @wickett We've used the Java input validation and encoding stuff. LOTS of dependencies, tho
  8. Hey everybody @denimgroup uses #OWASP ZAP and so should you bit.ly/KVFMxC
  9. RT @donicer: Movie today: Heartbreak Ridge with Clint Eastwood <One of the best
  10. RT @Zap0tek: PHP: a fractal of bad design -- bit.ly/HwbMMk <YES!
  11. @jack_daniel Avocado. Sprouts are filthy
  12. @falconsview That's just one item, right?
  13. @jcran Congrats on the move! Exciting stuff
  14. @mkonda Most of the teams we work w/ that have quick cycle times choose to handle fixes in-house b/c they can do them lots cheaper
  15. @mkonda Fair point. Agile practices (auto test, cont integration) can help get 3rd party folks on board. But also reduce costs for in-house
  16. "What color plane you want to buy?" "Clear. Like Wonder Woman's" Damn 30 Rock is funny...
  17. RT @EoinKeary: #owasp fund raising for project and guide development. If you use #owasp give us a $1 bit.ly/KBW3dP
  18. OH "I don't hate adobe the mud product; it works just fine and you don't have to apply security updates every week"
  19. Upcoming webinar from @johnbdickson bit.ly/JXFucj on Keeping Your Data Safe
  20. @451wendy Hop on 35. You should be able to make it.