Profile_bird

Hey there! tatehansen is using Twitter.

Twitter is a free service that lets you keep in touch with people through the exchange of quick, frequent answers to one simple question: What's happening? Join today to start receiving tatehansen's tweets.

Already using Twitter
from your phone? Click here.

tatehansen

  1. searching for a free vuln tool/fuzzer for targeting a custom RTSP server (or maybe use http://peachfuzzer.com/ to create one)
  2. i also wish appscan & webinspect would produce reports with vulnerable URLs only (with affected keys/value pairs) minus all the duplicates
  3. i've been asked to remediate 100s of vulns from a round of web app & network scanning, i forgot how much pain this side of the fence can be
  4. a nice little animated graphic on how the large hadron collider works http://bit.ly/zmhZ
  5. annoyed commercial app scanners appear unable to test forms utilizing hidden fields w/dynamic tokens (used to disrupt continuous POSTing)
  6. wsj article on hack at citibank: http://online.wsj.com/article/SB126145280820801177.html?mod=WSJ_hps_LEFTWhatsNews
  7. love listening to foreign music stations (for music i like and for languages i have no understanding of) - commercials don't annoy me
  8. favorite tools for reducing the pain of scoping large web apps?
  9. just got back from checking out the Genghis Khan exhibit at the Denver Museum: http://www.dmns.org/gk/
  10. bought 8GB kit for my late '08 unibody macbook pro, but i could use only 1 (6GB works, 8GB no) selling 1 stick on ebay http://bit.ly/5TPnfu
  11. trying out the fever feed reader http://feedafever.com/
  12. watching peepcode's jquery screencast http://peepcode.com/products/jquery
  13. "a giant Norseman armed with an axe held up the entire Saxon army, and singlehandedly cut down over 40 Saxon soldiers"
  14. working rails + rsruby + R (pass controller variables to R functions, create R plot png images, reference via image_tag) http://bit.ly/BPZaH
  15. Dan Carlin's hardcore history podcast http://bit.ly/15KF6T - warriors from Antiquity were badass
  16. I wrote a blog entry on doing a GET before POST when fuzzing with BURP/WebScarab (http://bit.ly/3MsNTa), maybe there is an easier way?
  17. Retaining contracts like ‘try to break this web app every month for 10 hours’ rocks, it enables deep dives into narrow attack vectors
  18. just read "Some Courts Raise Bar on Reading Employee Email" http://bit.ly/1xC6lT
  19. BURP intruder, enumerating photos marked private, pick non-private photo, “like it”, intercept POST, change photo ID, now see it :)
  20. "I'm so the boss of you"