Graham Bleaney

@GrahamBleaney

Security Engineer , focusing on vulnerability detection and prevention using Pyre Static Analyzer (Pysa) -

New York, New York
Vrijeme pridruživanja: ožujak 2011.

Tweetovi

Blokirali ste korisnika/cu @GrahamBleaney

Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @GrahamBleaney

  1. 30. sij

    was fantastic. Top talks to watch when the video is released: - 's "Next-Generation Secure Drop: Protecting Journalists from Malware" - Matt Bishop's "How Anonymous is my Anonymized Data?" - 's "Securing the Software Supply Chain"

    Poništi
  2. 18. sij

    Great explanation of CVE-2020-0601 (aka Curveball aka Whose Curve is it Anyway aka the NSA Microsoft CryptoAPI Vulnerability). It's really accessible and accidentally made me understand ECC properly for the first time

    Poništi
  3. 4. sij

    If you want to find issues like this yourself, the first Pysa exercises are up: They're brand new, and probably need refinement, so feedback is appreciated. They're also best done with the docs open on another screen:

    Prikaži ovu nit
    Poništi
  4. proslijedio/la je Tweet
    16. pro 2019.

    Facebook is starting a "prodsec but for privacy" team to compliment existing privacy work. This team will identify privacy risks and be the technical voice on the "jedi council" of privacy decisions. First up the manager role:

    Poništi
  5. 14. pro 2019.

    CVE-2019-19775 - The first CVE found by Pysa, during some work and I did. Hopefully the first of many.

    Prikaži ovu nit
    Poništi
  6. 13. pro 2019.

    Pysa (Python Static Analyzer built on Pyre) docs got some love recently. New page includes strategies for increasing coverage on pre-existing open source projects:

    Poništi
  7. 12. pro 2019.

    15 minute CTF I made: . It's all simple web app stuff, so no need to break out the scanners or anything beyond Chrome Developer Tools. Please don't go for a shell 😅

    Poništi
  8. 11. pro 2019.

    What to do when you have a spare weekend and a stored XSS on ? Take inspiration from and write a worm (but then responsibly disclose it)!

    Poništi
  9. 10. pro 2019.

    Back before gave up on payment through their website, I found a fun XSS on login that let you steal credentials and money (and then spent way too many words writing about it):

    Poništi

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·