Tim Tomes

@LaNMaSteR53

Believer †. Husband :-*. Father \o/. Veteran o7. Burp Suite master and king of making HTTP requests tremble.

Upstate South Carolina
Joined August 2009

Tweets

You blocked @LaNMaSteR53

Are you sure you want to view these Tweets? Viewing Tweets won't unblock @LaNMaSteR53

  1. Pinned Tweet
    Aug 28

    'During the Civil War, someone asked President Abraham Lincoln why he was making friends of his enemies when he should be thinking about destroying them. Lincoln replied, “Do I not destroy my enemies when I make them my friends?”' - Love this so much!

    Undo
  2. Sep 20

    And testing up to this point has proven that you want to opt out of the new scan approach. What it gives you isn't worth what it takes away. I'll be covering all this in detail at Augusta next month. 2/2

    Show this thread
    Undo
  3. Sep 20

    The more I play with the new Burp stuff, the more I've found that it's pretty much just a new skin on top of mostly old functionality with a new scan approach that you can opt out of. 1/2

    Show this thread
    Undo
  4. Retweeted
    Sep 19

    Working with to get PWAPT training in Raleigh some time soon. Who all would be interested in participating?

    Undo
  5. Retweeted
    Sep 18

    Can’t help but love these accounts... pleasant break from infosec Twitter at least.

    Undo
  6. Sep 18

    In typical style...

    Undo
  7. Sep 18

    Sorry Jim. I couldn't resist. :-D

    Show this thread
    Undo
  8. Sep 18

    And if you want to learn how to break stuff made by the people that don't take Jim's class, I have availability. DM me.

    Show this thread
    Undo
  9. Retweeted
    Sep 18

    Coming to the beautiful city of Augusta Georgia for which includes a week of awesome training followed by and then and you need some things to do and places to eat. check this out!

    Undo
  10. Retweeted
    Sep 17
    Undo
  11. Sep 18

    Anyone have or know of a good resource for desktop/think client application testing methodology? I realize there can be overlap with web, but looking for stuff that is decoupled from web technologies. i.e. direct db connection, no web service, etc. Thanks!

    Undo
  12. Retweeted
    Sep 17
    Undo
  13. Sep 14

    Been getting some concerned messages, so here's an update. Nothing major where we are yet. Expecting flooding and wind starting tomorrow. Possible power outages. Nothing like the coast is getting today. Thanks for caring. Send prayers for all.

    Undo
  14. Sep 13

    So I got a that ended up having software issues. They sent a me new one that works perfectly and let me keep the old one. Anyone know what I can do with the hardware? Will provide pictures of circuit board if needed.

    Undo
  15. Sep 12

    Say "web service attack surface" 10 times really fast. Go!

    Undo
  16. Sep 10

    Just had a contractor ask me for my testing checklist so they could track my progress. SERIOUSLY!? A checklist? Methodology is key, but if you test by a checklist, you are robbing yourself of the creativity to find anything beyond your list.

    Undo
  17. Sep 10

    Don't forget, if you missed out on getting into at , there's still one more chance to get trained up this year at in conjunction with .

    Undo
  18. Retweeted
    Sep 10

    How to use Google's CSP Evaluator to bypass CSP.

    Undo
  19. Retweeted
    Sep 8

    Thread: Today, I am going to show you how much data is leaked on and how easy it is to query that data by malicious actors using services such as Google BigQuery.

    Show this thread
    Undo
  20. Retweeted
    Sep 9

    I thought blog is better than a tweet, so I wrote small post. / "What Permission Delegation changes in Web Security"

    Undo
  21. Sep 8

    Anyone know what this thing is?

    Undo

Loading seems to be taking a while.

Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

    You may also like

    ·