Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @_staaldraad
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @_staaldraad
-
Prikvačeni tweet
Here is my write-up of the new Git RCE vulnerability. Covers the process of discovery, stumbling, exploiting and disclosure.https://staaldraad.github.io/post/2018-06-03-cve-2018-11235-git-rce/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
& Stalmans proslijedio/la je Tweet
I work with the
@IWFhotline in helping poke fingers into the eyes of those who feel they can abuse children by using technology to hide. They are desperate for anyone who knows databases and can offer time in helping make theirs better and more efficientPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
& Stalmans proslijedio/la je Tweet
We issued a micropatch for CVE-2017-11774, a remote code execution vulnerability in Outlook that has been widely exploited and remains popular with attackers. In contrast to official patch which could be reverted by non-admins, micropatch will reliably disable Outlook Home Page.pic.twitter.com/3MW0l0PvuV
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
yay! Two distinct solutions from
@Marcus_Noble_ and@SARICAMelih Love things like this because you always get to learn something new from how others approach the problem
https://twitter.com/_staaldraad/status/1205385009621864453 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
A mini challenge, can you read the file at `data/flag`? https://cat-my-file.herokuapp.com/
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
& Stalmans proslijedio/la je Tweet
It's FRIYAY and here's Terrier, slides and a cheatsheet repo as mentioned in our
@BlackHatEvents EU talk. Terrier-> https://github.com/heroku/terrier Slides+Cheatsheets ->https://github.com/heroku/bheu19-attacking-cloud-builds …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
& Stalmans proslijedio/la je Tweet
Aaaaaaannnnd now I've made it public
https://twitter.com/vashta_nerdrada/status/1202698503870246912 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
New write-up: Command injection is usually mitigated but argument injection is often overlooked. An example of an argument injection chain leading to code execution:https://staaldraad.github.io/post/2019-11-24-argument-injection/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Excellent write-up and really fun bug.https://unit42.paloaltonetworks.com/docker-patched-the-most-severe-copy-vulnerability-to-date-with-cve-2019-14271/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
& Stalmans proslijedio/la je Tweet
Hiring! We have popsicles*!! *popsicles not provided, we are a near 100% remote team, but don’t let that stop you from reaching out because the partial list below beats popsicleshttps://twitter.com/_staaldraad/status/1195252860885372928 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
If you still aren't convinced (or just curious), here are just a few things we have worked on recently: https://blog.heroku.com/bug-bounties-black-swans … https://blog.heroku.com/applying-seccomp-filters-on-go-binaries … https://blog.heroku.com/identifying-ruby-ftp-cve … https://blog.heroku.com/exploration-of-security-when-building-docker-containers … https://github.com/brompwnie/botb https://www.youtube.com/watch?v=QPCI69vKN04 …https://www.youtube.com/watch?v=hUhXulSelUQ …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
My team at Heroku is hiring! If you want to chat about what we do, want to know what the culture of the team is like or if you have any other questions, my DMs are open. https://www.heroku.com/careers/principallead-platform-security-engineer-17 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Means avoiding the official Docker base images and their dodgy/weird build process and non history. See this for more context:https://twitter.com/spidler/status/1187656254170251264?s=21 …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Pretty excited about this. Building a Docker “scratch” image directly from Ubuntu source (no Docker base layer). And then using that to build a CI image. Verification each step of the way and exact knowledge of what is on the image. Updates are a ‘git push’ away and full history.pic.twitter.com/Lve54q8zpN
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
& Stalmans proslijedio/la je Tweet
OHAI!! So turns out I’ve got an extra ticket to
@kawaiiconNZ and would like to give that to a deserving soul...Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
With the evil genius of
@brompwnie and@uchi_matahttps://twitter.com/BlackHatEvents/status/1179396106024824833 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
We've had a lot of fun with this research, and I'm really looking forward to sharing it with everyone
@BlackHatEvents Europe.https://twitter.com/brompwnie/status/1177520368308969472 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
& Stalmans proslijedio/la je Tweet
Know what’s better than waking up to see what your team has been pwning while you slept? Having the
@heroku engineering teams creating/releasing a fix in ~10mins, and then going the extra mile because they care. Symbiosis folks.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
CVE-2019-13139 ; command injection in `docker build`: https://staaldraad.github.io/post/2019-07-16-cve-2019-13139-docker-build/ …pic.twitter.com/rFpNCAZD2o
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
New blog post up! Bypassing a Docker AuthZ plugin and using docker-containerd for privesc.https://staaldraad.github.io/post/2019-07-11-bypass-docker-plugin-with-containerd/ …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
& Stalmans proslijedio/la je Tweet
On my way to Boston to attend the first
#AWSreInforce, any restaurant recommendations or just foodie places in general?Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.