Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @d0znpp
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @d0znpp
-
Ivan Wallarm Retweeted
Download DZone’s 2019
#AppSec Trend Report to read about the future of secure programming, experience how companies have overcome the dangers of digital transformation, and learn why shifting left isn’t enough. http://ow.ly/3Fhu50v98lZ pic.twitter.com/7yQECGhIPh
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
If you are running multiple apps in multiple cloud environments this short video might help to understand how Wallarm can handle that: https://www.youtube.com/watch?v=TIW112tSDUg … As always you can start a free trial at https://us1.my.wallarm.com/signup
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
So CVE-2020-1523 and CVE-2020-1440 are actually powerful SSRF bugs and not just result in "tampering". Likewise CVE-2020-16875 is certainly NOT a memory corruption and I have a full working RCE exploit. https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1523 … https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-1440 … https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2020-16875 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm RetweetedThanks. Twitter will use this to make your timeline better. UndoUndo
-
Ivan Wallarm Retweeted
Clipboard API for browsers is inconsistenthttps://rushter.com/blog/clipboard-api/ …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
Just published confirmed tech specs of Flipper Zero https://flipperzero.one/#tech-specs (Please check for errors) There are still many missing specs for U2F, USB, etc. Will update it while developing.pic.twitter.com/DEKM348t40
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
Bypassing HTML sanitizers via prototype pollution (Sanitizers covered are: DOMPurify, sanitize-html, Closure and xss) : https://research.securitum.com/prototype-pollution-and-bypassing-client-side-html-sanitizers/ … credits
@SecurityMBThanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
unimap: reduce scan times with Nmap for large amounts of datahttps://securityonline.info/unimap-reduce-scan-times-with-nmap-for-large-amounts-of-data/ …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
{“id”:111} --> 401 Unauthriozied {“id”:{“id”:111}} --> 200 OK POST /api/get_profile Content-Type: application/json {“user_id”:<attacker_id>,”user_id”:<victim’s_id>} GET /api_v1/messages?user_id=VICTIM_ID --> 401 GET /api_v1/messages?user_id=attack&user_id=VICTIM --> 200 OK
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
If you are in financial space and still have not signed up for our webinar next week, it's time to do that. We will discuss the most important threads in the Financial space we see today and how to deal with them:https://lab.wallarm.com/modern-security-challenges-for-financial-organizations-september2020/ …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
AWS uses a default security group of 0.0.0.0 when launching EC2 and RDS instances resulting in hosts and DB available to the world, by DEFAULT. Do you think this is a USER problem or an Provider problem?
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
Feels good to find a critical XXE on a program in one hour.
If you haven't heard about local DTDs in XXE yet, check it out here: https://github.com/GoSecure/dtd-finder/blob/698fd678f26395e1c7c097525f7182aecad0cd5f/list/xxe_payloads.md …
Another cool trick with error-based XXE is to access a file starting with colon (:) to trigger a "no protocol" error.pic.twitter.com/jVRuJU6PoY
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
The biggest weak JWT secrets dictionary available publiclyhttps://lab.wallarm.com/340-weak-jwt-secrets-you-should-check-in-your-code/ …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
Fantastic insights from
@NathanLatka from@SaaStrAnnual by@saastr on capital options and their recommended minimum ARRpic.twitter.com/Mqpd1MCunt
Thanks. Twitter will use this to make your timeline better. UndoUndo -
The biggest weak JWT secrets dictionary available publiclyhttps://lab.wallarm.com/340-weak-jwt-secrets-you-should-check-in-your-code/ …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
One of the immensely popular types of attacks in recent times that we see is brute force attacks on APIs. Wallarm helps to deal with that, and you can see how to configure that in this short video below. You can always start a trial https://us1.my.wallarm.com/signup https://www.youtube.com/watch?v=0R_2wL5_a-I&t=2s …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Ivan Wallarm Retweeted
If you did attend our webinar yesterday but would like to learn about Modern Cloud security solutions from Frank Kim feel free to download the deck or watch the recording.https://lab.wallarm.com/webinar-august-cloud-security/ …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
THAT was not easy. But we did it.
#ios14#exploit#zerodaypic.twitter.com/nl6HLXHzt9Thanks. Twitter will use this to make your timeline better. UndoUndo -
Ivan Wallarm Retweeted
If the entire URL is reflected unfiltered in href value, split the payload in different parameters to bypass the WAF
#BugBounty#bugbountytipspic.twitter.com/tRRovit3iT
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.