Can I just say how DAMN refreshing that James starts off with a side no-one talks about: the fear we all have of the subject and failures along the way.
-
Prikaži ovu nit
-
Now we all know RFCs right? RFC 2616 #4.4.3 says that if you get a message with both transfer-encoding AND content-length, the latter MUST be ignored. But who reads the docs??
1 reply 0 proslijeđenih tweetova 3 korisnika označavaju da im se sviđaPrikaži ovu nit -
The Kettle Break The Web© methodology. it's based upon timing and on influence.pic.twitter.com/avax1zhRkO
1 reply 0 proslijeđenih tweetova 2 korisnika označavaju da im se sviđaPrikaži ovu nit -
Ok Jesus wept bugbounty crowd, stop DMing me. Here's the simple trick. Buy a copy of
@PortSwigger and support Daffs growing fancy shirt collectionpic.twitter.com/W9GtfcKbop
1 reply 0 proslijeđenih tweetova 9 korisnika označava da im se sviđaPrikaži ovu nit -
Attack one: bypassing front-end rulespic.twitter.com/aPOnWqcxgM
1 reply 0 proslijeđenih tweetova 2 korisnika označavaju da im se sviđaPrikaži ovu nit -
Attack two: request reflection Cool thing here is that the request gets concatenated onto the other POST login request. That's sexy af!pic.twitter.com/NqWeQ1B4lr
1 reply 0 proslijeđenih tweetova 5 korisnika označava da im se sviđaPrikaži ovu nit -
The X-Forwarded headers are so misunderstood and at the same time so widely used.pic.twitter.com/aRFCC89NDQ
1 reply 0 proslijeđenih tweetova 6 korisnika označava da im se sviđaPrikaži ovu nit -
PSA: F5 didn't seem to think that this was enough to issue a patch but just an advisory.pic.twitter.com/n96u43N4dq
1 reply 0 proslijeđenih tweetova 2 korisnika označavaju da im se sviđaPrikaži ovu nit -
When James says "accidental" and "cache poisoning" and then making many accessing a well-known homepage automatically hit the burp collaborator, to grab an image Accidental, pfftpic.twitter.com/SXrsnpnP7U
1 reply 1 proslijeđeni tweet 4 korisnika označavaju da im se sviđaPrikaži ovu nit -
He is the Dwayne Johnson of infosec and bug bounties. Such a ballerpic.twitter.com/0O0kssUN5J
0 proslijeđenih tweetova 6 korisnika označava da im se sviđaPrikaži ovu nit
The demo video truly shows how friggin amazing this research is and has earned him over 90,000 USD. Seriously I couldn't be more of an appsec fanboy at this moment in timepic.twitter.com/2oCpk3bMZD
-
-
The defensive side is actually the most important. We really need to push adoption of HTTP/2 overall. Many said WAFs solve this, no no no they will only ever be bandaids.pic.twitter.com/mGZGkBvqxG
0 replies 1 proslijeđeni tweet 9 korisnika označava da im se sviđaPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.