Pedro Fortuna

@pedrofortuna

Co-Founder & CTO | Speaker at and events | contributor | The Client-side is the new battlefront!

Vrijeme pridruživanja: travanj 2009.

Tweetovi

Blokirali ste korisnika/cu @pedrofortuna

Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @pedrofortuna

  1. proslijedio/la je Tweet
    24. sij

    Our research on Safari's Intelligent Tracking Prevention (ITP) is now available on cc

    Poništi
  2. 19. sij

    Super cute holidays gift from our friends thank you 🙏

    Poništi
  3. 3. sij

    Hey twitter, can you please recommend me good online web security trainings, preferably with a bit of hands-on, for beginners/mid-level ?

    Poništi
  4. 26. stu 2019.

    No wonder! A JSON parser is WAY simpler than a JS parser.

    Poništi
  5. 9. stu 2019.
    Poništi
  6. 7. stu 2019.

    Next week is hosting its 5th Security masterclass in . Our 2nd speaker is founder and VP Eng . Luisa will help shed some light into the concept of Security. Surely not to miss! RSVP ASAP:

    Poništi
  7. 5. stu 2019.

    Next week . is hosting its 5th Security masterclass in . Our 1st speaker is founder and CEO . Avi will do a generous 2h session on . Surely not to miss! RSVP ASAP:

    Poništi
  8. 28. lis 2019.

    Also, we rolled out a newsletter. Please subscribe and be the 1st to know about future Security Masterclasses:

    Prikaži ovu nit
    Poništi
  9. 28. lis 2019.

    On November 11th is hosting its 5th Security masterclass, with two special guests: and . Not to miss if you are around Porto on that date. More details and RSVP here:

    Prikaži ovu nit
    Poništi
  10. 23. lis 2019.

    How about letting users add custom policies to npm audit? e.g. if last update came from TOR, fail my build

    Prikaži ovu nit
    Poništi
  11. 23. lis 2019.
    Prikaži ovu nit
    Poništi
  12. 8. lis 2019.

    You have an iframe sandbox="allow-scripts allow-same-origin". You control the iframe document. Can you breakout of the iframe and navigate the top window away? Let me know your solutions.

    Poništi
  13. 6. lis 2019.

    Ok found how I can reenable it, by disabling edge://flags/-of-blink-cors. Nice chatting with you 😂

    Prikaži ovu nit
    Poništi
  14. 6. lis 2019.

    Update: an OPTIONS request is definitely sent, but by default your Canary Channel does not display the request in the network tab of devtools. Why?

    Prikaži ovu nit
    Poništi
  15. 5. lis 2019.
    Poništi
  16. 5. lis 2019.

    WTH! is your Canary for MacOS not doing CORS preflights or just not showing the OPTIONS request in the network tab in devtools? Your Dev Channel is working fine!

    Prikaži ovu nit
    Poništi
  17. 5. lis 2019.

    Found the answer in 's OWASP AppSec EU '15 talk about the Rosetta Flash attack. The empty comment is to prevent an attacker from controlling the first bytes of the JSONP response and e.g. trick browsers into handling it as a different content-type.

    Prikaži ovu nit
    Poništi
  18. 5. lis 2019.

    Anyone has a clue why ExpressJS res.jsonp() prefixes JSONP responses with an empty JS comment? e.g. /**/ typeof myCallback === 'function' && myCallback({"data": ... });

    Prikaži ovu nit
    Poništi
  19. 11. ruj 2019.
    Poništi
  20. proslijedio/la je Tweet
    3. ruj 2019.

    A significant Electron.js vulnerability was disclosed recently and could impact several companies that rely on the framework. In this article, discusses how devs can shut this backdoor:

    Poništi

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·