Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @pwntester
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @pwntester
-
Alvaro Muñoz proslijedio/la je Tweet
OK Google: bypass the authentication! :D by
@s0wdust https://techblog.mediaservice.net/2020/01/ok-google-bypass-the-authentication/ …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
Does anyone remember any explicit (or highly suspected/suspicious) bugdoor attempts in OSS history besides the = vs == uid thing in the Linux kernel?
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
In my team at GitHub, we'd like to study examples of "nefarious commits" in open source, which introduce a bug on purpose. Can you point me at such commits? Could it have been detected by analysing the committer's behaviour as well as the code change itself?
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
Indeed, some of the new challenges were somewhat hard, but I enjoyed them and learned new tricks. Fortunately, I solved them all fast enough, so I didn't lose my first place in the ranking.
These labs are totally recommended, as always!https://twitter.com/WebSecAcademy/status/1221883816299704326 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Nice! Glad the DotNetNuke gadget helped you win
#pwn2own! Feel free to contribute the new bridge gadget to http://ysoserial.net if you want :) https://twitter.com/mufinnnnnnn/status/1221130863523614721 …Tweet je nedostupan.Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
And now Alvaro Muñoz
@pwntester is breaking SAML at the GitHub Security Meetup.pic.twitter.com/NTwk2h5o1H
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
Welcome to 2 new security researchers in the GitHub Security Lab:
@pwntester and@yarlob !Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
Once again, an app without any permission could access restricted information from the Download and TV Providers. The proof-of-concept apps and source code are public too: https://github.com/IOActive/AOSP-DownloadProviderDbDumperSQLiWhere … https://github.com/IOActive/AOSP-DownloadProviderDbDumperSQLiLimit … Fixes for all of them were released in November 2019.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
Last year I published 3 high-severity vulnerabilities in Android (https://ioactive.com/multiple-vulnerabilities-in-androids-download-provider-cve-2018-9468-cve-2018-9493-cve-2018-9546/ …) I did some additional research and reported new similar issues some months ago. These advisories are now public: https://act-on.ioactive.com/acton/attachment/34793/f-5c01ebda-2cb5-47b9-9330-2d71b3a34db6/1/-/-/-/-/cve-2019-2196.pdf … https://act-on.ioactive.com/acton/attachment/34793/f-0b1db136-6474-4c86-b944-0ba96a89283a/1/-/-/-/-/cve-2019-2198.pdf … https://act-on.ioactive.com/acton/attachment/34793/f-0760e60e-1532-4d61-8767-20eec7e2ddf1/1/-/-/-/-/cve-2019-2211.pdf …
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
If you are using TLS client authentication with Java 11 or Java 13 you should patch your servers NOW.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
Here are some examples of vulnerabilities found in the past: CVE-2019-16763 (https://github.com/mpetroff/pannellum/commit/cc2f3d99953de59db908e0c6efd1c2c17f7c6914 …) and CVE-2019-9844 (https://github.com/Khan/simple-markdown/pull/63/commits/a15cddf65215a39f2a31606873b89563db94de1d …)pic.twitter.com/YcAhFJLW12
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
Thursday mini-challenge: Triage some of the bugs on https://lgtm.com/rules/1510852698359/alerts/ … and report interesting ones to the maintainers! We have pretty cool GitHub swag waiting for you.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
1. Never stop learning. 2. See failure as a beginning. 3. Teach others what you know. 4. Assume nothing, question everything. 5. Analyze objectively. 6. Practice humility. 7. Respect constructive criticism. 8. Love what you do. 9. Give credit where it's due. 10. Take initiative.
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
Awesome line-up of speakers for the GitHub Security Meetup, January 22 in San Francisco:
@pwntester@tiraniddo@scovetta@samlanninghttps://www.eventbrite.com/e/github-security-meetup-tickets-86189967513 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
We are excited to announce that
@pwntester, will be presenting "Breaking SAML (.NET Edition)" at the GitHub Security Meetup, Jan 22 San Francisco. http://eventbrite.com/e/github-secur …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Thank you all for the best wishes. I will be joining a team of great security researchers at
@GHSecurityLab. Excited to start contributing to a better and more secure OSS!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
After 9 years at
#Fortify, its time to move on and take on new challanges. Thanks to all the amazing people I met on the way!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
a kid with a weird obsession can invest more free time into something than an adult might have in a decade a nontrivial number of people I know are living off returns on human capital they accidentally created as 14 year olds
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Seems like
#javadeser is hot again! Two talks with great findings at BlackHat EU this week: https://i.blackhat.com/eu-19/Wednesday/eu-19-An-Far-Sides-Of-Java-Remote-Protocols.pdf … https://i.blackhat.com/eu-19/Thursday/eu-19-Zhang-New-Exploit-Technique-In-Java-Deserialization-Attack.pdf …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Alvaro Muñoz proslijedio/la je Tweet
New deserialisation attack vector discussed at
#BlackHatEu which can lead to RCE, done via Jdbc uri ( usually found in fundamental classes, such as URLClassLoader) Combining this attack vector, can bypass all of the blacklists and gain Remote Code Execution.pic.twitter.com/aNzRvdUKHq
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.