The https://t.co/HApBDuaJaR post by @xoreipeip shows how prepared statements can be exploited in NodeJS using mysql and mysql2 packages leading to SQLi! 🪄
So use of prepared statement might not be the ultimate solution here 🥵
as a side note, @xoreipeip later found this overlooked article with similar concept after doing his own original research: https://t.co/mWRaQxDnUI
Many thanks to @xoreipeip for presenting his talk "Server-Side Cross-Site Scripting" #XSS at the #OWASPLondon Chapter meetup last week!
The video recording of the talk is now available to watch on our YouTube channel 📺 [PLEASE SUBSCRIBE!]:
👇
https://t.co/kJSZXsOjdG
The next OWASP London Chapter in-person Meetup will take place on Thursday 17th July 2025 kindly hosted by Civo Tech Junction and kindly sponsored by @BlackDuck_SW
Talks from @xoreipeip and Matthew Brady
- Register to attend here:
👇
https://t.co/lziG3WzE0f
I've written a free book to help non-technical readers understand and avoid scams.
It's designed for friends, grandmas, moms&pops. Anyone who might be vulnerable to online or phone scams. Please help spread the word and protect your loved ones.
LINK: https://t.co/BBfKhwlb2R
We've got two talks tomorrow evening at the Greene Man! @xoreipeip is talking about Cisco phones, and Nick Dunn https://t.co/14XyQwrk9b will explain SOSL injection #defcon#london
🚀 #x33fcon 2025 Onsite Workshop! 🚀
Join @xoreipeip to master software reverse-engineering with Unicorn Engine! Learn to dynamically execute and analyze code to crack encryption and obfuscation in binaries using Python and Ghidra. Perfect for #malwareanalysis, #vulnerabilityresearch, and #embeddeddevice hacking.
Details: https://t.co/UfBRtzpXDF
🎤 Speaker Announcement 🎤
We’re excited to welcome @xoreipeip to the stage!
His talk?
“Is Your Phone Spying on You? An In-Depth Analysis of Vulnerabilities in Cisco VoIP Phones”
Don’t miss this deep dive into device-level security.
#BSidesBirmingham#BSides
Please welcome Balazs Bucsay with their talk on 'Is Your Phone Spying on You?'
Sponsored by Optimising IT | B Corp™, CyberCX, Cydea and Orange Cyberdefense.
Grab your ticket today https://t.co/I0DdHrcHpi
#oooarrcyber
Next stop: Prague, Czech Republic! Join us at our Unicorn Workshop at BSides Prague - solve our challenges and win a couple of pints! 🍻 @bsidesprg#bsidesprg#bsidesprague
Our workshop, Defeating Encryption Using the Unicorn Engine will be held at @BSidesLondon this Saturday. All tickets are sold out, but @xoreipeip will be around for the whole day to chat.
Thrilled to announce that our CEO will be hitting the stage at #BSidesLjubljana this Friday with an unmissable talk on Server-Side Cross-Site Scripting! Get ready for some cutting-edge insights and live demos about how to take over the cloud with alert(1).