@Hyperoptic@Hyperoptic your 12 hour SLA has been violated multiple times with delays over days. The best you've done so far is a single reply to multiple emails over the course of days. And even that one took 2 days, 16 hours, 42 minutes.
Why are you so bad at this?
@Hyperoptic for over a week now I've been experiencing drop-outs on my internet connection and and for 6 days I've been largely ignored by your support team. You used to have excellent competent staff and now it's a frustrating mess to deal with you.
I asked ChatGPT to give me a #BurpSuite Bambda Custom Action to update cookies in Repeater based on the response so I don't need to do it manually when my token/ticket is being renewed.
It works well:
https://t.co/WXEuQgtdLw
As a…
– Twitter user
I want…
– unlimited interactivity – centered in audio, video, messaging, payments/banking – creating a global marketplace for ideas, goods, services, and opportunities.
so that…
– It’s no longer possible to even parody this fucking shitshow.
Our Academy developers take deleting Carlos very seriously... Share your Academy devotion snaps using #deletecarlos - the best ones will win some exclusive swag!
@alehresmann@WebSecAcademy@PortSwigger We don't have a blog post but if you email me I'll be happy to give you an overview and answer any questions you have :)
@JLLeitschuh@streetsofboston@PortSwigger And rather than `.normalize()` we could go even further to make sure that a traversal can't pivot via symlinks by using `.toRealPath()` - but that does IO
@JLLeitschuh@streetsofboston@PortSwigger I prefer `Path.of(BASE_DIRECTORY, userInput).normalize().startsWith(BASE_DIRECTORY)` - it's prettier sticking to a single type imho (excluding String and boolean!)
If you'd like to try DOM Invader out (on our Early Adopter channel) with a real CSPP vulnerability, we've hidden one in our Gin & Juice Shop; see if you can exploit it! #CSPP https://t.co/nImkEFp7wP