My Paste cURL Burp Suite extension is now live in the BApp Store! It allows you to take any curl command (e.g. from API docs) and paste it into Repeater as a raw HTTP request.
https://t.co/mXXnn32knb
While #BCheck from @PortSwigger is still a work in progress, I've already replicated some useful Burp extensions within BCheck. Explore them here https://t.co/qlZxq7da67
Of course, we have to thank you @albinowax and @jahadix@codemagi & more for their incredible original work ๐ช
@ChaseSupport your certificates are expired for https://t.co/kxYX5wJat4. This is preventing pages from loading, particularly the login. When will this situation be fixed?
OWASP Security Logging v1.1.7 released, after much wrangling with the Nexus staging repository (I wonder if this is their busiest day ever?) https://t.co/1jfLgPkWHG
@manicode@omerlh What if a web server parsed all request params into byte[] (that's what an incoming request really is) until they were specifically called for in other types, then overwrote those arrays? If you could go directly from byte[] -> SecureString would that be better?
@manicode@asanso@SchmiegSophie@jedisct1 Sigh* maybe you should explain that if you give out the symmetric (or private) key, you give people the ability to ISSUE tokens, as opposed to just verifying them.
@manicode Maybe not to write secure code. But to create secure _applications_ (many moving parts, high complexity) you need to be able to threat model. And to threat model you must be able to think like an attacker.
@dcuthbert@pinger Sometimes I wonder if the companies aren't signing my email up themselves. Maybe using out as free advertising that evades spam filters. Look we have millions of users! Cool how many are real? That's just it, nobody knows!
@jeremiahg The cities are not comparable size/population. There'll be less in-town demand when they arrive at SLC vs San Jose/Bay Area. When they arrive at SLC those assets will spend more time idle and that's figured into the price of the rental.