one of my engineers reached out to me about how they struggled to find satisfaction in their work in the age of AI. I asked them if I could publish our brief exchange, and they agreed. I know people are feeling similarly, so maybe they can relate. https://t.co/YbeImE6aId
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame" is coming to #DEFCON33! This talk will feature multiple new classes of desync attack, mass exploitation spanning multiple CDNs, and over $200k in bug bounties. See you there!
Shame that @SkyNews is doing the kind of research that our mainstream news channels should have done.
Instead of focusing their MASSIVE resources on exposing terror in Pakistan - they are blaring sirens in their studios & creating panic nowhere else but India.
New post: Deep dive into JWT attacks — none alg, alg confusion, kid injection & more.
Learn how to break (and fix) real-world JWT issues!
🔗 https://t.co/XkbajJexoD
#AppSec#JWT#WebHacking#InfoSec
@xavvierrrrrr What's the point when both are hell-bent to throw away your tax money.
This has to be the most fuckall election of all time. Did not even bother to vote this time . . .
🔥We have big news for you, NetExec now has a new protocol: NFS🔥
Main features:
- Detecting NFS servers
- List exported shares
- Recursive enumeration of shares
- Up&Download files
Many thanks to @mehmetcanterman who had the idea and implemented the protocol with me.
Here's a link to my first blog on medium tackling "Updown" box on HTB. The machine is rated medium.
Any kind of feedback is highly appreciated.
https://t.co/0tOSBz3V7K