"Vertical slice architecture is about focusing on your use cases. CRUD is the exact opposite of that. CRUD doesn’t capture intent. When you organize code around features, you’re explicitly capturing your system’s capabilities. " https://t.co/0SXjF7mhyn
Should you care about design patterns? There are books devoted to them; heck, even I post videos about specific design patterns. But do they matter?
https://t.co/o0lQsmcSAu
CoRJail: From Null Byte Overflow To Docker Escape Exploiting poll_list Objects In The Linux Kernel
D3v17 published an article describing the solution of their @cor_ctf challenge CoRJail.
https://t.co/7G7LvteyEz
Orchestration and workflow tools have been around for a while, and the major public clouds all offer these sorts of things as built-in services.
@codeopinion offers a good overview of how to use "workflow orchestration for resilient systems" ... https://t.co/wd2UYqYDgX
[1/2]
"Fun" for today... we have the industry standard NIST SP 800-63B "NIST SP 800-63B DIGITAL I DENTITY G UIDELINES :
AUTHENTICATION & LIFECYCLE M ANAGEMENT". This states that complexity wise passwords at minimum should contain on-alphabetic characters, for example, !, $, #, %
Happy Friday! Looking to learn a little more about #ghidra or software RE? Here is a quick thread with some resources that I've put together over the years (1/6) 🐉
A backlog, if you have one, lists domain-level problems that your customers need solved. It is not a to-do list. It is not a set of things your stakeholders want. It is not a set of modifications to your system. It does not describe _your_ work. It describes your customers'.
My new article about hacking the Zircon microkernel of Fuchsia OS
"A Kernel Hacker Meets Fuchsia OS"
https://t.co/5GQHhceHiB
🟪 Fuchsia security architecture
🟪 My exploit dev experiments for the Zircon microkernel
🟪 PoC attack planting a rootkit into the microkernel
Enjoy!
I thought quite a bit about this extension of Conway's Law, which is taking the flexibility of the system under change into account. Here are some unsorted and maybe random thoughts from my experience of doing an inverse Conway maneuver on a larger scale at Flix. #SoftwareDesign
“When you relegate your business logic to services that operate on an anemic, behavior-free domain model, your domain model types are nothing but DTOs and you're more likely to have problems with your model.” On anemic models by @ardalis https://t.co/6vrf0kLnnX
Common advice is to abstract dependencies. While this is generally true, it depends. You don't want to create an abstraction that is more work in the short and long run that adds little value but adds unneeded complexity.
https://t.co/K7BcMCONq9
Windows Kernel Exploitation Tutorial
Part 1: Setup
https://t.co/lFkT2Nl530
Part 2: Stack Overflow
https://t.co/iIZZORGVci
Part 3: Memory Overwrite
https://t.co/7YuhjQViUi
Part 4: Pool Overflow
https://t.co/TI9AIlYjwt
Part 5: NULL Pointer Dereference
https://t.co/rEO6VmCMe0
Blogged: How do you handle processing large payloads? Make it asynchronous with message broker! Combined with the Claim Check Pattern to keep message sizes small to not exceed any message limits or cause performance issues with your message broker.
https://t.co/tV6h8VOW2C
GraphQL security checks and exploitation vectors: https://t.co/r0dxQmxSiv
BatchQL: a GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations (GitHub repo): https://t.co/SqrvtzWgSQ credit @assetnote