We're open sourcing new Semgrep rules to detect CSRF and CORS misconfigurations in Apollo GraphQL. Check out how we used Semgrep's taint mode to make the rules more accurate and easier to write. https://t.co/8kj4R7PI8M
Earlier this week, a post detailed how we escaped Webviews in real-world misconfigured VSCode extensions. But can you escape the extensions if they are well-configured? (Hint: You can and we did.) https://t.co/5m827vUYVy
Why should you care about the security of VSCode extensions? How does compromising a local machine, stealing all local files from that machine, or even swiping your SSH keys sound? https://t.co/rlUU1MaloX
It was an honor to speak at @h2hconference. Thanks to all of you that attended the talk and thank you @gynvael and @bsdaemon for choosing my article as best securiy/RE in issue #1 of @pagedout_zine and giving me this opportunity. #H2HC#H2HC2019
Paged Out! #1 is out! (and it's free to download!)
https://t.co/XT3HXa7gH3
There are 57 articles in 12 categories:
Electronics
Programming
Assembly
Reverse Engineering
Sec/Hack
Retro
File Formats
Algorithmics
SysAdmin
Radio
Phreaking
OS Internals
Enjoy! #PagedOut!
All articles for Paged Out! reviewed!
Now we just need to finish the PDF-making scripts :)
Expect Issue #1 to be out around DEF CON this week*.
* Subject to Murphy's law