Christian Pedersen wrote a cool scanner for the Netscaler Gateway flaw, and is hosting it on Azure.&...
Read More
Simon Bennetts reminds me that OWASP ZAP also has a shiny new web presence, and an upgraded executab...
Read More
You know that open S3 buckets are one of my pet peeves - well guess what. Azure isn't any...
Read More
Good Twitter thread on JavaScript based redirection and Cross-site Scripting.
https://twitter.com/ha...
Read More
Austin Schertz won the CodeMash CTF this year, and he dropped off his answers to all 19 challenges.&...
Read More
Post-CodeMash edition!
The Government of Gibraltar had a SQL Injection vulnerability in the s...
Read More
Pre-CodeMash Edition!
Adam Caudill is a personal friend of mine and has forgotten more about...
Read More
It's the holiday edition! No I'm kidding it's the same stuff as usual. Sorry.
App...
Read More
Hope everyone has a good holiday.
You probably heard that the Russian offices of ngnix were r...
Read More
Nice writup that explains a pivot from and iPhone app all the way through to domain access via chain...
Read More
My favorite thing this week: SwiftOnSecurity accidentally dropped a Confluence 0-day on Twitter.&nbs...
Read More
Fortinet is communicating with static keys and a simple XOR. Whoops.
https://sec-consult.com/e...
Read More