Tim Tomes

15.2K posts

Tim Tomes banner
Tim Tomes

Tim Tomes

@LaNMaSteR53

Believer † | Husband :-* | Father \o/ | Veteran o7 | PractiSec | "Burp Suite master and king of making HTTP requests tremble."

Upstate South Carolina 参加日 Ağustos 2009
122 フォロー中8.1K フォロワー
固定されたツイート
Tim Tomes
Tim Tomes@LaNMaSteR53·
If you've seen me present, you know I introduce myself as a follower of Jesus. Everyone has an opinion of what that means. Can I challenge you to watch this explanation? It's more important than anything I've ever said, and may surprise you. youtu.be/ykH8E9wTCcQ
YouTube video
YouTube
English
2
1
27
0
Tim Tomes
Tim Tomes@LaNMaSteR53·
It's the last week to sign up for Practical Web Application Penetration Testing (#PWAPT) and the Practical Training Bundle. Class starts next Monday! practisec.com/events/
English
0
0
5
322
Tim Tomes
Tim Tomes@LaNMaSteR53·
Just submitted a talk titled "Web Application Authorization: Taming the Perfect Storm" to the @WWHackinFest CFP. I am particularly excited about this one. It's the first time I'll be sharing how I tackle authorization outside the classroom, plus a few extra goodies.
English
0
0
7
357
Tim Tomes
Tim Tomes@LaNMaSteR53·
Greetings! There are 2 training opportunities currently available on my events page at practisec.com/events/: * PWAPT beginning April 7th * PBAT beginning June 9th Bundle them and save $500!
English
0
0
0
229
Tim Tomes
Tim Tomes@LaNMaSteR53·
Just pulled this gem out of a client code base: "AESKey": "dsfsfdfgsdfsgfdg", I guess their version of a cryptographically secure RNG is to smash the 4 main fingers of their left hand on the keyboard 4 times.
English
1
1
6
313
Tim Tomes
Tim Tomes@LaNMaSteR53·
@Ch33z_plz There is admin enforcement in the actual code, but I left out for brevity. Probably should have made that more clear. But yes, your disgnosis is correct. Lastly, the route for `schedules`, is missing the preceding `/`, which means it isn't a match and can already be accessed.
English
0
0
0
24
Ch33z_plz🧀🐀
Ch33z_plz🧀🐀@Ch33z_plz·
@LaNMaSteR53 The middleware tries to block admin pages by checking the last part of the URL, but it's flawed. Attackers can bypass it with extra path segments (/customers/123), uppercase, or query params. There's no real admin enforcement, just a log, so unauthorized users still get through.
English
1
0
1
30
Tim Tomes
Tim Tomes@LaNMaSteR53·
This is real code I am working with today. This is an authorization check protecting admin-only resources. There are multiple ways to bypass this. What are they? For additional context, this is middleware for an Express.js back end.
Tim Tomes tweet media
English
1
0
1
431
Tim Tomes がリツイート
Tim Medin
Tim Medin@TimMedin·
Join us on the @RedSiege Wednesday Offensive with @LaNMaSteR53 discussing testing web apps for authorization issues. Join us for just 30 minutes (and no slides!) at redsiege.com/wedoff. Awkward fam photo time!
Tim Medin tweet media
English
0
1
3
552
Tim Tomes
Tim Tomes@LaNMaSteR53·
As always, I thoroughly enjoyed presenting at WWHF and appreciate the opportunity. If you enjoyed the content of my presentation, then keep an eye on my socials, as I will be announcing my first training opportunities for 2025 in the next week. Happy New Year everyone!
Wild West Hackin' Fest@WWHackinFest

Check out @LaNMaSteR53 's talk, "{JWT}.{ Misuse}. & Abuse," from Wild West Hackin' Fest - Deadwood 2024! youtube.com/watch?v=L4W7Cm…

English
0
1
7
1K
Tim Tomes
Tim Tomes@LaNMaSteR53·
@PortSwigger What parts of the API were added? The dropdown documentation looks the same. Is the AuditIssue class accessible?
Tim Tomes tweet media
English
0
0
2
140
Tim Tomes
Tim Tomes@LaNMaSteR53·
Anyone on my feed have a connection with the Carolina Hurricanes?
English
0
0
1
405
Tim Tomes
Tim Tomes@LaNMaSteR53·
I was literally saying this to a friend the other day and wondered if I was the only one that noticed. I'm glad I'm not. tidbits.com/2024/11/11/mis…
English
0
0
1
368
Tim Tomes
Tim Tomes@LaNMaSteR53·
@hacks2learn My pleasure. The filtering capabilities are in the proxy configuration panel. It behaves like a split-tunnel for HTTP traffic. Pretty awesome. Make sure you set FoxyProxy to proxy by filters though, or they won't apply.
English
0
0
1
28
hacks2learn
hacks2learn@hacks2learn·
@LaNMaSteR53 Thanks for the FoxyProxy filter tip! I use it, but obviously to it's full potential 😀
English
1
0
0
33
Tim Tomes
Tim Tomes@LaNMaSteR53·
I actually use the FoxyProxy browser extension to accomplish this. It's another tool you have to install (downside), but it persists across projects (upside). Thanks for the tip!
English
1
2
5
797
Tim Tomes
Tim Tomes@LaNMaSteR53·
I'm going to try and be more active on this platform again. Any tips for finding favor with the algorithm? My engagement is next to zero, and it doesn't seem to matter how many followers I have. Thanks!
English
3
0
3
734
Tim Tomes
Tim Tomes@LaNMaSteR53·
@jessecooper Communities and Spaces? ... I've been gone for a while. I got some catching up to do.
English
0
0
0
47
jessecooper
jessecooper@jessecooper·
@LaNMaSteR53 Maybe posting in some of the communities? Also spaces for live quick discussions or demos.
English
1
0
0
43
Tim Tomes
Tim Tomes@LaNMaSteR53·
@bl4nk_io Bah. That's too bad. Maybe I can add some value. I'll try not to be a bot.
English
1
0
1
53