tprime

623 posts

tprime banner
tprime

tprime

@tprime_

Sr. Security Consultant

サイベリア Katılım Eylül 2010
777 Takip Edilen424 Takipçiler
tprime
tprime@tprime_·
Interesting whitepaper from 2019 by @AndresRiancho about insecure AWS Cognito configurations. I wonder if anyone has done something similar, but for applications which mistakenly expose the SignUp endpoint? andresriancho.com/internet-scale…
English
0
0
1
0
tprime
tprime@tprime_·
@Viss Thanks for the reminder. I remember wandering into this talk at DC19 and being really glad I did.
English
0
0
0
0
tprime
tprime@tprime_·
hmmm....
tprime tweet media
0
0
3
0
tprime
tprime@tprime_·
@sylv3on_ I recommended following that book with The Tangled Web if you haven't read it already. They compliment each other really well.
English
0
0
0
0
tprime
tprime@tprime_·
the agenda at #CLSI2019 looks awesome... would love to attend one day
English
0
0
0
0
tprime
tprime@tprime_·
Managed to get a nice hike in during a rural onsite
English
1
0
5
0
tprime
tprime@tprime_·
disappointing to see journalists apologizing for or celebrating government censorship in #srilanka
English
1
0
1
0
tprime
tprime@tprime_·
@Alra3ees This option also exists in the GUI under 'User options -> SSL -> Disable Java SNI extension'!
English
0
0
3
0
tprime
tprime@tprime_·
@brutelogic perhaps, I just prefer the approach of whitelisting like with CSP instead of depending on the filtering cat-and-mouse game.
English
1
0
1
0
Brute Logic
Brute Logic@BRuteLogic·
@tprime_ CSP can be highly effective but it's a policy not a filter.
English
1
0
1
0
Brute Logic
Brute Logic@BRuteLogic·
Who does a better job as a 2nd line of defense against #XSS?
English
4
2
11
0