Kamil Vavra
412 posts

Kamil Vavra
@vavkamil
Application Security Engineer | Burp Suite Certified Practitioner | Offensive Web Application Security | OWASP Czech Chapter Leader
Czech Republic Katılım Kasım 2018
100 Takip Edilen1.6K Takipçiler
Kamil Vavra retweetledi
Kamil Vavra retweetledi

Dear OWASPers, you can register for our upcoming event here eventbrite.com/e/owasp-czech-…. The CZ chapter meeting takes place on 4th of December. See you there 😎
English
Kamil Vavra retweetledi
Kamil Vavra retweetledi

Hey all 👋 it is a pleasure to announce, that registration for upcoming OWASP chapter meeting is open, grab your ticket here: eventbrite.com/e/1339881524709
English

I had an idea for a tool and asked ChatGPT to generate it. JS Snitch is a command-line tool that scans remote JavaScript files for leaked secrets or potential credentials with Trufflehog + Semgrep
github.com/vavkamil/js-sn…
I already found some great secrets in the wild :)
English
Kamil Vavra retweetledi

Dear followers, we would love to let you know that there is going to be #owasp #chapter #meeting in Prague next week. Feel free to register here eventbrite.com/e/owasp-czech-…. Capacity is limited, so don't wait with the registration.
English
Kamil Vavra retweetledi

.@Volexity’s latest blog post describes in detail how a Russian APT used a new attack technique, the “Nearest Neighbor Attack”, to leverage Wi-Fi networks in close proximity to the intended target, while the attacker was halfway around the world.
volexity.com/blog/2024/11/2…
#dfir
English
Kamil Vavra retweetledi

I'm thrilled to finally share my research on HTML parsing and DOMPurify at @GreHack 2024 📜
The research article is available here: mizu.re/post/exploring…
The slides are available here: slides.com/kevin-mizu/gre…
1/3

English
Kamil Vavra retweetledi

Hey! The next OWASP event in Brno will happen in a week:)
Grab your tickets on the following link 🤓
eventbrite.com/e/owasp-czech-…
English
Kamil Vavra retweetledi

Learn how to conceal payloads in URL credentials and abuse them for DOM XSS and DOM Clobbering.
portswigger.net/research/conce…
English

@vavkamil @PortSwiggerRes @garethheyes @albinowax @vavkamil Everything should work now. Launching a new service is not an easy task 🚀
English

Upgrade your SSRF, CORS & Open Redirect testing with our new URL Validation Bypass cheat sheet, containing all known techniques! portswigger.net/web-security/s…
English

@d4d89704243 @PortSwiggerRes @garethheyes @albinowax Does it work? I'm not getting any DNS answer on the subdomain
English

@PortSwiggerRes This is the result of the hard team work. Many thanks to the @garethheyes and @albinowax for helping me with. We really hope that you’ll like it.
English
Kamil Vavra retweetledi

See you in 2 days in a new venue! x.com/OWASP_Czech/st…
OWASP_Czech@OWASP_Czech
Hello OWASP fellows, next Brno event will be on May 14th at Atlas Copco! We are still finalizing speakers, so let us know if you have something interesting to talk about. New venue should assure more crisp presentations and no background noise. Sign up eventbrite.com/e/owasp-czech-…
English
Kamil Vavra retweetledi

Hello all, the last event of this year is comming! See you on December 13th🥳
eventbrite.com/e/770129807987/
English
Kamil Vavra retweetledi

@garethheyes @albinowax @WebSecAcademy No way, I tried random email and solved the lab :D Thank you!
English

We've just published a new @WebSecAcademy topic on GraphQL! Learn how to abuse introspection, discover hidden data, bypass rate-limits, and trigger CSRF with this popular API technology.
portswigger.net/web-security/g…
English

@albinowax @WebSecAcademy Yep, sorry, I sent the payload to support email, but then noticed it was eventually solved. Still not a clue what I did wrong :)
English

@vavkamil @WebSecAcademy We have automated tests that verify all labs are solveable - and someone's already solved all five labs - so it's likely you're doing something wrong. Not sure what though!
English
