AppSec Charlie

11 posts

AppSec Charlie banner
AppSec Charlie

AppSec Charlie

@AppSecCharlie

application security person with an interest in music, AI, and digital art

شامل ہوئے Eylül 2019
49 فالونگ3 فالوورز
Calvin Wilkinson (Kinson Digital)
Well, I thought I was caught up on dependency updates until I added a dependabot.yml file to the project. 🤔
Calvin Wilkinson (Kinson Digital) tweet media
English
2
0
3
65
AppSec Charlie ری ٹویٹ کیا
Simone Margaritelli
Simone Margaritelli@evilsocket·
* Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago. * Full disclosure happening in less than 2 weeks (as agreed with devs). * Still no CVE assigned (there should be at least 3, possibly 4, ideally 6). * Still no working fix. * Canonical, RedHat and others have confirmed the severity, a 9.9, check screenshot. * Devs are still arguing about whether or not some of the issues have a security impact. I've spent the last 3 weeks of my sabbatical working full time on this research, reporting, coordination and so on with the sole purpose of helping and pretty much only got patronized because the devs just can't accept that their code is crap - responsible disclosure: no more.
Simone Margaritelli tweet media
English
82
491
2.8K
364.5K
AppSec Charlie ری ٹویٹ کیا
Christopher Stanley
Christopher Stanley@cstanley·
This is a wake up reminder that you shouldn’t have an internet connected privileged binary running on your production systems. What was a bad update could have easily been a massive adversary backdoor. A third party vendor will always be the weakest link. Isolate critical systems
English
698
1.9K
11.7K
27.2M
AppSec Charlie
AppSec Charlie@AppSecCharlie·
@Jr0dR87 Users can make themselves admin, password likely stored in plaintext, no validation on username/password (not checking for malicious input or that they meet requirements like password complexity). All running in debug mode so attackers get nice helpful error messages
English
0
0
0
3
Jarrod
Jarrod@Jr0dR87·
Can you see the vulnerability in this python code?
Jarrod tweet media
English
111
49
561
111.6K
AppSec Charlie
AppSec Charlie@AppSecCharlie·
@github build stuff, a lot. reading all the books and taking all the courses are useless if you don't practice solving real problems.
English
0
0
0
3
GitHub
GitHub@github·
What advice would you give to someone just starting out as a developer?
English
427
104
1K
375.5K