Ed

1.2K posts

Ed banner
Ed

Ed

@EdOverflow

Web developer & security researcher. Senior Pentester @cure53berlin. Author of @securitytxt. ➡️ https://t.co/BOy1tiLLBr

شامل ہوئے Ekim 2016
160 فالونگ20.1K فالوورز
پن کیا گیا ٹویٹ
Ed
Ed@EdOverflow·
After 5 years of work, security.txt is officially an RFC. I am pleased to announce RFC 9116: rfc-editor.org/rfc/rfc9116. I would like to use this opportunity to thank those who made this possible. Thank you. ❤️
Ed tweet media
English
43
956
2.7K
0
Ed
Ed@EdOverflow·
@codingo_ Excuse me, sir. Do you have a moment to talk about our Lord and Saviour, security.txt?
English
0
0
14
789
Ed
Ed@EdOverflow·
I will be giving a talk on Coordinated Vulnerability Disclosure (CVD) at Swiss Cyber Storm. If you are interested in attending, please find additional information below.
swisscyberstorm@swisscyberstorm

Speaking @swisscyberstorm 2023 Edwin Foudil (@cure53berlin): “Navigating The Coordinated Vulnerability Disclosure Landscape” Demystifying concepts surrounding CVD and showing solutions to overcome challenges Program: lnkd.in/d52RpEnH Tickets: lnkd.in/eTXQRjnP #SCS23

English
1
2
14
5.7K
Ed
Ed@EdOverflow·
@ElSec_ 👏
QME
0
0
1
172
Ed ری ٹویٹ کیا
security.txt (RFC 9116)
security.txt (RFC 9116)@securitytxt·
Where did you first hear about security.txt?
English
7
2
2
4.2K
Hussein Daher
Hussein Daher@HusseiN98D·
Is there any open source tool / paid service that will fetch response of a list of URLs every day and alert on status code / content length change?
English
18
4
101
38K
Hac
Hac@Hac10101·
Any tips for a person who is starting with bug bounty? #infosec
English
13
6
68
15.7K
Ed ری ٹویٹ کیا
security.txt (RFC 9116)
security.txt (RFC 9116)@securitytxt·
How do you pronounce "security.txt"?
English
2
2
14
7.6K
Ed ری ٹویٹ کیا
security.txt (RFC 9116)
security.txt (RFC 9116)@securitytxt·
Exciting news! @Apple joins the list of companies with a security.txt file. Now, we only need @netflix to complete the FAANG list. 🙌
security.txt (RFC 9116) tweet media
English
6
84
658
199.8K
Ed
Ed@EdOverflow·
I have been playing around with SvelteKit a lot recently. I wrote a short blog post on adding security headers to SvelteKit applications: edoverflow.com/2023/sveltekit…. I might do a more long-form one on the security pitfalls of SvelteKit applications at some point.
Ed tweet media
English
1
4
25
5.5K
Ed
Ed@EdOverflow·
@ant0inet 3️⃣ Finally, realising that *.cust.swisscom.ch is out of scope
English
1
0
6
1.1K
Ed
Ed@EdOverflow·
Reminder: if you would like to follow my blog via RSS, I have a feed at edoverflow.com/index.xml. :)
English
0
0
7
3.1K
Ed
Ed@EdOverflow·
I have published a new blog post on my bug bounty methodology: "Learn to build it, then break it" — edoverflow.com/2023/learn-to-….
English
4
38
191
23.3K
Ed
Ed@EdOverflow·
@ant0inet There is a recent publication (12 Jan 2023) where the authors explored these factors and even ranked each factor's importance with a survey: arxiv.org/pdf/2301.04781…. Learning and building a career are some of the other factors not mentioned in your tweet.
Ed tweet media
English
2
0
5
946
so long and thanks for the phish
In your opinion, what are the other drivers for vulnerability researchers to disclose vulnerabilities besides recognition and financial gain? I can't seem to find other obvious motives...
English
11
0
7
5.4K