nitter
Bil Corry
@bilcorry
CISO at
@sardineai
. Treasurer of
@OWASP
Board of Directors. (he/him) qatta' mIghtaHghach.
Phoenix, AZ
linkedin.com/in/bilcorry/
Joined July 2009
Tweets
8,305
Following
139
Followers
776
Likes
17,402
Tweets
Tweets & Replies
Media
Search
Filter
Retweets
Media
Videos
News
Verified
Native videos
Replies
Links
Images
Safe
Quotes
Pro videos
Exclude
Retweets
Media
Videos
News
Verified
Native videos
Replies
Links
Images
Safe
Quotes
Pro videos
Time range
-
Near
Load newest
Bil Corry
@bilcorry
27 Feb 2010
RT
@timoreilly
: Amazing map showing how the Chilean earthquake's energy is expected to spread through the ocean http://bit.ly/cPFj7D
Bil Corry
@bilcorry
27 Feb 2010
RT
@jeremiahg
: RT haha, the "official" XSS patent
@psifertex
:
@jeremiahg
@RSnake
Fixed it for you: http://bit.ly/bXD7vf <- brilliant!
Bil Corry
@bilcorry
26 Feb 2010
RT
@RSnake
: Facebook Patents Social Feeds and I Patent XSS http://bit.ly/96JSZl
Bil Corry
@bilcorry
26 Feb 2010
XP & Vista support ending http://is.gd/9fcpB Can your existing HW be upgraded? http://is.gd/9fbpG Users that can't, mass pwning to ensue
Bil Corry
@bilcorry
26 Feb 2010
@djdarkbeat
That ctag could be simplified to: define_tag('status',-required='p'); return(action_params->find(
#p
)->size > 0); /define_tag;
Bil Corry
@bilcorry
26 Feb 2010
CEOs, Conan and Calfornia public teachers: all paid to leave. Why getting rid of bad teachers is near impossible in CA http://is.gd/9dP5B
Bil Corry
@bilcorry
26 Feb 2010
One final thought from Dawn Song. Leverage those who attack your website as free pentesting, and quickly patch = cost-effective solution!
1
Bil Corry
@bilcorry
26 Feb 2010
The paper on Automated Blackbox Testing will be presented at the upcoming IEEE Security + Privacy conference http://is.gd/9dzd9
Bil Corry
@bilcorry
26 Feb 2010
Kudzu isn't available publicly yet. Jason Bau (Stanford) presented on Automated Blackbox Testing of Webapps. Lots of room for improvement!
Bil Corry
@bilcorry
26 Feb 2010
The OWASP Bayarea meeting was really interesting. Dawn Song introduced Kudzu, a JavaScript symbolic exec. framework for crawling Web 2.0
Bil Corry
@bilcorry
25 Feb 2010
RT
@ivanristic
: OpenSSL 0.9.8m released; first version to support for secure renegotiation http://www.openssl.org
Bil Corry
@bilcorry
25 Feb 2010
RT
@jeremiahg
: interesting, "Form-based HTTP Authentication Proof of Concept" http://bit.ly/cGjTyo <-- the readme mentions my contribution
Bil Corry
@bilcorry
25 Feb 2010
RT
@honeyapps
: Good post from
@rafallos
on a real world & common case of SQLinjection http://bit.ly/cXdPYZ
Bil Corry
@bilcorry
24 Feb 2010
RT
@chiefmonkey
: Blogged "GoDaddy Has My Passwords?" http://it.toolbox.com/trd/46/2/37130/3 <-- root access!
Bil Corry
@bilcorry
24 Feb 2010
“your money is insured up to $250,000, but they should have an asterisk next to that saying ‘except for businesses’" http://is.gd/95xS0
Bil Corry
@bilcorry
24 Feb 2010
RT
@spinkham
: Web Security Dojo 1.0 released. Dojo = tools + targets for learning & training http://dojo.mavensecurity.com
#appsec
Bil Corry
@bilcorry
24 Feb 2010
"Security of Voting Systems" with Ronald Rivest was interesting http://is.gd/8Dsai Many ways to subvert election systems; I found some too.
Bil Corry
@bilcorry
23 Feb 2010
Using MMORPGs to teach math: "The textbook is perhaps the worst possible medium for teaching mathematics" http://is.gd/91c32
Bil Corry
@bilcorry
23 Feb 2010
Replying to
@jeremiahg
@jeremiahg
Imagemagick works too for quick and dirty CAPTCHA breaking http://is.gd/90Hvi
1
Bil Corry
@bilcorry
23 Feb 2010
Preliminary IETF 77 meeting agenda http://is.gd/8Z5Ji - httpstate is meeting Tuesday morning, come help us with the next cookie spec
Load more