CISO at @sardineai. Treasurer of @OWASP Board of Directors. (he/him) qatta' mIghtaHghach.

Phoenix, AZ
Joined July 2009
Filter
Exclude
Time range
-
Near
A five-line Python script finds 20 critical security vulnerabilities in Apple's Preview application http://is.gd/aLvDi (via @wkandek)
RT @hypatiadotca: RT @thorstenholz: Twitter Spamdetector Service: http://bit.ly/bC7HFG (see @spamdetector) - please RT
"Top Ten particularly well crafted [targeted malware] messages of 2009-2010" http://is.gd/aLumN
1
Replying to @jeremiahg
@jeremiahg This is probably as close as to 'delete' for MySpace as you're going to get: http://suicidemachine.org/
Note to self, do not send fake Facebook password reset emails to phishing-report@us-cert.gov when the email contains malware - it bounces
New IETF list 'certid' - verify the identity of application servers in TLS transactions http://is.gd/aKDaK (I-D http://is.gd/aKDlo)
RT @jeremiahg: Bay Area WASC Meet-Up Tomorrow Night (Mar. 16 @ 6pm) at FireHouse in Downtown Sunnyvale. - http://bit.ly/bcAx5J
2
RT @miscsecurity: SiliSec, Silicon Valley's Security Meetup, is this Thursday. http://bit.ly/c529rv
"I don't understand the connection between CSRF and what the site superadmin is doing. " <- More security education needed for developers
RT @lithium: Cyber-criminals don't need technical skills - http://bit.ly/90wUV7 "The three men, authorities said, were no computer geniuses"
Stanford research: "Automated Black Box Web Application Vulnerability Testing" http://is.gd/ayEeF Paper to be published later this year.
RT @gollmann: RT @rgaucher: "Haven't found that software glitch, Toyota? Keep trying" - http://bit.ly/dpiLrl <- crazy subtle bugs e.g. 2+2=5
RT @mckt_: RT: @0x6D6172696F: "Strokejacking" - valid name :D http://lcamtuf.coredump.cx/focus-webkit/ Indeed amusing PoC by Michal Zalewski
RT @gollmann: Why DRM doesn't work... http://www.bradcolbow.com/archive.php/?p=205
RT @jeremiahg: XSS PW theft http://bit.ly/bYx5cK slashdot http://bit.ly/b0jQaB FIX bugzilla http://bit.ly/dbhzOY PoC http://bit.ly/bg8Qpk
RT @ebellis: interesting business logic abuse use case: verifying bank acct numbers through micro transfers http://bit.ly/9AiDMy #SilverTail
U-Prove offers improved privacy in financial transactions http://is.gd/am6KW
RT @miscsecurity: 10 ways you COULD be breaking the law with your computer http://bit.ly/bTPXVX <- No. 9 sends innocent people to jail
Digg moving from MySQL to Cassandra to improve performance and scalability http://is.gd/aiCd7 (Cassandra: http://is.gd/aiDlt)
RT @jeremiahg: RSAC slides posted, "2010: A Web Hacking Odyssey - Top Ten Hacks of the Year" http://bit.ly/b7yz8Q