Twitter | Pretraživanje | |
James Kettle
Director of Research at PortSwigger Web Security aka
2.442
Tweetovi
63
Pratim
22.597
Osobe koje vas prate
Tweetovi
James Kettle 4 h
Odgovor korisniku/ci @testerofpen
I meant in the Symfony advisory. It's not a big deal though.
Reply Retweet Označi sa "sviđa mi se"
James Kettle 7 h
Odgovor korisniku/ci @ahack_ru @WebSecAcademy
I reported it to Drupal, they reported it to Symfony/Zend and therefore I didn't get credited. Full writeup (explaining where the poisoning comes in) at
Reply Retweet Označi sa "sviđa mi se"
James Kettle 7 h
Odgovor korisniku/ci @ahack_ru @WebSecAcademy
It was me the got the CVE for it...
Reply Retweet Označi sa "sviđa mi se"
James Kettle proslijedio/la je tweet
Web Security Academy 4. velj
During his research into web-cache poisoning, stumbled upon a new route-poisoning trick for systems built on Zend and Symfony frameworks. Try it for yourself:
Reply Retweet Označi sa "sviđa mi se"
James Kettle 3. velj
Odgovor korisniku/ci @julianor @Burp_Suite
Yep you're right it shouldn't be on that page, but as described third parties turning evil isn't what our bounty policy is aimed at. For example, if your browser saves your password then any JS third party could steal it from literally any page.
Reply Retweet Označi sa "sviđa mi se"
James Kettle 3. velj
Odgovor korisniku/ci @julianor @Burp_Suite
The CSP is because we want to mitigate XSS. Nothing to do with third parties. Maybe I misunderstood what your original tweet is trying to draw attention to?
Reply Retweet Označi sa "sviđa mi se"
James Kettle 3. velj
Odgovor korisniku/ci @julianor @Burp_Suite
We have disabled crazyegg's higher-risk features, and a trusted third party hypothetically going rogue wouldn't qualify as a medium or higher severity bug under our bounty program. Also, you already publicly disclosed the issue.
Reply Retweet Označi sa "sviđa mi se"
James Kettle 3. velj
Odgovor korisniku/ci @julianor @Burp_Suite
I wouldn't bother
Reply Retweet Označi sa "sviđa mi se"
James Kettle 3. velj
I miss chrome://cache . At least Firefox's about:cache still exists.
Reply Retweet Označi sa "sviđa mi se"
James Kettle 3. velj
Odgovor korisniku/ci @ricardo_iramar @Burp_Suite
This is automatically done by default. If you have further questions, the team between would love to help.
Reply Retweet Označi sa "sviđa mi se"
James Kettle 31. sij
Odgovor korisniku/ci @therealdudez
Some fonts were causing performance issues so we whittled the list down
Reply Retweet Označi sa "sviđa mi se"
James Kettle 31. sij
Odgovor korisniku/ci @notsoshant @DafyddStuttard @524f464c
It does both
Reply Retweet Označi sa "sviđa mi se"
James Kettle 31. sij
I've been beta testing this update for a while, it's a good one :)
Reply Retweet Označi sa "sviđa mi se"
James Kettle 31. sij
Odgovor korisniku/ci @ericlaw
The dotless domains feature was great for exploitation, so some people will miss it :)
Reply Retweet Označi sa "sviđa mi se"
James Kettle 31. sij
Odgovor korisniku/ci @filedescriptor @ngalongc @EdOverflow
Nice work! I love the domain name too...
Reply Retweet Označi sa "sviđa mi se"
James Kettle 31. sij
Odgovor korisniku/ci @g33kyshivam @filedescriptor i 2 ostali
If you didn't already see it, check out
Reply Retweet Označi sa "sviđa mi se"
James Kettle proslijedio/la je tweet
FD 31. sij
, , and I are starting a new security blog. In our first write-up, we will discuss the impact of "SameSite by default" and how it affects web app sec. Feel free to request future topics you would like us to cover.
Reply Retweet Označi sa "sviđa mi se"
James Kettle 28. sij
Odgovor korisniku/ci @ganggangsincep4
That said, these days I use novel unpublished desync techniques because unless you do a serious amount of recon, you are six months too late to get decent bounties with low effort using this technique.
Reply Retweet Označi sa "sviđa mi se"
James Kettle 28. sij
Odgovor korisniku/ci @ganggangsincep4
I assumed you hadn't read that post because it answers the question of why the FP rate has changed. Of course I use my own tool; I mostly focus on 'confirmed' findings as detailed in that post.
Reply Retweet Označi sa "sviđa mi se"
James Kettle 28. sij
Odgovor korisniku/ci @ganggangsincep4
Refer to for further info
Reply Retweet Označi sa "sviđa mi se"