|
GitHub Security Lab
@
GHSecurityLab
|
|
GitHub Security Lab’s mission is to inspire and enable the community to secure the open source software we all depend on.
|
|
|
107
Tweetovi
|
0
Pratim
|
5.101
Osobe koje vas prate
|
| Tweetovi |
|
GitHub Security Lab
@GHSecurityLab
|
4 h |
|
#spotthebug Explain why this code triggers an ASAN error. The first good answer will get some nice swag! pic.twitter.com/a7WlYOf7jw
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
4. velj |
|
Awesome CodeQL query from @ggolawski that detects many variants of LDAP Injections in Java: Plain Java JNDI, UnboundID, Spring LDAP and Apache LDAP API. We are pleased to award him our maximum bounty reward $3000
github.com/Semmle/ql/pull… pic.twitter.com/wXJPh4ZwQ0
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
4. velj |
|
Las diapositivas de la charla de @nosoynadiemas están disponibles.
#hc0n2020 github.com/github/securit…
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
4. velj |
|
Learn from the past to secure the future. At @typhooncon 2020 @nicowaisman will explore Linux Kernel vulnerabilities and model the bug classes to avoid repeating the same mistakes typhooncon.com/speakers-2020/…
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
30. sij |
|
Do you know #aflplusplus? It brings interesting add-ons to AFL. @nosoynadiemas used it during his fuzzing research to create custom instrumentation whitelists, increasing AFL code coverage securitylab.github.com/research/fuzzi…
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
30. sij |
|
Are you in Brussels this Saturday evening? Join us for a GitHub networking event. No sales, no product, just chat with GitHubbers and with your peers, about your needs as open source maintainers, such as securing your open source projects. github.co/os-social-bru
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
29. sij |
|
Are you in Brussels this weekend? We are proposing some 1:1 meetings to discuss open source security. You are interested? Reach out in DMs to book your spot! twitter.com/XCorail/status…
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
28. sij |
|
Video and slides of the latest Meetup are available. Subjects are as diverse as: Automating variants analysis, Hunting backdoors in open source, Researching local windows RPC, and Breaking SAML! Repeated thanks to our 4 speakers! securitylab.github.com/events/github-…
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
28. sij |
|
Check out @Nosoynadiemas ' tips on Fuzzing, to overcome known challenges and maximize results: securitylab.github.com/research/fuzzi…
|
||
|
|
||
| GitHub Security Lab proslijedio/la je tweet | ||
|
OWASP Mobile Security Testing Guide
@OWASP_MSTG
|
27. sij |
|
We're happy to announce that we're now part of the Open Source Security Coalition. We'd like to thank the @GHSecurityLab guys for their warm welcome and support.
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
24. sij |
|
We're closing out the week strong by announcing the Open Source Security Coalition's latest partners: @TencentGlobal @auth0 and @owasp!
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
24. sij |
|
Hey. Please use the contact form on the Semmle web page, that will put you in contact with the relevant GitHub team!
|
||
|
|
||
| GitHub Security Lab proslijedio/la je tweet | ||
|
Bas Alberts
@basalberts
|
23. sij |
|
You can catch the rerun of last night’s lightning talks here. TL;DR: fancy grep with CodeQL, backdoor grep with MSFT, Windows RPC wrapping for fun and convenience, and a game of “who’s SAML key is it really tho?” twitter.com/GHSecurityLab/…
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
23. sij |
|
ICYMI: Thursday mini-challenge: Triage some of the bugs on lgtm.com/rules/15108526… and report interesting ones to the maintainers! We have pretty cool GitHub swag waiting for you.
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
23. sij |
|
And now Alvaro Muñoz @pwntester is breaking SAML at the GitHub Security Meetup. pic.twitter.com/NTwk2h5o1H
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
23. sij |
|
Live demo from James Forshaw at GitHub Security Meetup. pic.twitter.com/1llX4no51Z
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
23. sij |
|
@scovetta is hunting back door in open source at the GitHub Security Meetup. « Why would the malicious developer infect only one package? How many vulnerabilities are out there? » pic.twitter.com/5Rx2dZVKM0
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
23. sij |
|
@samlanning talking about a story of many bugs at the GitHub security meetup ... scary! pic.twitter.com/vkQXssbLpW
|
||
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
23. sij |
|
|
||
|
GitHub Security Lab
@GHSecurityLab
|
23. sij |
|
We will go live in 2 min! twitter.com/GHSecurityLab/…
|
||
|
|
||