|
Josh Grossman š» (tghosth)
@
JoshCGrossman
Israel
|
|
AppSec Nerd | Based in Silicon Wadi | Personal account, content does not represent my employer. | @OWASP_IL board member | @OWASP_ASVS co-leader
|
|
|
2.725
Tweetovi
|
1.138
Pratim
|
789
Osobe koje vas prate
|
| Tweetovi |
| Josh Grossman š» (tghosth) proslijedio/la je tweet | ||
|
MyDevSecOps
@MyDevSecOps
|
4. velj |
|
Did you know the top ten most popular default #Docker images, each contains at least 30 vulnerable system library versions? Check out our previous virtual session where we chatted about this & other findings in the 2019 state of open source security! š¬ buff.ly/3915bI5 pic.twitter.com/6sLP50TspQ
|
||
|
|
||
|
Josh Grossman š» (tghosth)
@JoshCGrossman
|
4. velj |
|
Super cool! Well done mate! Are you gonna be visiting head office at any point soon? :)
|
||
|
|
||
|
Josh Grossman š» (tghosth)
@JoshCGrossman
|
3. velj |
|
|
||
| Josh Grossman š» (tghosth) proslijedio/la je tweet | ||
|
Katy Anton
@KatyAnton
|
2. velj |
|
The Call For Trainings for Global AppSec Dublin 2020 has opened. Submit your training here:
owasp.submittable.com/submit/157929/⦠pic.twitter.com/4AFV9OUDgN
|
||
|
|
||
| Josh Grossman š» (tghosth) proslijedio/la je tweet | ||
|
Shannon Dingle
@ShannonDingle
|
2. velj |
|
Ten years ago today, The Lancet retracted Andrew Wakefieldās fraudulent 1998 article claiming the MMR vaccine caused autism. He performed procedures on children unethically, paid kids at a birthday party to give him blood samples, and doctored data.
He still claims he was right.
|
||
|
|
||
| Josh Grossman š» (tghosth) proslijedio/la je tweet | ||
|
Guy Barnhart-Magen
@barnhartguy
|
2. velj |
|
Our @BsidesTLV CfP is open!
cfp.bsidestlv.com/20/cfp
|
||
|
|
||
|
Josh Grossman š» (tghosth)
@JoshCGrossman
|
30. sij |
|
|
||
|
Josh Grossman š» (tghosth)
@JoshCGrossman
|
30. sij |
|
Yes indeed :)
Tune in tonight to discover all this and more about the @OWASP_ASVS! 5pm GMT, 12pm EDT, 9am PDT
mydevsecops.io/post/what-s-ne⦠twitter.com/benhall_io/staā¦
|
||
|
|
||
| Josh Grossman š» (tghosth) proslijedio/la je tweet | ||
|
š¦Irena Damskyš¦
@DamskyIrena
|
30. sij |
|
××פש×× ×¢××××? twitter.com/JohnLaTwC/statā¦
|
||
|
|
||
| Josh Grossman š» (tghosth) proslijedio/la je tweet | ||
|
MyDevSecOps
@MyDevSecOps
|
29. sij |
|
Only 24 hours until @JoshCGrossman joins us to explain whatās new in the ASVS 4.0, he''ll go through what the ASVS is & how it's put together, as well as what has changed in this new version.
JOIN US!!!!
šļøbuff.ly/2RyPx0w
š
Jan 30th
ā° 5pm GMT / 12pm EDT / 9am PDT
|
||
|
|
||
|
Josh Grossman š» (tghosth)
@JoshCGrossman
|
29. sij |
|
Can confirm that cert pinning is still requires quite some effort to bypass on mobile devices.
|
||
|
|
||
|
Josh Grossman š» (tghosth)
@JoshCGrossman
|
28. sij |
|
Looking forward to this on Thursday, excited to raise awareness of this important standard! @OWASP_ASVS twitter.com/MyDevSecOps/stā¦
|
||
|
|
||
|
Josh Grossman š» (tghosth)
@JoshCGrossman
|
28. sij |
|
|
||
|
Josh Grossman š» (tghosth)
@JoshCGrossman
|
28. sij |
|
Thanks so much for the fast response, that is really useful! I hope you don't mind but I opened a PR to include the mitigations in the mean document. Feel free to edit if I have misunderstood or mis-stated something :)
github.com/veracode-reseaā¦
|
||
|
|
||
|
Josh Grossman š» (tghosth)
@JoshCGrossman
|
27. sij |
|
Hey @artsploit, this is really cool research :)
Do you have any mitigation advice for this? Is stripping curly brackets and ampersands sufficient or are there other control characters?
twitter.com/artsploit/statā¦
|
||
|
|
||
|
Josh Grossman š» (tghosth)
@JoshCGrossman
|
26. sij |
|
Me: "I emailed you the questions last week"
Them: "No you didn't"
Me: "Ok, I will resend the questions later"
Them: "No no no, you will *send* us the questions"
*A few hours later*
Me: "š„š„As per my previous email....š„š„"
|
||
|
|
||
|
Josh Grossman š» (tghosth)
@JoshCGrossman
|
26. sij |
|
|
||
| Josh Grossman š» (tghosth) proslijedio/la je tweet | ||
|
Per Thorsheim
@thorsheim
|
24. sij |
|
22) So I'll stop my rant here, and say thank you for reading all these tweets.
I am now ready to answer your questions, comments and flames. pic.twitter.com/7LM1h2R52X
|
||
|
|
||
|
Josh Grossman š» (tghosth)
@JoshCGrossman
|
25. sij |
|
Enjoy! Be sure to catch the @dc9723 meeting if that is your thing :) lots of interesting people there and @barnhartguy is an excellent speaker (and a great person!)
|
||
|
|
||
| Josh Grossman š» (tghosth) proslijedio/la je tweet | ||
|
Jarrod Overson
@jsoverson
|
23. sij |
|
Great talk from @manicode on moving from the OWASP top ten to the OWASP ASVS as an actual standard and checklist for web application security.
owasp.org/www-project-apā¦
|
||
|
|
||