|
Laban Sköllermark
@
LabanSkoller
Malmö, Sweden
|
|
Interested in information and IT security. Occational CTF player for @xil_hackerspace. Systems Specialist at Verisure Innovation AB. Opinions are mine.
|
|
|
672
Tweetovi
|
160
Pratim
|
122
Osobe koje vas prate
|
| Tweetovi |
|
Laban Sköllermark
@LabanSkoller
|
1. velj |
|
No nibbles either?
|
||
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
30. sij |
|
Lite som Särimner fast tvärtom? ;)
kryptera.se/sarimner/
Eventuellt skulle det kunna bli ett projekt med bidrag från @stiftelsen?
|
||
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
29. sij |
|
It's a sign that your body wants vacation!
|
||
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
28. sij |
|
Bra jobbat! Väl påläst som vanligt! En fröjd att lyssna på.
|
||
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
28. sij |
|
Hmm. Corona already contains alcohol so I don't buy that. People should start rub hands with lime instead...
|
||
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
28. sij |
|
Is there a fixed list of what HTTP response headers are considered "security headers"? This site include cache headers for instance: nullsweep.com/http-security-…
|
||
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
28. sij |
|
And what is "code"? What languages? You want to include PHP I assume. Of course it's possible to find/create a language where you can't set any HTTP response headers at all.
|
||
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
28. sij |
|
"It depends" I guess. Is "server" the software terminating TLS? What web servers do you want to cover? Even those like HAProxy? What about "apps" that implement the HTTP Server itself, like what's possible in Python and Go? Then "server" == "code" as someone pointed out.
|
||
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
26. sij |
|
Eller "No invitation necessary" för den delen...
|
||
|
|
||
| Laban Sköllermark proslijedio/la je tweet | ||
|
Lina
@d0rkph0enix
|
25. sij |
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
17. sij |
|
Kommer de läsa i hemlighet från /dev/hda bara? Lätt att kringgå! ;)
|
||
|
|
||
| Laban Sköllermark proslijedio/la je tweet | ||
|
ᴉpᴉǝH 🐐💕
@summer__heidi
|
16. sij |
|
How did the hackers get away?
They ransomeware.
|
||
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
17. sij |
|
Ah! Yeah that will override whatever comes from http(s)_proxy environment variable I assume. Thanks!
|
||
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
17. sij |
|
The (strange) option for *not* using a proxy. --noproxy '*'
|
||
|
|
||
| Laban Sköllermark proslijedio/la je tweet | ||
|
Thomas 🐦
@tqbf
|
16. sij |
|
If you DON’T give your new vulnerability a spicy name, everyone else will try to do it for you, and 2 years from now nobody will remember if “Chain Of Fools” is the same bug as “CurveBall” or “Who’s Curve”. The lesson is obvious.
|
||
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
16. sij |
|
Another suggestion seems to be #curveball.
twitter.com/TalBeerySec/st…
|
||
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
16. sij |
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
15. sij |
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
15. sij |
|
This sentence seems incomplete:
"Since the bug would have presented installation problems for the majority of users."
|
||
|
|
||
|
Laban Sköllermark
@LabanSkoller
|
14. sij |
|
0601? Oh, it's the one NSA warned about. Where's the name and the logo? NSA usually come up with code names for stuff and sometimes clever or funny. Not in this case?
|
||
|
|
||