Erling Ellingsen

@steike

ex-fb prodsec

Oslo, Norway
Participa desde agosto de 2008

Tweets

Você bloqueou @steike

Tem certeza de que deseja ver estes Tweets? Visualizar os Tweets não desbloqueará @steike

  1. Tweet Fixado
    23 de fev de 2017

    Make your own colliding PDFs:

    Desfazer
  2. 9 de ago de 2018

    Ooh! On DOS, this was a much faster way to allocate space than writing zeros—but you would get whatever was on disk (so, random data from deleted files). This led to an early privacy panic when private data turned up inside the cache files of some online service client… Prodigy?

    Desfazer
  3. 22 de mai de 2018

    Someone should set up a meta-tags-as-a-service company that keeps track of all the new browser features and automatically opts your site out of the ones that create unnecessary attack vectors

    Desfazer
  4. retweetou
    3 de abr de 2018

    Do I even want to know why Debian has a security update for beep(1) today?

    Desfazer
  5. 13 de mar de 2018

    This is so great. Also, to save some work: If you have a crazy hetereogenous setup, it's enough to automate the setup for one domain. You can CNAME _acme-challenge.[everything else] to that (once) and just serve all the TXT records from there (extra garbage is ignored)

    Desfazer
  6. 16 de fev de 2018

    Online shopping is a lot easier when you take into account that (1) humans make systems (2) reliably comparing free-format street addresses is a difficult but unsexy problem

    Desfazer
  7. 7 de jan de 2017
    Desfazer
  8. 24 de nov de 2016

    today

    Desfazer
  9. 24 de nov de 2016
    Desfazer
  10. 28 de ago de 2016

    Oh hey, that's CVE-2011-3441! (except on iOS no extra tricks were needed, just 1.2.3.4%20.victim.㏄ and get cookies)

    Desfazer
  11. 11 de ago de 2016

    It looks like the same solution should work in all the modern browsers with small modifications. This is surprising.

    Desfazer
  12. 3 de ago de 2016

    Had a bunch of alert(1)-to-win levels left over that weren't really security related. General ecmascript golf time!

    Desfazer
  13. 7 de abr de 2016

    Is your entire domain 'X-Frame-Options: DENY', but not your error pages? Now's as good a time as any to fix it… (iframe UXSS in Safari)

    Desfazer
  14. 18 de mar de 2016

    We gave the whole internet keys so airport security won't break open your luggage. They do anyway. In other news, an FPGA dev kit is a bomb.

    Desfazer
  15. 10 de mar de 2016

    "Can you please provide me the last 4 characters of the cPanel password to verify ownership of the account?" - cc :-)

    Desfazer
  16. 7 de fev de 2016

    fin-fin wifi, men utløpt sertifikat på . Bonus om den kan bli synlig i DNS for de som bruker ⒏⒏⒏8 e.l

    Desfazer
  17. 15 de dez de 2015

    @Fridababy_HQ assuming you don't have an online phramacy seo side business, your web server is hacked

    Desfazer
  18. 5 de out de 2015
    Desfazer
  19. retweetou
    10 de set de 2015
    Desfazer
  20. 22 de jun de 2015
    Em resposta a

    @JamEngulfer221 Sort of. Each user gets a sandbox branch. Hmm, I guess there should be a way to request a merge...

    Desfazer

O carregamento parece estar demorando.

O Twitter deve estar sobrecarregado ou passando por algum problema momentâneo. Tente novamente ou acesse o Status do Twitterpara obter mais informações.

    Você também pode gostar

    ·