77 Followers
23 Following
88 Posts
Reverse engineering, web application security, talking too much 😅 ADHD/ASD

Great article from @ulldma about the ruby-saml library https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/

If you use this library make sure to patch to the latest version!

Sign in as anyone: Bypassing SAML SSO authentication with parser differentials

Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.

The GitHub Blog
My first ever CFP got rejected :( I’ve spoken at conferences as a sponsored speaker before but never as an accepted one. I hope that my next one fares better!! Is it bad manners to message asking for feedback? 🥺
Why must go back to job can I simply not job and get money anyway

AWS IAM is really awesome when you can get it to work, but damnnn is it complicated 😅

I feel like I could take a whole course on the intricacies of cross-account usage of AWS services and their implications on IAM and not even scratch the surface.

What do you use to scan for dependency vulnerabilities in Python apps?
@NorthSec it seems like Firefox thinks the NSec CFP site is deceptive? 😬

I am doing an info session for people at risk of trafficking on how to protect themselves online. Anyone wanna share ideas on which topics to cover?

#publictechliteracy #basictechliteracy #onlinesafety

I’ve got some crazy social anxiety so I’m kind of freaking out 🥲
What’re folks up to at DEFCON? ❤️ Hoping to meet new people :)
Does anybody have an extra ticket for BSidesLV? I managed to forget to buy one and I’m here now :( #bsideslv EDIT: I got a ticket 😊 Tysm!