Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
EdOverflow
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
EdOverflow
5y ago
I am a security researcher referenced in the winning web-hacking technique on that list ("Dependency Confusion" by Alex Birsan [1]) and was ranked 7th in Portswigger's 2019 issue [2,3]. My motto has always been "Learn to
2.
▲
by
EdOverflow
6y ago
I am the author of an Internet Draft (security.txt) that is going through a similar process to Mark Nottingham's RFC above, so I might be able to help. This is an "Informational" specification which means it went via the &quo
3.
▲
by
EdOverflow
7y ago
Updated accordingly. :)
4.
▲
by
EdOverflow
7y ago
Aside from Filedescriptor's work, here are some of my favourite blogs in the web application security space (not an exhaustive list): - https://blog.orange.tw/ - https://ngailong.wordpress.com/ - http
5.
▲
An analysis and thought about recently PHP-FPM RCE(CVE-2019-11043)
(blog.orange.tw)
4 points
by
EdOverflow
7y ago
|
0 comments
6.
▲
by
EdOverflow
7y ago
(Obligatory: I am not a lawyer) This is what the "safe harbor" that the author was referring to is supposed to cover. > Tesla considers that a pre-approved, good-faith security researcher who complies with this policy to access
7.
▲
Cracking My Windshield and Earning $10k on the Tesla Bug Bounty Program
(samcurry.net)
574 points
by
EdOverflow
7y ago
|
182 comments
8.
▲
VPN Extensions are not for privacy
(blog.innerht.ml)
94 points
by
EdOverflow
8y ago
|
37 comments
9.
▲
Uncovering Drupalgeddon 2 – Check Point Research
(research.checkpoint.com)
1 points
by
EdOverflow
8y ago
|
0 comments
10.
▲
by
EdOverflow
9y ago
http://attrition.org/errata/legal_threats/
11.
▲
by
EdOverflow
9y ago
This is a wonderful thing to see and I hope that more vendors will follow suit. Amit Elazari [1] has been doing some amazing work in this field advocating for legal safe harbours for security researchers. She posts regular reviews of securi
12.
▲
by
EdOverflow
9y ago
This sounds like something along the lines of password reset poisoning as described in James Kettles' technical write-up "Practical HTTP Host header attacks". [1] [1]: http://www.skeletonscribe.net/2013/0
13.
▲
An analysis of logic flaws in web-of-trust services
(edoverflow.com)
3 points
by
EdOverflow
9y ago
|
0 comments
14.
▲
Show HN: Bug Bounty Guide, a launchpad for bug bounty programs and hunters
(bugbountyguide.com)
2 points
by
EdOverflow
9y ago
|
0 comments
15.
▲
by
EdOverflow
9y ago
My finding was heavily inspired by Frans' report, but it is not actually related.
16.
▲
by
EdOverflow
9y ago
Unfortunately, I cannot disclose any further details until GitLab give me permission to do so. All that I can say is that GitLab has certain features for custom domains that GitHub does not have. I plan on publishing a technical write-up on
17.
▲
by
EdOverflow
9y ago
Yes, GitHub pages are vulnerable to (sub)domain takeovers too [1], but GitLab has a couple of specific characteristics that make matters worse. [1]: https://hackerone.com/reports/263902
18.
▲
Show HN: Contact.sh – a tool to find contacts to report security vulnerabilities
(github.com)
4 points
by
EdOverflow
9y ago
|
0 comments
19.
▲
by
EdOverflow
9y ago
I am the security researcher that reported this issue to GitLab. There is more to the issue than is described in GitLab's security advisory and it was definitely a design flaw on GitLab's part. Hopefully, more details will be publ