Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
fmavituna
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
Preventing CSRF Attacks with the SameSite Cookie Attribute
(netsparker.com)
1 points
by
fmavituna
10y ago
|
0 comments
32.
▲
Collapsed – Learn Lessons from Failed Startups
(collapsed.co)
2 points
by
fmavituna
10y ago
|
0 comments
33.
▲
Identifying WordPress Websites on Local Networks and Bruteforcing Login Pages
(netsparker.com)
4 points
by
fmavituna
10y ago
|
0 comments
34.
▲
by
fmavituna
10y ago
It's a bit (actually a lot) worrying that their donation page that you enter personal and credit card info is not over HTTPS. Possibly it will significantly decrease the donations they'll receive online.
35.
▲
by
fmavituna
10y ago
My argument was about software development and I don't know how much it would hold up for other fields. Employer pays the time for that employee to acquire the knowledge, employer serves the know-how that the employee might never ever
36.
▲
by
fmavituna
10y ago
And that's exactly my point. This is why non-compete makes sense. To repeat, because none of the stuff you have mentioned can replace what non-compete provides.
37.
▲
by
fmavituna
10y ago
I agree, but if we want that we should start from demolishing "patents" and many other similar more basic issues first, but we all know why that's not going to happen. Secondly when you do that, aren't you actually killi
38.
▲
by
fmavituna
10y ago
Sorry I wasn't clear on the original comment, how can NDA stop a developer to use what he knows while writing code or creating procedures? If you are a developer and worked on a code for 2 years. NDA cannot cover what you know what you
39.
▲
by
fmavituna
10y ago
> Trade secrets, IP, secret sauce: covered by NDA and IP assignment agreements As a developer pretty much none of these matter or protects anything. Imagine this scenario; - John has no idea about video encoding but a good developer. -
40.
▲
Hacking local MongoDB installation from web with CSRF and timing attacks
(netsparker.com)
1 points
by
fmavituna
10y ago
|
0 comments
41.
▲
Using the Same-Site Cookie Attribute to Prevent CSRF Attacks
(netsparker.com)
1 points
by
fmavituna
10y ago
|
0 comments
42.
▲
CSRF Vulnerability in Yandex's Login Page Allows Steal Browsing Data
(netsparker.com)
1 points
by
fmavituna
10y ago
|
0 comments
43.
▲
Alexa Top 1M Crawl – August 2016
(scotthelme.co.uk)
2 points
by
fmavituna
10y ago
|
0 comments
44.
▲
Doomsday prepping for less crazy folk
(lcamtuf.coredump.cx)
2 points
by
fmavituna
10y ago
|
0 comments
45.
▲
Black Desert Online players protest “pay-to-win” changes in-game
(pcgamer.com)
4 points
by
fmavituna
10y ago
|
0 comments
46.
▲
by
fmavituna
10y ago
I used to commute 3 hours a day, I used to finish 1-2 books per week. 3 hours of solid reading every single day. Now, depending on the book it can be 1 week to 3 months as I don't commute and when I'm at home it's quite hard
47.
▲
by
fmavituna
10y ago
I never used them or seen them in a benchmark so cannot comment much of the capability or quality. I think it's best if you compare it for yourself. Running a scan very easy and won't take much of your time, drop me an email and w
48.
▲
by
fmavituna
10y ago
2 things: * It's about how make the suggestion. "How about making this blue darker?" vs. "Do you think making this blue darker would give us more engagement? Are there any studies, or have we done A/B testing on thi
49.
▲
by
fmavituna
10y ago
If your team cannot take your feedback just like taking feedback from their colleagues, cannot argue with you or veto your idea easily with a legitimate response, take everything you said as a "command" then you have failed as a
50.
▲
by
fmavituna
10y ago
Thanks for the feedback. We are actually renewing our website and changing that slogan. This will be the new message, "Proof Based Scanning" and we tried to explain it in here : https://www.netsparker.com/blog
51.
▲
by
fmavituna
10y ago
Use static source code analysis and dynamic web app scanners. They are easy to integrate into your SDLC, they are not going to replace manual testing or secure development practices but they'll help a lot. They'll pick up tons of
52.
▲
by
fmavituna
10y ago
Hey, good job there, much needed improvements. Thanks. There is a CSRF vulnerability in the "favorite" feature. A very quick demo, Visit this URL: https://jsfiddle.net/o9hw1u75/embedded/result/ Now
53.
▲
by
fmavituna
10y ago
For whose wondering, brief read of the paper's initial chapters show that it's a methodology (and toolset) to find access control issues in RoR. Seems like a smart approach, need to see it in production though. I'm not really
54.
▲
by
fmavituna
11y ago
That's pretty much bullshit for the pure reason that a job very rarely can only include the things you love. I love programming but I hate polishing up the same features for days, but that's what's necessary to make a good ap
55.
▲
Updated Version of the Original SQL Injection Cheat Sheet
(netsparker.com)
2 points
by
fmavituna
11y ago
|
0 comments
56.
▲
Remote Code Execution in CCTV-DVR affecting over 70 different vendors
(kerneronsec.com)
1 points
by
fmavituna
11y ago
|
0 comments
57.
▲
Career Advice No One Tells You
(medium.com)
7 points
by
fmavituna
11y ago
|
0 comments
58.
▲
by
fmavituna
11y ago
With 7 years experience of running a remote & distributed team (5+ countries) at Netsparker [1]. We have 4 platforms: * Bug Tracking / Project Management * Group Chat * Skype / Voice * Email Since we grew organically, here is
59.
▲
by
fmavituna
11y ago
There are many apps like this; Skype, Whatsapp, Twitter, LinkedIn are come to my mind (a few of my personal list), heck even Flash & Java Runtime (same problem different field). For the lack of better and popular alternative we have to
60.
▲
What Can You Learn from Advisories About Web Application Vulnerabilities?
(netsparker.com)
11 points
by
fmavituna
11y ago
|
0 comments
More ›