Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jtaft
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
91.
▲
by
jtaft
7y ago
One Up Security, LLC | Application Security Engineer, Consulting | Rochester, NY | ONSITE | Interns and Part Time We love challenging and interesting projects! Our focus has been testing web applications, and prefer white box testing. Proje
92.
▲
by
jtaft
7y ago
SEEKING WORK | Remote | Application Security Engineering We love challenging and interesting projects! Our focus has been testing web applications, and prefer white box testing. Projects have ranged from: - Threat modeling systems to miti
93.
▲
Marty Lobdell – Study Less Study Smart [video]
(youtube.com)
1 points
by
jtaft
7y ago
|
0 comments
94.
▲
by
jtaft
7y ago
Good writeup! Finding bugs is just a portion of a pen tester's responsibilities. - You need to have strong technical writing skills. Reporting for each vulnerability should include: * Title * Two sentence summary explaining th
95.
▲
by
jtaft
7y ago
The music video is a bit addicting :) https://www.youtube.com/watch?v=HM1Zb3xmvMc
96.
▲
by
jtaft
8y ago
Can they simulate their sensors input pretty well? Do they use car driving simulators (video-game like) to see what would happen in similar scenarios? Of course, real world testing would still be necessary.
97.
▲
by
jtaft
8y ago
It's an interesting problem, because all the connected devices would need the attack mitigation. Would be interesting to see a protocol which auto-revokes certificates for devices which do not digitally sign some "ping" messa
98.
▲
by
jtaft
8y ago
Thanks for the clarification. I thought Columbia's definition of a pre-image attack was incorrect, due to the vagueness of the verbiage "existing file". Ie, I considered the chosen document created by google as an "exist
99.
▲
by
jtaft
8y ago
>However, given an existing file and hence its hash, it is not possible, as far as anyone knows, to generate a second file with that same hash. Interesting...I thought google did exactly this in 2017. Although, they controlled the PDF pr
100.
▲
by
jtaft
8y ago
For here am I sitting in a tin can Far above the world Planet Earth is blue And there's nothing I can do
101.
▲
by
jtaft
8y ago
http://www.woodmann.com/crackz/Orc.htm :). Chrome will display a warning about the page being unsafe. woodmann.com had a bunch of reversing stuff on their forums. Use wget or something if concerned.
102.
▲
Fravia’s web-searching lore (2009)
(search.lores.eu)
112 points
by
jtaft
8y ago
|
24 comments
103.
▲
by
jtaft
8y ago
"Hit enter to break into the command prompt..." I wonder what's there.
104.
▲
by
jtaft
8y ago
The engineering list is a decent start! Multiple vulnerability categories I see day to day appear to be missing though, such as race conditions, direct object references, and file inclusions. Would be nice to add a slide stating "Don&#
105.
▲
Five Minute Guide to Software Security
(oneupsecurity.com)
142 points
by
jtaft
9y ago
|
35 comments
106.
▲
Five Minute Guide to Software Security
(oneupsecurity.com)
1 points
by
jtaft
9y ago
|
0 comments
107.
▲
Remote Code Execution in Counter-Strike via Player Fragging
(oneupsecurity.com)
1 points
by
jtaft
9y ago
|
0 comments
108.
▲
Remote Code Execution via player fragging in source games
(oneupsecurity.com)
4 points
by
jtaft
9y ago
|
0 comments
109.
▲
Chrome XSS Auditor Bypass
(twitter.com)
2 points
by
jtaft
9y ago
|
0 comments