Scholars - Women in Security and Privacy
WISP Privacy Statement
Today Iβm raising money to send underrepresented folks to @defcon.bsky.social + other technical cons/training next year! Yes, youβll get a tax write off β€οΈ
Hear our Scholar Stories for the impact of WISP: www.wisporg.com/scholars
Hereβs the donation link! wisporg.app.neoncrm.com/forms/donation
03.12.2024 14:58
π 58
π 28
π¬ 0
π 4
Scene from "The Hobbit" movie with Elrond and Bilbo talking with meme text saying "it is said: go not to the principal engineers for counsel, for they will say both no and yes"
29.11.2024 19:30
π 5
π 0
π¬ 0
π 0
What I had read in multiple places seemed to indicate that it did not do that, but now I'm not so sure
26.11.2024 05:41
π 2
π 0
π¬ 1
π 0
Imported my previous posts from twitter. App should show a small indicator to note that it isn't new
26.11.2024 04:17
π 3
π 0
π¬ 1
π 0
speech and writing are just serialization for human thoughts #showerthoughts
06.02.2024 07:27
π 3
π 0
π¬ 0
π 0
summary of how apps tended to mitigate a reported deserialization vulnerability
25.08.2022 00:23
π 2
π 0
π¬ 0
π 0
summary of how gadgets tended to be introduced into a library
25.08.2022 00:17
π 2
π 0
π¬ 1
π 0
paper here https://arxiv.org/pdf/2208.08173.pdf
24.08.2022 23:59
π 1
π 0
π¬ 1
π 0
Some very cool research and analysis in this paper, but remember kids: don't assume that fixing/removing/blocking gadget classes is going to protect you if you're still deserializing objects from untrusted data https://twitter.com/TheRegister/status/1561805738699259905
24.08.2022 23:55
π 2
π 0
π¬ 1
π 0
Though tbf, anything trying to be an API is only as good as it's documentation, contracts, and change control
24.08.2022 05:19
π 0
π 0
π¬ 0
π 0
Also, your internal app logs are not an API https://twitter.com/rakyll/status/1562239578865405952
24.08.2022 05:16
π 0
π 0
π¬ 1
π 0
More fun bespoke Oracle product java deserialization gadget chains and blacklist bypasses https://twitter.com/peterjson/status/1539920744129634305
24.06.2022 00:42
π 0
π 0
π¬ 0
π 0
This seems likely to be fruitful against a lot of apps out there. https://twitter.com/iangcarroll/status/1455580303578124291
05.11.2021 00:01
π 0
π 0
π¬ 0
π 0
https://twitter.com/josephfcox/status/1448711092201472006
14.10.2021 18:17
π 0
π 0
π¬ 0
π 0
Great analogy, and applicable to the whole tech industry https://twitter.com/kwestin/status/1445965144979218435
07.10.2021 19:16
π 0
π 0
π¬ 0
π 0
Good survey of Ruby ecosystem deserialization vulnerabilities https://twitter.com/zenn_dev/status/1442089822156296193
27.09.2021 15:20
π 0
π 0
π¬ 0
π 0
In my previous life as a lead sweng, our project's maven pom.xml literally listed my role as "code archaeologist" https://twitter.com/rakyll/status/1441832225595527169
25.09.2021 18:37
π 0
π 0
π¬ 0
π 0
Artistic rendition of code reuse attacks a la ROP and deserialization https://twitter.com/Rainmaker1973/status/1402664288104292353
21.09.2021 18:57
π 0
π 0
π¬ 0
π 0
Older post focusing on intra-service auth is also great https://web.archive.org/web/20200507173734/https://latacora.micro.blog/a-childs-garden/
08.09.2021 07:51
π 0
π 0
π¬ 0
π 0
Great overview and pros/cons of various types of auth tokens https://twitter.com/tqbf/status/1430278923653468168
08.09.2021 07:45
π 0
π 0
π¬ 1
π 0
That's the sound of 100k developers firing up Linux VMs https://twitter.com/QuinnyPig/status/1432720164169076755
31.08.2021 17:52
π 0
π 0
π¬ 0
π 0
I don't always do work on weekends, but when I do...
21.08.2021 22:38
π 0
π 0
π¬ 0
π 0
More excellent WebLogic deserializaion gadget blocklist bypass work from @matthias_kaiser. I've lost count on all these. https://twitter.com/matthias_kaiser/status/1417837065060950021
21.07.2021 22:29
π 0
π 0
π¬ 0
π 0
PSA: folks should be aware that AWS Infinidash allows full read access by default so make sure you lock yours down with a fine-grained IAM policy
03.07.2021 21:30
π 0
π 0
π¬ 0
π 0
This would make a great April fool's day prank next year https://twitter.com/FooBartn/status/1411349844292247553
03.07.2021 19:37
π 0
π 0
π¬ 0
π 0
For anyone who didn't finish the Deathball challenge series at @LayerOneCTF and was curious, here's the map of our pseudo-randomly generated network REPL container labyrinth:
31.05.2021 02:12
π 0
π 0
π¬ 1
π 0