Hello world! From my 10 yrs as a dev working at scale and talking to 300+ security engineers, I have been meaning to share some dos-and-don'ts of API Security. ðŸ¤
This is my first time posting on Twitter. Shower some love 🕺 #apisecurity#securecodingpractice#devsecops
For anyone who is currently attempting the labs on @PortSwigger's @WebSecAcademygist.github.com/rizemon/677a…
Useful if you are studying for the Burp Suite exam and just want to focus on the Apprentice and Practitioner labs only!
In March, I found an SSRF in a @googlecloud service, which gave me access to a few internal Cloud projects.
I recorded myself finding the bug from start to finish. Today, I published a video where I react to these recordings and explain the issue.
piped.video/UyemBjyQ4qA
Our intern @daniellimws wrote a blogpost about the Taint Analysis tool that he worked with @Puzzorsj, @hi_im_d4rkn3ss & Akash
"Identifying Bugs in Router Firmware at Scale with Taint Analysis - starlabs.sg/blog/2021/08/ide… "
Sounds exciting? 😋
We hope it's a fun read on a Wednesday.