EdOverflow Profile Banner
Ed Profile
Ed

@EdOverflow

Followers
20K
Following
3K
Media
186
Statuses
1K

Web developer & security researcher. Senior Pentester @cure53berlin. Author of @securitytxt. ➡️ https://t.co/BOy1tiLLBr

Joined October 2016
Don't wanna be here? Send us removal request.
@EdOverflow
Ed
3 years
After 5 years of work, security.txt is officially an RFC. I am pleased to announce RFC 9116: I would like to use this opportunity to thank those who made this possible. Thank you. ❤️
Tweet media one
43
975
3K
@EdOverflow
Ed
2 years
RT @swisscyberstorm: The Swiss Federal Government has adopted a report on ethical hacking referencing two @swisscyberstorm 2023 speakers: @….
0
3
0
@EdOverflow
Ed
2 years
I will be giving a talk on Coordinated Vulnerability Disclosure (CVD) at Swiss Cyber Storm. If you are interested in attending, please find additional information below.
@swisscyberstorm
swisscyberstorm
2 years
Speaking @swisscyberstorm 2023.Edwin Foudil (@cure53berlin): “Navigating The Coordinated Vulnerability Disclosure Landscape”.Demystifying concepts surrounding CVD and showing solutions to overcome challenges.Program: Tickets: #SCS23
Tweet media one
1
2
14
@EdOverflow
Ed
2 years
RT @KarimPwnz: 👋 I'm graduating (Spring 2024), and I am looking for a security role in the US. My interests include web app security, CI/CD….
0
8
0
@EdOverflow
Ed
2 years
I have set up a LinkedIn profile if people want to stay connected:
0
0
9
@EdOverflow
Ed
2 years
RT @securitytxt: Where did you first hear about security.txt?.
0
2
0
@EdOverflow
Ed
2 years
RT @securitytxt: How do you pronounce "security.txt"?.
0
2
0
@EdOverflow
Ed
2 years
I am working on something fun with @KarimPwnz to address the challenge of repetitive security questionnaires: @BlueMagnetIO (.
Tweet media one
0
4
15
@EdOverflow
Ed
2 years
RT @securitytxt: Exciting news! @Apple joins the list of companies with a security.txt file. Now, we only need @netflix to complete the FAA….
0
87
0
@EdOverflow
Ed
2 years
I have been playing around with SvelteKit a lot recently. I wrote a short blog post on adding security headers to SvelteKit applications: I might do a more long-form one on the security pitfalls of SvelteKit applications at some point.
Tweet media one
1
4
26
@EdOverflow
Ed
2 years
Reminder: if you would like to follow my blog via RSS, I have a feed at :).
0
0
7
@EdOverflow
Ed
2 years
With references to @hacker_ and @fin1te. Thank you to @KarimPwnz for reviewing a draft.
0
0
5
@EdOverflow
Ed
2 years
I have published a new blog post on my bug bounty methodology: "Learn to build it, then break it" —
4
40
193
@EdOverflow
Ed
2 years
Nice blog post by @KarimPwnz on the security implications of command injection in GitHub Actions.
@KarimPwnz
Karim Rahal
2 years
You have command injection in a GitHub Actions workflow. Now what?. Read my blogpost on leaking secrets from GitHub Actions workflows:.
0
1
11
@EdOverflow
Ed
3 years
Retweeting this because I know BSides London tickets are hard to come by. :).
@controlplaneio
controlplane
3 years
Security BSides London: Are you a woman who works (or wants to work) in tech? We have FIVE tickets to give away for the Security BSides London conference, Saturday 10 December. Just DM us to get one. Please RT. @BSidesLondon #BSidesLDN2022 #WomenInTech
Tweet media one
0
1
8
@EdOverflow
Ed
3 years
Also, shout-out to @internet_nl & @mxsash for their work integrating security.txt checks in
0
0
2
@EdOverflow
Ed
3 years
It was a pleasure presenting with @jschreuder and @DTC_NL at @OneConferenceNL. The work they are doing to promote security.txt in the Netherlands is amazing. You can read more about their work here:
1
2
13
@EdOverflow
Ed
3 years
RT @troyhunt: I love that the Dutch government is actively promoting security.txt and encouraging companies to establish a route for report….
0
20
0
@EdOverflow
Ed
3 years
RT @internet_nl: Where can ethical hackers report vulnerabilities at your organization? Publish a security.txt file and test it with Intern….
0
41
0
@EdOverflow
Ed
3 years
And here are some photos from the trip. Thank you, @spaceraccoonsec, for being an excellent tour guide. :)
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
0
6
@EdOverflow
Ed
3 years
Thank you, @fbsecurity, for organising another fantastic event. I thoroughly enjoyed BountyCon and exploring Singapore. Team BBAC members (@xdavidhu, @_zulln, @ElSec_, @spaceraccoonsec, @rub003, @EdOverflow) managed to find valid vulnerabilities with @rub003 finishing #3 overall.
Tweet media one
Tweet media two
Tweet media three
Tweet media four
4
4
62