Jerrin Jacob Profile
Jerrin Jacob

@JerrinJacob26

Followers
59
Following
1K
Media
11
Statuses
555

Appsec enthusiast. Always in for learning. love tinkering and coding whenever possible.

Joined September 2015
Don't wanna be here? Send us removal request.
@JerrinJacob26
Jerrin Jacob
3 years
RT @RachelTobac: 🔑How does a FIDO security key limit the hacks we're seeing in the news now?🔑.Beyond fun to work with @Yubico & partner wit….
0
218
0
@JerrinJacob26
Jerrin Jacob
3 years
Huge shoutout to @ropnop on this article of SOP, CORS and CSRF. I don't know how many times I have referred to this blog to make sure I understand these concepts properly. Looking forward to more of these.🙌.
Tweet card summary image
blog.ropnop.com
1
3
12
@JerrinJacob26
Jerrin Jacob
3 years
RT @briankrebs: Atlassian is warning about a zero-day in Confluence (CVE-2022-26134). This is a pre-auth, remote code execution bug. No pat….
0
97
0
@JerrinJacob26
Jerrin Jacob
4 years
RT @marcioalm: FIX: Here is a PoC in how to bypass allowedLdapHost and allowedClasses checks in Log4J 2.15.0. to achieve RCE: ${jndi:ldap:/….
0
374
0
@JerrinJacob26
Jerrin Jacob
4 years
RT @pwntester: CVE-2021-45046 is vulnerable when attackers can control **non-message** parts of the pattern layout. Here are some examples 🧵.
0
103
0
@JerrinJacob26
Jerrin Jacob
4 years
RT @NCCGroupInfosec: We've updated the blog post on Log4Shell: Reconnaissance and post exploitation network detection. - New vulnerable .cl….
Tweet card summary image
github.com
Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105) - fox-it/log4j-finder
0
48
0
@JerrinJacob26
Jerrin Jacob
4 years
RT @SteveLasker: More details on the @CloudNativeFdn #Notaryv2 Alpha 1 release, supporting #signing of @docker images and other #securesupp….
0
15
0
@JerrinJacob26
Jerrin Jacob
4 years
RT @arstechnica: Apple users warned: Clicking this attachment will take over your macOS
arstechnica.com
Internet shortcuts come with code execution capability. Latest Mac not fully patched.
0
34
0
@JerrinJacob26
Jerrin Jacob
4 years
RT @TwitterEng: Calling all bounty hunters - it’s officially go time! We’ve just released the full details of our algorithmic bias bounty c….
0
282
0
@JerrinJacob26
Jerrin Jacob
4 years
RT @manicode: I’m teaching a secure coding masterclass at GOTOpia Chicago on April 19th, this Monday! If you care to join please use discou….
0
10
0
@JerrinJacob26
Jerrin Jacob
5 years
RT @_tessr: Is this a phishing attempt? Goes to " and asks for username and pw . (if so, it nearly got me!) . /cc @….
0
832
0
@JerrinJacob26
Jerrin Jacob
5 years
RT @sethvargo: I wrote a highly-extensible #golang library for parsing environment variables into struct fields: ht….
0
112
0
@JerrinJacob26
Jerrin Jacob
5 years
RT @briankrebs: For 327 days, the impostor site has been stealing traffic/privacy/users from .
0
96
0
@JerrinJacob26
Jerrin Jacob
5 years
RT @0xtakemyhand: Just published "[SSTI] Breaking Go's template engine to get XSS". I believe this to be the first payload for SSTI to comp….
0
49
0
@JerrinJacob26
Jerrin Jacob
5 years
RT @USCERT_gov: Shield your system from a malicious takeover: update Google Chrome! #Cyber #Cybersecurity #InfoSec.
0
47
0
@JerrinJacob26
Jerrin Jacob
5 years
RT @The_Pi_Hole: After a successful beta testing and development period (many thanks to the beta testers!), we are pleased to announce the….
0
243
0