
Jerrin Jacob
@JerrinJacob26
Followers
59
Following
1K
Media
11
Statuses
555
Appsec enthusiast. Always in for learning. love tinkering and coding whenever possible.
Joined September 2015
Wrote a simple CSP report violations listener in GO.
github.com
CSP Report listener - This service can be used to listen to CSP Violations generated - jerrinss5/CSP-Listener
0
0
2
RT @RachelTobac: 🔑How does a FIDO security key limit the hacks we're seeing in the news now?🔑.Beyond fun to work with @Yubico & partner wit….
0
218
0
Huge shoutout to @ropnop on this article of SOP, CORS and CSRF. I don't know how many times I have referred to this blog to make sure I understand these concepts properly. Looking forward to more of these.🙌.
blog.ropnop.com
1
3
12
RT @briankrebs: Atlassian is warning about a zero-day in Confluence (CVE-2022-26134). This is a pre-auth, remote code execution bug. No pat….
0
97
0
RT @_r_netsec: Unauthenticated Remote Code Execution in Atlassian Confluence (CVE-2022-26134)
bugalert.org
An unauthenticated remote code execution flaw has been found, and is being actively exploited, in Atlassian Confluence, and has been assigned a bug alert severity of 'very high'. Atlassian recommends...
0
12
0
RT @manicode: Absolutely my favorite #AppSec publication and news source. Outstanding blog from @clintgibler.
tldrsec.com
How Chime empowers developers to own security via internal tools, purposefully vulnerable CI/CD exercises, a microservices-based framework for learning network security.
0
4
0
RT @praetorianlabs: We have a working exploit for the new spring rce vulnerability .
praetorian.com
Update: March 31, 2022 A patch has officially been released. https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement https://tanzu.vmware.com/security/cve-2022-22965 Overview Spring...
0
5
0
RT @marcioalm: FIX: Here is a PoC in how to bypass allowedLdapHost and allowedClasses checks in Log4J 2.15.0. to achieve RCE: ${jndi:ldap:/….
0
374
0
RT @pwntester: CVE-2021-45046 is vulnerable when attackers can control **non-message** parts of the pattern layout. Here are some examples 🧵.
0
103
0
RT @NCCGroupInfosec: We've updated the blog post on Log4Shell: Reconnaissance and post exploitation network detection. - New vulnerable .cl….
github.com
Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105) - fox-it/log4j-finder
0
48
0
RT @SteveLasker: More details on the @CloudNativeFdn #Notaryv2 Alpha 1 release, supporting #signing of @docker images and other #securesupp….
0
15
0
RT @arstechnica: Apple users warned: Clicking this attachment will take over your macOS
arstechnica.com
Internet shortcuts come with code execution capability. Latest Mac not fully patched.
0
34
0
RT @TwitterEng: Calling all bounty hunters - it’s officially go time! We’ve just released the full details of our algorithmic bias bounty c….
0
282
0
RT @manicode: I’m teaching a secure coding masterclass at GOTOpia Chicago on April 19th, this Monday! If you care to join please use discou….
0
10
0
RT @_tessr: Is this a phishing attempt? Goes to " and asks for username and pw . (if so, it nearly got me!) . /cc @….
0
832
0
RT @sethvargo: I wrote a highly-extensible #golang library for parsing environment variables into struct fields: ht….
0
112
0
RT @briankrebs: For 327 days, the impostor site has been stealing traffic/privacy/users from .
0
96
0
RT @XssPayloads: An FF only event from @PortSwiggerRes cheatsheet: <image src=validimage.png onloadend=alert(1)>.
portswigger.net
Interactive cross-site scripting (XSS) cheat sheet for 2025, brought to you by PortSwigger. Actively maintained, and regularly updated with new vectors.
0
22
0
RT @0xtakemyhand: Just published "[SSTI] Breaking Go's template engine to get XSS". I believe this to be the first payload for SSTI to comp….
0
49
0
RT @USCERT_gov: Shield your system from a malicious takeover: update Google Chrome! #Cyber #Cybersecurity #InfoSec.
0
47
0
RT @The_Pi_Hole: After a successful beta testing and development period (many thanks to the beta testers!), we are pleased to announce the….
0
243
0