lojikil Profile Banner
Logyi várja a Mikulást Profile
Logyi várja a Mikulást

@lojikil

Followers
3K
Following
77K
Media
72
Statuses
2K

Brains in the "trying to be a good dad despite having a bad dad" gang. ☦️|Philosopher|Offensive Security|PLT

the infosec oil barrel
Joined September 2011
Don't wanna be here? Send us removal request.
@lojikil
Logyi várja a Mikulást
3 years
I’m @lojikil@mastodon.social (and pinning now for others looking).
1
0
5
@lojikil
Logyi várja a Mikulást
3 years
Will mastodon assuage the deep-seated concerns about social media that I have? Absolutely not. Will it maybe be a cool place to release some bots? Maybe.
0
0
4
@grok
Grok
11 days
Join millions who have switched to Grok.
354
759
6K
@lojikil
Logyi várja a Mikulást
3 years
this is a niche costume, but one year I want one of my kids to dress up as your company's complete lack of operational security
Tweet media one
0
0
4
@lojikil
Logyi várja a Mikulást
3 years
RT @GlaasGD: attending #RoguelikeCelebration right now and the talks are super good! it barely started, strongly recommend you check it out.
0
2
0
@lojikil
Logyi várja a Mikulást
3 years
Every public Java library grows until it has some form of OGNL injection. /cc @DanAmodio.
@1ZRR4H
Germán Fernández
3 years
@GossiTheDog Similar to CVE-2022-33980 🤔.${script:js:java.lang.Runtime.getRuntime().exec("ping -c1 10.10.10.10")}.
Tweet media one
Tweet media two
1
0
2
@lojikil
Logyi várja a Mikulást
3 years
RT @raesene: Next part of my PCI Kubernetes series up now, looking at the authorization section - This one's not as….
0
10
0
@lojikil
Logyi várja a Mikulást
3 years
Also, the amount of semantic tools that default to CSV instead of n-triples or Turtle or the like is quite sad really.
1
0
1
@lojikil
Logyi várja a Mikulást
3 years
I haven’t worked in semantic data properly in years, but it’s amazing how unfriendly the tools have become to import/export, even as they have become amazing for doing the work.
1
0
2
@lojikil
Logyi várja a Mikulást
3 years
It’s basically me acting like Buck Turgidson for an hour
@absoluteappsec
Absolute AppSec
3 years
Absolute AppSec presents a special episode at 12 Noon Eastern/ 10 AM Mountain time! Join @sethlaw and guest host @lojikil with special guest @LegendaryPatMan. Key topics: #Informationwarfare vis-a-vis the real world case of Ukraine, #infosecurity, etc,
0
0
3
@lojikil
Logyi várja a Mikulást
3 years
RT @absoluteappsec: Absolute AppSec presents a special episode at 12 Noon Eastern/ 10 AM Mountain time! Join @sethlaw and guest host @lojik….
0
2
0
@lojikil
Logyi várja a Mikulást
3 years
It’s interesting that Multics solved certain classes of supply chain attacks (“Trojan horse” in the link below) in the 70s and we now act like this is truly a hard problem that is hard to solve…
1
4
7
@lojikil
Logyi várja a Mikulást
3 years
Thinking about this further, part of the issue is that CVEs are taken as a quality statement, rather than a point in time, point in environment issue. - Zero CVEs doesn’t mean your system has no flaws.- Finding CVEs means your bug tracking issue is public, not how smart you are.
@JGamblin
Jerry Gamblin
3 years
The House passed a defense spending bill saying you can't sell software to the DoD that has *any* known CVEs in it.
Tweet media one
0
5
21
@lojikil
Logyi várja a Mikulást
3 years
hardly surprising from experience but super interesting research pinning harder numbers as to the why.
0
1
4
@lojikil
Logyi várja a Mikulást
3 years
Me: [disables all location information in twitter and phone preferences].Twitter: hey would you like to know what people in your town are tweeting about?.Me: literally no.
0
0
3
@lojikil
Logyi várja a Mikulást
3 years
Does anyone know of the *opposite* of a boot2root? Like a local or online blue team CTF where you are given an image/log/whatever and have to find and remediate the problem?.
1
0
0
@lojikil
Logyi várja a Mikulást
3 years
Collecting “incredible journeys” one tshirt and tchotchke at a time….
@NPR
NPR
3 years
Meet Christian Warren, the software developer who has developed a niche hobby: collecting branded swag from massively hyped companies with epic flameouts — like Fyre Festival and CNN+.
0
0
1
@lojikil
Logyi várja a Mikulást
3 years
Listen, Google, I get it, I’m bad about opening a new calendar tab each time rather than finding the open one, but please only play the sound once, not 32 or more times, ok?.
2
0
12
@lojikil
Logyi várja a Mikulást
3 years
RT @herokustatus: Update: Heroku Security Notification
0
10
0
@lojikil
Logyi várja a Mikulást
3 years
RT @GitHubSecurity: GitHub has uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrat….
Tweet card summary image
github.blog
On April 12, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to...
0
662
0
@lojikil
Logyi várja a Mikulást
3 years
RT @TheMijCipher: Check out our latest blog post! My teammates and I have discovered several, severe vulnerabilities stemming from insecure….
0
8
0