snyff Profile Banner
Louis Nyffenegger Profile
Louis Nyffenegger

@snyff

Followers
20K
Following
23K
Media
1K
Statuses
12K

Founder/CEO/Trainer/Researcher/CVE archeologist @PentesterLab. Security engineer. Bugs are my own, not of my employer...

โ˜
Joined December 2011
Don't wanna be here? Send us removal request.
@snyff
Louis Nyffenegger
2 months
As an engineer, I โค๏ธ clever engineering. Ruby on Rails relies on signed sessions (AES GCM). They are secure, but there is a catch: you cannot invalidate them early. You have to wait for expiry. Workarounds exist, like caching sessions you want to kill, but nothing universal.
2
4
36
@snyff
Louis Nyffenegger
4 days
Heading to @CHCon_nz next week! Come say hi at the @PentesterLab booth ๐Ÿ‘‹ First people with an active PentesterLab sub get a free t-shirt ๐ŸŽ First in, first served!
0
3
19
@sekurprivate
Sekur Private (OTCQB:SWISF)
5 days
Youโ€™re not the customer, youโ€™re the data stream. Every โ€œfreeโ€ message, file, and login you create is a micro-investment, just not in your own business. Itโ€™s funding someone elseโ€™s data vault.
1
4
14
@snyff
Louis Nyffenegger
7 days
Anyone knows what the end goal is with those? @GitHubSecurity
1
0
6
@snyff
Louis Nyffenegger
7 days
The TIOBE Index is a psy-op operation from Python lovers. ๐Ÿ
0
0
1
@snyff
Louis Nyffenegger
8 days
I had a great time at BSides Perth this week-end! My talk went well, people even laughed at some of my jokes, and the entire room unanimously agreed that Ruby is the best programming language. What a success!
1
0
6
@BSidesPer
BSides Perth
10 days
0
3
9
@snyff
Louis Nyffenegger
11 days
Imagine if knuth chose 1 BTC instead of $2.56
0
0
1
@4osp3l
Gospel
1 year
Here is a great platform you can learn & practice "All ABout Bug Bounty From Recon To Exploitation" https://t.co/N27mYwh0yO #Bug_Bounty
0
6
51
@mqst_
Muqsit ๐•
3 months
๐Ÿ“ Effective Note-Keeping for Web Security Code Reviews Blog: https://t.co/37f3azi439 author: @snyff #infosec
0
24
86
@DeniseKShull
Denise K Shull
5 days
In 2003 I learned through the research of Damasio that there is no such thing as a decision made without emotion. Amazes me how many people still say "control the emotion" - a logical fallacy. In 2008, I learned that the brain is a prediction machine. In 2015 , I learned that
5
3
68
@PentesterLab
PentesterLab
12 days
Wanna up your Go secure code review game? Spot timing attacks, ZIP slip, hard-coded secrets & weak randomness! All with code examples. ๐Ÿ” Read: https://t.co/yKhTO5L2t0 #AppSec #Go #Cybersecurity
0
3
24
@TheRaildex1
raildex1
12 days
@0xMstar OSCP first, but then Iโ€™d go for CWEE instead (Gold Annual from HTB). If you want specific appsec - https://t.co/DaEldybakp for code review, and n-day/research @steventseeley โ€˜s full Stack course (he wrote the OG modern OSWE course material from memory)
0
3
12
@ahmtbrt07
Ahmet Barut
13 days
Most Important Subdomains - development - test - production You might encounter applications that companies shouldn't open to the internet. If you're lucky, you could make big profits. Thanks legend @snyff #EthicalHacking #BugBounty
0
2
4
@snyff
Louis Nyffenegger
18 days
0
0
5
@snyff
Louis Nyffenegger
18 days
Food $400 Data $100 Rent $850 H100 $36,000 Utility $150 Can someone who is good with money help me budget this? My family is dying.
0
0
3
@beginbotbot
Beginbot ๐Ÿƒ
21 days
Wait vercel is a website thingy? I thought it was an insult for frontend devs like incel
85
180
5K
@openmind_agi
OpenMind
13 days
In @FortuneMagazineโ€™s latest robotics commentary, OpenMind Founder @JanLiphardt explores a key question: "How do you trust a robot you've never met?" Only through transparent, enforceable, and human-first standards can we truly build trust with robots. (Full Article Below)
67
70
455
@snyff
Louis Nyffenegger
21 days
As one of my teachers used to say: eval() is evil...
@PentesterLab
PentesterLab
22 days
๐ŸWhen you like playing with danger in Python... ๐Ÿ๐Ÿ
1
0
8
@snyff
Louis Nyffenegger
29 days
Speaking at @BSidesPer soon (Only there on Sunday but I'm bringing swag). Iโ€™ll present the same talk (slightly different forms) at @kawaiiconNZ and Hack The Hills! The main idea: Most people donโ€™t look at the actual code changes when a CVE drops.
1
0
9