webtonull Profile Banner
Erlend Oftedal Profile
Erlend Oftedal

@webtonull

Followers
4K
Following
11K
Media
443
Statuses
11K

Security researcher at Crosspoint Labs. AppSec. Tweets are my own and do not express the opinion of my employer. OWASP. retire.js

Oslo, Norway
Joined January 2008
Don't wanna be here? Send us removal request.
@webtonull
Erlend Oftedal
2 months
Tweet media one
0
1
1
@webtonull
Erlend Oftedal
3 months
RT @OsloBSides: It's 2025!.šŸ—“ļø We have a date: October 30th. šŸ“¢ We have a CFP: 🌐 We have a website: .
0
5
0
@webtonull
Erlend Oftedal
5 months
RIP Gene Hackman
Tweet media one
0
0
1
@webtonull
Erlend Oftedal
6 months
Reminder that the Call for Presentations for Sikkerhetsfestivalen (The Security Festival) is open. OWASP Oslo is hosting an AppSec track. Scroll down the page for English version:.
0
0
0
@webtonull
Erlend Oftedal
6 months
RT @ThomasArdal: I've made a new Azure DevOps extension that runs Retire.js as part of a build pipeline. Retire.js will detect vulnerable J….
Tweet card summary image
marketplace.visualstudio.com
Extension for Azure DevOps - An Azure DevOps task to run Retire.js.
0
1
0
@webtonull
Erlend Oftedal
6 months
RT @ryanchenkie: āš ļø Developers, please be careful when installing Homebrew. Google is serving sponsored links to a Homebrew site clone tha….
0
3K
0
@webtonull
Erlend Oftedal
7 months
The CFP for the developer conference NDC Oslo closes today. Security talks of course also very welcome.
0
3
6
@webtonull
Erlend Oftedal
9 months
#BallonDor . Caroline Graham Hansen: 32 goals, 28 assists, average score 8.4.Aitana Bonmati: 19 goals, 18 assists, average score 8.0. Ok….
1
0
3
@webtonull
Erlend Oftedal
9 months
Back when I found an XSS in the Wifi Pineapple admin GUI by creating a wifi called "</textarea>" + XSS vector šŸ˜…
0
0
7
@webtonull
Erlend Oftedal
10 months
RT @rebane2001: new blogpost time!!. this one's a fun writeup on a vulnerability chain i found across multiple google services that earned….
lyra.horse
A writeup of my $4133.70 Google Drive vulnerability chain.
0
170
0
@webtonull
Erlend Oftedal
11 months
The CFP for NDC Security in Oslo, Norway is about to run out! Submit your talk today!.
Tweet card summary image
ndcsecurity.com
NDC Security 2026 is a 4-Day Event for Software Developers with a focus on Security. 2-5 March 2026 - Radisson Blu Scandinavia Hotel.
0
0
1
@webtonull
Erlend Oftedal
1 year
RT @OsloBSides: Ticket sales for BSides Oslo 2024 just opened at
0
3
0
@webtonull
Erlend Oftedal
1 year
RT @mkonda: Not to mention the staff like Kelly and Dawn and some of the old school folks like Laura Grau and Kate Hartmann. They were ama….
0
1
0
@webtonull
Erlend Oftedal
1 year
Great research from Gareth! You should be really restrictive in which characters you allow in email adresses. Ignore the RFC and restrict to what you actually need (allow as few special chars as possible).
@garethheyes
Gareth Heyes \u2028
1 year
Everyone knows that the RFCs for email addresses are crazy. This post will show without doubt that you should not be following the RFC.
0
0
2
@webtonull
Erlend Oftedal
1 year
You’re welcome, Southgate.
@webtonull
Erlend Oftedal
1 year
One would think Southgate would want to use the PL playmaker of the year when they score too few goals #EURO2024 #AVFC.
1
0
3
@webtonull
Erlend Oftedal
1 year
One would think Southgate would want to use the PL playmaker of the year when they score too few goals #EURO2024 #AVFC.
0
0
1
@webtonull
Erlend Oftedal
1 year
RT @degargoyle: This is Jimmy Zhong. This guy made $3.4 billion and hid it in a Cheetos popcorn tin. Just one mistake, and he lost EVERYTHI….
0
2K
0
@webtonull
Erlend Oftedal
1 year
RT @OsloBSides: We're out of hibernation and gearing up for this year's event! The date is October 14th 2024 with more details to follow, b….
docs.google.com
Our Call for Presenters is open through August 11th. We value human creativity and human-generated content. We will reject any clearly AI-generated submissions. If you have any questions about our...
0
1
0
@webtonull
Erlend Oftedal
1 year
The Ā«new facebook profiles for people not using their real nameĀ» are super useful… for spam.
0
0
2