Egor Homakov

Architect of Xln – Financial Planetary Substrate | Sakurity | X: @homakov. homakov@gmail.com

Tuesday, July 3, 2012

The Most Common OAuth2 Vulnerability

›
HN discussion TL;DR If website uses  OAuth  multi-logins there is an easy way to log into somebody's account, protection is almost...
15 comments:
Friday, June 22, 2012

With New Features Come New Vulnerabilites. The Web is Broken.

›
I spam in  twitter and RSS . HN discussi0n Security Digest: Rails coders, I remind you the very last time :) Run command Find ".t...
8 comments:
Wednesday, June 6, 2012

x-www-form-urlencoded VS json - Pros and Cons. And Vulns.

›
In this short post I want to remind you how agile HTTP requests are. By "requests" we all mean GET and POST - these are the majori...
24 comments:
Saturday, May 19, 2012

Injects in Various Ruby Websites Through Regexp.

›
On HN You are a web developer. Let's assume you are building a website using Ruby(and probably Rails or any other Ruby framework). Thi...
34 comments:
Tuesday, April 24, 2012

"match" in Rails and CSRF

›
Related : CSRF afterparty & MUST READ rules Playing With Referer & Origin + disqus.com and yfrog.com Vulnerability ) Sometim...

Playing With Referer & Origin

›
(related:  CSRF afterparty & MUST READ rules  ) If you read owasp you should know that Referer has never been a good protection . I...
4 comments:
Monday, April 2, 2012

CSRF examples

›
Previous discussion on hacker news with tons of critics and conservatism. Remark: Post is published on April 2(but was expected ...
16 comments:
Friday, March 30, 2012

CSRF Is A Vulnerability In All Browsers

›
Navigation: #1 CSRF Is A Vulnerability In All Browsers - You MUST Deny It ASAP. #2 top secret(will be published on April 1) #3 Another Ra...
16 comments:
Sunday, March 4, 2012

Hacking rails/rails repo

›
So I commited in rails/rails repo I simply added a <input value=USER_ID name=public_key[user_id]> field to Public key update form, w...
57 comments:
‹
Home
View web version
Powered by Blogger.