Egor Homakov
Architect of
Xln – Financial Planetary Substrate
|
Sakurity
| X:
@homakov
. homakov@gmail.com
Tuesday, July 3, 2012
The Most Common OAuth2 Vulnerability
›
HN discussion TL;DR If website uses OAuth multi-logins there is an easy way to log into somebody's account, protection is almost...
15 comments:
Friday, June 22, 2012
With New Features Come New Vulnerabilites. The Web is Broken.
›
I spam in twitter and RSS . HN discussi0n Security Digest: Rails coders, I remind you the very last time :) Run command Find ".t...
8 comments:
Wednesday, June 6, 2012
x-www-form-urlencoded VS json - Pros and Cons. And Vulns.
›
In this short post I want to remind you how agile HTTP requests are. By "requests" we all mean GET and POST - these are the majori...
24 comments:
Saturday, May 19, 2012
Injects in Various Ruby Websites Through Regexp.
›
On HN You are a web developer. Let's assume you are building a website using Ruby(and probably Rails or any other Ruby framework). Thi...
34 comments:
Tuesday, April 24, 2012
"match" in Rails and CSRF
›
Related : CSRF afterparty & MUST READ rules Playing With Referer & Origin + disqus.com and yfrog.com Vulnerability ) Sometim...
Playing With Referer & Origin
›
(related: CSRF afterparty & MUST READ rules ) If you read owasp you should know that Referer has never been a good protection . I...
4 comments:
Monday, April 2, 2012
CSRF examples
›
Previous discussion on hacker news with tons of critics and conservatism. Remark: Post is published on April 2(but was expected ...
16 comments:
Friday, March 30, 2012
CSRF Is A Vulnerability In All Browsers
›
Navigation: #1 CSRF Is A Vulnerability In All Browsers - You MUST Deny It ASAP. #2 top secret(will be published on April 1) #3 Another Ra...
16 comments:
Sunday, March 4, 2012
Hacking rails/rails repo
›
So I commited in rails/rails repo I simply added a <input value=USER_ID name=public_key[user_id]> field to Public key update form, w...
57 comments:
‹
Home
View web version