Mozilla Security Team, OWASP Zed Attack Proxy lead
Tweets
- Tweets
- Tweets & replies
- Photos & videos
Mozdef session in progress
by @PragtiC @KeshvicaS
cc @archana_atri @null0x00 @0x7eff @GurjantSadhra @njohar pic.twitter.com/RFR2FWKcoz
"Why is @zaproxy sending me so many emails??" Its not. You've scanned your 'Contact Us' page. This is a learning opportunity for you ;)
Repository on the @CyberSecMonth website includes @OWASPCornucopia @zaproxy @owtfp and 10 other #OWASP projects http://cybersecuritymonth.eu/references
" Shellshock exploiting demo using OWASP's ZAP & PentesterLab CVE-2014-627...: http://youtu.be/wqEeGNNIUDg via @YouTube " My first hacking demo
@jmbrnt @humanPincushion you can try some simple automation like with ZAP which will scan and point out dodginess https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project …
I think companies should strongly discourage employees from working on OSS during nights and weekends. That's what work hours are for.
70 retweets 65 favorites9 active scan rules promoted from alpha to beta, including #HeartBlead and #ShellShock and source code disclosure. On the Marketplace now.
@psiinon @manicode @jerryhoff working on a CI cheat sheet for the past few weeks. It may turn into a guide :)
@EoinKeary @manicode @psiinon @jerryhoff @jeremiahg @costlow
1. Education
2. DAST integrated in build
3. Arch review
4. App IDS
5. SAST
@manicode @psiinon @jerryhoff @stephendv @jeremiahg @costlow
1. DAST - low hangers
2. Education - prevent
3. SAST - audit code
4. Measure
sub reddit dedicated to software all software security items
http://goo.gl/Angnmh
#development #owasp #software #infosec #code
@psiinon @JariLaakso @neilstudd @europetesters @zaproxy I'm loving the list of interesting password fuzzing parameters today!
@ToolsWatch Thank you guys ! #BHEU and Arsenal was epic, we had so much feedbacks on @zaproxy and so much good karma \o/
@TheTestDoctor @neilstudd @europetesters With @zaproxy I noticed their "customer service" is faster and better than for most paid stuff.
@neilstudd @europetesters we will look at some cool stuff, including @zaproxy should be fun
The #JuiceShop vulnerable RIA is now also available as a @docker container: https://registry.hub.docker.com/u/bkimminich/juice-shop/ … - Pull, run, pentest! Enjoy!
How much do you know about webapp security? Download, run & attack https://github.com/bkimminich/juice-shop … and beat 20+ challenges based on @owasp #top10!
@psiinon bro, definitely you should bring @zackhimself with u next time to vegas. The audience was enjoying his skills and sense of humor.
Twitter may be over capacity or experiencing a momentary hiccup.
Visit Twitter Status for more information.