skip to main
|
skip to sidebar
MasterPass and PayPal
10 Jul 2011
Octocat Tattoo
of course it's not a real one
Newer Post
Home
Popular Posts
OAuth1, OAuth2, OAuth...?
TL;DR OAuth2 sucks. Please don't think about OAuth2 as about the next generation of OAuth1. They are completely different like colors: ...
J.Crew in the News: Prices the Same or Lower?
" Thanks! " to Cubbiccino (in this post), as well as others, who shared the following quotes from J.Crew (check...
J.Crew Factory: Get 50% off the entire store
" Thanks! " to many of you, who shared the following promotion for J.Crew Factory. J.Crew is offering Factory Store shoppers a...
Last Day! Extra 50% Off Final Sale at J.Crew
J.Crew sent an email this morning reminding customers that today is the last day they are offering 50% off Final Sale with promotional code ...
Rails 'params' #2
I discovered [1, nil] attack, but while i was checking unsafe query generation and DoS with symbols people on twitter found RCE for YAML thr...
Evolution of Open Redirect Vulnerability.
TL;DR ///host.com is parsed as relative-path URL by server side libraries, but Chrome and Firefox violate RFC and load http://host.com inst...
Octocat Tattoo
of course it's not a real one
Hacking Github with Webkit
Previously on Github: XSS , CSRF ( My github followers are real , I gained followers using CSRF on bitbucket ), access bypass, mass assignm...
J.Crew's April 2014 Catalog on Pinterest
" Thanks! " to many of you , including Susan (in this post), who let us know that there are several images from ...
Two "WontFix" vulnerabilities in Facebook Connect
TL;DR Every website with "Connect Facebook account and log in with it" is vulnerable to account hijacking. Every website relying o...