Paul

Geek

Paul boosted:
nickbeardednickbearded
2025-04-30

Big news in the project: introducing — the same minimal, powerful BashCore, now with a lightweight graphical interface!
Tested on my old machine: just 300MB RAM on boot.
Hoping to release a public ISO soon using live-build!

It’ll include all BashCore tools +

@albinowax Your research is always mind blowing. Can’t wait!

@tib3rius That's excellent - haha

Paul boosted:
Lesley Carhart :unverified:hacks4pancakes@infosec.exchange
2025-04-02

Hello friends. The dreaded and long awaiting blog on WHAT THE FUCK HAPPENED TO THE CYBERSECURITY JOBS MARKET has arrived.

tisiphone.net/2025/04/01/lesle

I'm sorry.

Paul boosted:
2025-03-21

TIL of the bad.horse traceroute

the bad.horse traceroute has the entire lyrics to the sound
Paul boosted:
Gareth Heyes :verified:gaz@infosec.exchange
2025-03-19

You might have noticed that the recent SAML writeups omit some crucial details. In "SAML roulette: the hacker always wins", we share everything you need to know for a complete unauthenticated exploit on ruby-saml, using GitLab as a case-study.

portswigger.net/research/saml-

Paul boosted:

Paul boosted:
Patrick C Miller :donor:patrickcmiller@infosec.exchange
2025-03-04

@0xceba Thank you, this extension is awesome and is a huge time saver when testing APIs

Paul boosted:
2025-03-03

after a lengthy concept review, code review, and QA process, PortSwigger has published the Burp Variables extension to the BApp Store! if you do API testing from Burp, you should look into this productivity extension which allows you to store and reuse variables in your outgoing requests, similar to other API testing clients like Postman and Insomnia. this is a productivity boon because it gives you single place to update ephemeral credential/token values and it helps you keep track of your identifiers & credentials which minimizes false positives. to learn more:
- install the extension from the BApp Store
- see more details at the BApp Store page: portswigger.net/bappstore/27f8
- review the source code at the extension's source repo: github.com/0xceba/burp_variabl

#burp #burpsuite #burp_suite #pentesting #pentest #bugbounty #bugbountytips #hacking #cybersecurity #infosec

Paul boosted:
MacRumors.commacrumors
2025-02-26
Paul boosted:
Gareth Heyes :verified:gaz@infosec.exchange
2025-02-25

In case you missed them, here are all the videos to highlight some of Hackvertor v2 features.

youtube.com/watch?v=RV0LIlv6CCA

@albinowax @raptor @gaz I’d love to see local LLM support. Due to our contracts, I can’t utilize this feature until it supports that. I have other extensions that add AI and support local LLM so that is nice, but I’d like to enable the full suite of AI features.

Paul boosted:
Gareth Heyes :verified:gaz@infosec.exchange
2025-02-20

We've just released Shadow Repeater, for AI-enhanced manual testing. Simply use Burp Repeater as you normally would, and behind the scenes Shadow Repeater will learn from your attacks, try payload permutations, and report any discoveries via Organizer.

Shadow Repeater is now available via the BApp store. For technical details & backstory, check out our blog post: portswigger.net/research/shado

Paul boosted:
Patrick C Miller :donor:patrickcmiller@infosec.exchange
2025-02-11

Microsoft Identifies 3,000 Leaked ASP.NET Keys Enabling Code Injection Attacks thehackernews.com/2025/02/micr

Paul boosted:
2025-02-09

🎉 PESD v2.0 is now in the BApp store! Effortlessly generate dynamic sequence diagrams directly from BurpSuite traffic!
Now you can also create your own theme, conveniently edit the generated diagrams with MD syntax and much more! Install it today! 🎉
#doyensec #appsec #burpsuite #security

Paul boosted:
Greg Wilsongvwilson
2025-02-08

This link has been taken down from the NASA site by someone who probably told themselves as a kid that they would have stood up to the Nazis in the 1930s: nasa.gov/universe/nasa-intern- Here's the story that Musk and Trump and their goons are so afraid to let you read scitechdaily.com/nasa-intern-f

Screenshot of post by Rose Ferreira saying, "Well, my bio just got removed from the NASA site because of an order that went out to remove stuff about women in STEM. I've only been on Threads for a full year, so a lot of people here never heard of a feature tha tNASA did on me talking about my love of the Moon, how I grew up in poverty, then my homelessness in the US, and then me being at NASA itself. That's how easy it is to erase you as a person, and everything you've done. I'm not even sure how I feel right now."
Paul boosted:
2025-02-04

I'm excited to announce Burp Variables v.1.1.6. this version has an updated UI which streamlines how variables are added: they can now be added through the dedicated panel on the Variables tab or via the context menu for requests that come from the message editor. the latter option is convenient when working with new variable names that haven't been memorized yet. download the new release at: github.com/0xceba/burp_variabl

#burp #burpsuite #burp_suite #pentesting #pentest #bugbounty #bugbountytips #hacking

Paul boosted:
Cru Scanlan | Photographercruscanlan
2025-01-24

Hi Mastodon, time for an !

With Instagram getting continually worse I thought I'd give this a go. Looks like a promising platform and I'm excited to see where it goes.

My name is Cru and I'm a landscape from Rainbow Beach,

My photography is mostly and images. I sell my images as prints and for licensed use. This past year, much of my images have been taken in .

My website can be found here cruscanlan.com

Cirque 2024Celestial Flow 2024Cascade 2024Verdant Giant 2023
Paul boosted:
2025-01-24
Bmw has announced leaving X. Historic first time bmw has signaled before lane departure

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst