This Sunday August 30 at 17Uhr I will be running a session on XSS for @haecksen@chaos.social
Join us in Might Mary!
https://www.haecksen.org/bbb-raume/
katalyst
If you were gonna start learning php today, what resources would you reach for?
Im thinking of moving my rotation curation project over to this platform. Has any experienced problems with accounts run by multiple users?
I mean.. im glad to be on the unseasonably cold summer side of global warming, rather than the catastrophic fire or flood side of things, but i am wearing way too many clothes for the "middle of summer"
@spandauAnders@ioc.exchange actually django was gonna be my next step.. i just thought maybe it makes sense to learn php first.. but you think i can jump straight in with django instead?
My aunt in New Zealand has started making videos of her life on her small farm. I think she has made art here, there is a special atmosphere https://www.youtube.com/watch?v=VPPEtHHKfhY
I thought HTTP2 smuggling was going to be waaaay harder that HTTP/1.1 but it turns out its really common to downgrade to 1.1 between the front end and the server. And HTTP/2 just ignores headers its not interested in. #bscp #portswigger #httpsmuggling #appsec
I've been studying for the bscp since the start of July. I read that HTTP Smuggling doesnt come up often in the exam, and when it does, its mind-blowingly hard. But I thought, while Im here, I might as well figure this out. THIS lab has totally challenged my understanding of how TCP works once it gets past a reverse proxy. Instead of getting its own client stream, from this point there is a pool of streams that can be shared by different client requests coming in. Its not the first lab I have come across that blurs this transport/web boundary in a way that seems like it really shouldnt be possible, but it is for sure the most spectacular to this point, as you get the actual request from the victim posted as a comment to a blogpost #wtf #tcp #bscp #portswigger #appsec