Advertisement ยท 728 ร— 90

Posts by Dominique Righetto

๐Ÿ’ก Although the project is currently on hold due to the OWASP Foundationโ€™s migration to a new CMS (we are waiting for it to go live before strongly updating our content structure), we continue to update and improve the content behind the scenes.

4 days ago 0 0 0 0
Post image

๐Ÿ“ก OWASP Secure Headers Project: We have refactored the section on the browserโ€™s "Local Network Access" feature.

#appsec #appsecurity #owasp_shp

๐Ÿ“– owasp.org/www-project-...

4 days ago 1 0 1 0
Home | Security Titles

In collaboration with a couple of other leaders in the industry we are releasing securitytitles.com - It's an attempt to provide transparency about role levels, expectations and (just for the US market currently, salary ranges). For leaders writing JDs and candidates alike.

1 week ago 18 11 0 1
Preview
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.

๐ŸŽ‰ After a few years of refinement and close to 1 >> 9 commits, I'm pleased to announce the v1 release of my CORS middleware library for Go.

Let me know whether it patches things up between you and CORS!

github.com/jub0bs/cors

#golang #CORS

1 week ago 20 5 2 0
Preview
Defenders Finally Have the Edge - PentesterLab's Blog AI agents are changing vulnerability research, but the real advantage goes to defenders. Attackers face air-gap constraints while defenders get full access to frontier models on their own code. Every ...

Everyone is panicking about AI-generated zero days like it's an attacker story.

It's not.

Defenders can use the best models against their own code right now.

Your progress compounds. Attackers' job gets harder.

pentesterlab.com/blog/defende...

2 weeks ago 3 2 0 0
Preview
The Cornucopia of Gamified Threat Modeling At the OWASP Cornucopia project, we are done with updating the cards and help pages for the Website...

The Cornucopia of Gamified Threat Modeling

At the OWASP Cornucopia project, we are done with updating the cards and help pages for the Website App Edition v3.0!

dev.to/owasp/the-co...
#appsec #cybersecurity #gamedev #security

3 weeks ago 11 8 2 0

heads up: FreeBSD forums hacked. Be caeeful with your email or DMs coming from FreeBSD forum or freebsd{.}org for some time now.

https:// forums {.} freebsd {.} org/

2 weeks ago 49 31 1 2
Preview
Remote Command Execution in Google Cloud with Single Directory Deletion Introduction Hello, Iโ€™m RyotaK (@ryotkak ), a security engineer at GMO Flatt Security Inc. A while ago, I participated in the Google Cloud VRP bugSWAT, a live hacking event organized by Google. During...

๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿญ๐Ÿฏ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ
Only one entry but definitely worth reading!

โ˜๏ธ ๐—ฅ๐—ฒ๐—บ๐—ผ๐˜๐—ฒ ๐—–๐—ผ๐—บ๐—บ๐—ฎ๐—ป๐—ฑ ๐—˜๐˜…๐—ฒ๐—ฐ๐˜‚๐˜๐—ถ๐—ผ๐—ป ๐—ถ๐—ป ๐—š๐—ผ๐—ผ๐—ด๐—น๐—ฒ ๐—–๐—น๐—ผ๐˜‚๐—ฑ ๐˜„๐—ถ๐˜๐—ต ๐—ฆ๐—ถ๐—ป๐—ด๐—น๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† ๐——๐—ฒ๐—น๐—ฒ๐˜๐—ถ๐—ผ๐—ป
This one is a real tour de force: flatt.tech/research/pos....

2 weeks ago 2 1 0 0
Video

Dear contributors to Voxxed Days Luxembourg's renewed success: the call for your papers, supposedly closed tonight wil be extended by 2 weeks to accomodate latecomers.
A small reminder: 15 min. lunch talks are often under-filled, to test your speaker abilities, this is a perfect opportunity!

2 weeks ago 7 6 0 0
Advertisement
Example of execution

Example of execution

To make it visual, I made an example with a fictional function used to compare if two hosts have the same FQDN:

3 weeks ago 0 0 0 0

๐Ÿ”ฌ In Python, the zip() function consider the number of elements of the smallest of the both arrays passed. If the function is used against arrays with different sizes then the items that are parts of the largest array are skipped.

๐Ÿ“– References used:

- pentesterlab.com

#appsec #appsecurity

3 weeks ago 1 0 1 0

๐Ÿง‘โ€๐ŸŽ“ Learning of the day for me, once again thanks to @pentesterlab.com (for the presentation of the behavior and the code review lab) and Claude (for the detailed explanation).

#appsec #appsecurity

3 weeks ago 2 1 1 0
Testing AI for Vulnerability Research: 4 Approaches & Where I Failed | xclow3n Tested 4 AI-assisted approaches for finding vulnerabilities over one week. Found real bugs โ€” 14 confirmed vulns in one target in 20 minutes. Also burned time on an approach that found nothing useful. ...

๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿญ๐Ÿฎ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ
AI doing research, AI killing CTF

๐Ÿค– ๐—ง๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด ๐—”๐—œ ๐—ณ๐—ผ๐—ฟ ๐—ฉ๐˜‚๐—น๐—ป๐—ฒ๐—ฟ๐—ฎ๐—ฏ๐—ถ๐—น๐—ถ๐˜๐˜† ๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต: ๐Ÿฐ ๐—”๐—ฝ๐—ฝ๐—ฟ๐—ผ๐—ฎ๐—ฐ๐—ต๐—ฒ๐˜€ & ๐—ช๐—ต๐—ฒ๐—ฟ๐—ฒ ๐—œ ๐—™๐—ฎ๐—ถ๐—น๐—ฒ๐—ฑ
If you can only read one thing this week, make it this article: xclow3n.github.io/post/7.

3 weeks ago 4 2 1 0
Post image

Le CFP des 10 ans de VoxxedDays Luxembourg est toujours ouvert, ne trainez plus :)
โ†’ voxxedlu2026.cfp.dev#/

1 month ago 8 5 1 0
Preview
Advanced Web Hacking and Security Code Review Training | PentesterLab Learn advanced web hacking and security code review through real-world CVEs, vulnerable code, hands-on exploitation, and detailed technical walkthroughs.

๐Ÿ’ก The instruction "()" at the end is important otherwise the code is not executed.

๐Ÿ“– References used:

- pentesterlab.com

1 month ago 0 0 0 0

๐Ÿ”ฌ In JavaScript, the instruction "Function(inputString)()" cause the content of "inputString" to be executed. "Function()" is a constructor that creates a new function from a string of code, similar to "eval()", but slightly more contained.

#appsec #appsecurity

1 month ago 0 0 1 0
Example of execution.

Example of execution.

๐Ÿง‘โ€๐ŸŽ“ Learning of the day for me thanks to @pentesterlab.com (for the presentation of the behavior and the code review lab) and Claude (for the detailed explanation):

#appsec #appsecurity

1 month ago 1 1 1 0
Advertisement

๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿญ๐Ÿฌ, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ
A great mix of content this week!

๐Ÿ”’ ๐—œ๐—ฟ๐—ผ๐—ป๐—–๐˜‚๐—ฟ๐˜๐—ฎ๐—ถ๐—ป: ๐—” ๐—ฃ๐—ฒ๐—ฟ๐˜€๐—ผ๐—ป๐—ฎ๐—น ๐—”๐—œ ๐—”๐˜€๐˜€๐—ถ๐˜€๐˜๐—ฎ๐—ป๐˜ ๐—•๐˜‚๐—ถ๐—น๐˜ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ฒ ๐—ณ๐—ฟ๐—ผ๐—บ ๐˜๐—ต๐—ฒ ๐—š๐—ฟ๐—ผ๐˜‚๐—ป๐—ฑ ๐—จ๐—ฝ
Niels Provos (from OpenBSD's systrace) is sharing a new tool to sandbox your AI assistant: www.provos.org/p/ironcurtai....

1 month ago 4 1 1 0
CVE-2026-1731 Metasploit module demo

CVE-2026-1731 Metasploit module demo

My first @metasploit-r7.bsky.social module is live! You can now exploit CVE-2026-1731 (BeyondTrust command injection) with the latest version ๐Ÿ˜Ž

1 month ago 3 2 1 0
Browser-Based Port Scanning in the Age of LNA

๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿต, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ
Mostly AI...

๐Ÿ’ป ๐—•๐—ฟ๐—ผ๐˜„๐˜€๐—ฒ๐—ฟ-๐—•๐—ฎ๐˜€๐—ฒ๐—ฑ ๐—ฃ๐—ผ๐—ฟ๐˜ ๐—ฆ๐—ฐ๐—ฎ๐—ป๐—ป๐—ถ๐—ป๐—ด ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—”๐—ด๐—ฒ ๐—ผ๐—ณ ๐—Ÿ๐—ก๐—”
Leveraging Local Network Access to create a port scanner! wiki.notveg.ninja/tools/lna-po....

1 month ago 2 3 1 0
Preview
What you don't see - PentesterLab's Blog More and more, with the progress of coding agents, people are rewriting software.And honestly, it looks easy. You write a good ...

I wrote about what happens when you rewrite mature software with agents. You rebuild the features. You don't rebuild the scars.

vinext: one engineer, one week, $1,100 in tokens. Then plenty of vulnerabilities found within days.

pentesterlab.com/blog/what-yo...

1 month ago 4 5 0 1
vue de zensical

vue de zensical

Zensical : un gรฉnรฉrateur de sites statiques qui permet de transformer rapidement une documentation Markdown en un site professionnel, personnalisable et multilingue. (Dรฉcouvert via Mat V. )

๐Ÿ‘‰ Le projet : github.com/zensical/...
๐Ÿ‘‰ En savoir plus : https://zensical.org/

1 month ago 36 12 2 1
Preview
PentesterLab: Learn with our JavaScript Code Review The JavaScript Code Review Badge is our badge dedicated to security code review in JavaScript. It covers the discovery of weaknesses and vulnerabilities using source code review.

6 new code review labs just dropped ๐Ÿš€
+3 for JavaScript Code Review
+3 for Python Code Review

JS: pentesterlab.com/badges/javas...

Python: pentesterlab.com/badges/pytho...

1 month ago 5 2 0 0
Overview of one repo

Overview of one repo

๐Ÿง‘โ€๐ŸŽ“ As part of my homework on AI from an AppSec perspective, I have decided to gather all my content on GitHub so that I can share it in case anyone is interested.

๐Ÿ“– Cheat sheet, methodology and tools: github.com/righettod/to...

๐Ÿ”ฌ R&D: github.com/righettod/po...

#appsec #appsecurity #ai

1 month ago 1 1 0 0
Advertisement

๐Ÿ”ฅ OWASP CRS is evolving! Introducing #CRSLang โ€” a new YAML-based rule language replacing Seclang. Cleaner syntax, multi-engine support, bidirectional translation, and a lower barrier for new contributors.
Check it out ๐Ÿ‘‰ coreruleset.org/2026...
#WAF #AppSec #OWASP #ModSecurity

1 month ago 4 2 0 1

Erratum, it's opened tonight February the 15th ๐Ÿ˜‚
--------------
Erratum, c'est ouvert ce soir le 15 fรฉvrier ๐Ÿ˜‚

2 months ago 3 2 0 0
Video

Voxxed Days Luxembourg's CFP will be opened from tonight February the 17th at 11:30 PM to March the 29th at midnight.Luxembourg
----------------
L'appel aux orateurs de Voxxed Days sera ouvert ร  partir de ce soir, le 17 fรฉvrier ร  23h30 jusqu'au 29 mars ร  minuit.
---
voxxedlu2026.cfp.dev

2 months ago 6 10 2 0
Preview
Release Release v2.6.0 ยท OWASP/cornucopia What's Changed Bump svelte from 5.49.2 to 5.50.0 in /cornucopia.owasp.org by @dependabot[bot] in #2188 Bump postgrex from 0.21.1 to 0.22.0 in /copi.owasp.org by @dependabot[bot] in #2186 Bump wait...

OWASP Cornucopia just release v2.6.0

github.com/OWASP/cornuc...

The new release comes with support for continuing the game session even if players can not continue the game when playing on copi.owasp.org

#owasp #appsec #security #cornucopia

2 months ago 7 4 1 0
Post image

Added a small feature to cspbypass.com to warn the user if unsafe-inline is detected, in which case you typically donโ€™t need to waste time hunting for 3rd-party whitelisted CSP bypasses and go straight to inline scripts / event handlers.

2 months ago 7 5 0 0
Post image

Sqldef : un outil CLI qui permet le "diffing" de deux schรฉmas SQL et de gรฉnรฉrer automatiquement les instructions de migration nรฉcessaires.

๐Ÿ‘‰ sqldef.github.io/

2 months ago 17 2 1 0