David K. (@ncd_leen) 's Twitter Profile
David K.

@ncd_leen

where is my mind?

IT security research @tuBraunschweig

Interested in, e.g., web security, input validation, enforcement of security and privacy properties

ID: 279443677

calendar_today09-04-2011 08:21:45

63 Tweet

55 Followers

258 Following

RuhrSec – IT Security Conference (@ruhrsec) 's Twitter Profile Photo

Sanitizer functions can be used to mitigate malicious code. Watch David Klein share his insights about custom JavaScript sanitizer functions. RuhrSec Ticketshop - Get your ticket know! 👉 ruhrsec.de/2023/tickets.h… 🌐 ruhrsec.de/2023/ #itsecurity #conference #Java #ITtalk

Sanitizer functions can be used to mitigate malicious code. Watch David Klein share his insights about custom JavaScript sanitizer functions.

RuhrSec Ticketshop - Get your ticket know!
👉 ruhrsec.de/2023/tickets.h…

🌐 ruhrsec.de/2023/

#itsecurity #conference #Java #ITtalk
RuhrSec – IT Security Conference (@ruhrsec) 's Twitter Profile Photo

We are excited to announce our next speaker: "Server-Side Browsers: Exploring the Web’s Hidden Attack Surface" by MariusM. Conference program, more information and details on our website: 🌐 ruhrsec.de/2023/ #itsecurity #itsicherheit #cybersicherheit #conference

We are excited to announce our next speaker:

"Server-Side Browsers: Exploring the Web’s Hidden Attack Surface"
by <a href="/m4riuz/">MariusM</a>.

Conference program, more information and details on our website:
🌐 ruhrsec.de/2023/

#itsecurity #itsicherheit #cybersicherheit #conference
RuhrSec – IT Security Conference (@ruhrsec) 's Twitter Profile Photo

And now catch up on: "Hand Sanitizers in the Wild: A Large-Scale Study of Custom JavaScript Sanitizer Functions" by David Klein. Conference program, more information and details on our website: 🌐 ruhrsec.de/2023/ #itsecurity #itsicherheit #cybersicherheit #conference

And now catch up on:

"Hand Sanitizers in the Wild: A Large-Scale Study of Custom JavaScript Sanitizer Functions"
by David Klein.

Conference program, more information and details on our website:
🌐 ruhrsec.de/2023/

#itsecurity #itsicherheit #cybersicherheit #conference
Thibaut Mattio (@tmattio_) 's Twitter Profile Photo

I'm considering launching OCaml Meetups in various major cities in Europe (for now). I'm looking for OCaml enthusiasts to co-host these Meetups. Interested? Send me a DM and let's chat! RTs are appreciated!

Aanjhan Ranganathan (@tuxmaniac) 's Twitter Profile Photo

Big change coming to USENIX Security starting 2025. "Starting with USENIX Security '25, we will be decoupling paper publication from paper presentation, so not all papers will have full-length talk presentations at the conference." usenix.org/blog/2023-usen…

\/era🌻 (@eramm314) 's Twitter Profile Photo

The 3rd Workshop on Rethinking Malware Analysis (WoRMA) will be co-located with EuroS&P 2024, in Vienna, Austria ☕️🏛️🏔️. Submit your work, be that novel technical research or a position/open-problem paper! worma.gitlab.io/2024/

jason polakis (@jpolakis) 's Twitter Profile Photo

The call for papers of the #SecWeb workshop (co-located with IEEE Security and Privacy) is now online! The deadline is in 1 month. Please consider submitting your web security and privacy research here! secweb.work/2024.html cc Marco Squarcina

Moritz Schloegel (@m_u00d8) 's Twitter Profile Photo

Fuzzing is hard, evaluating fuzzing is harder 🔥 For our new IEEE S&P paper, we studied 150 fuzzing evals and found issues such as lackluster documentation, bad experiment setups, or questionable CVEs 📄 Paper mschloegel.me/paper/schloege… 🔧 Help us fix this github.com/fuzz-evaluator…

David K. (@ncd_leen) 's Twitter Profile Photo

Hey Marco Squarcina, the self nomination link for Madweb 2025 is broken. Looks like the markdown conversion failed and the URL points to the form for 24.

Sonar Research (@sonar_research) 's Twitter Profile Photo

The reason most PHP-based HTML sanitizers are inherently vulnerable to bypasses is just the tip of the iceberg🥶. Check out our latest blog post to learn why server-side sanitization is doomed to fail. sonarsource.com/blog/sanitize-… #appsec #security #vulnerability #php

RuhrSec – IT Security Conference (@ruhrsec) 's Twitter Profile Photo

🚀 Check out the #RuhrSec 2025 program! 💡 14 expert talks are waiting for you. 🎟️ Don’t miss out—get your ticket now and join us! 👉 ruhrsec.de/2025/tickets.h… #itsecurity #itsicherheit #cybersecurity #cybersicherheit #itsecurityconference #bochum #NRW

🚀 Check out the #RuhrSec 2025 program!
💡 14 expert talks are waiting for you.
🎟️ Don’t miss out—get your ticket now and join us!

👉 ruhrsec.de/2025/tickets.h…

#itsecurity #itsicherheit #cybersecurity #cybersicherheit #itsecurityconference #bochum #NRW
slonser (@slonser_) 's Twitter Profile Photo

This year, there has been a lot of great research about HTML and sanitizers. I finally decided to organize my scripts to one package and am ready to present the HTML Universal Identifier (HUI). It's still a pretty raw version, but here it is: github.com/Slonser/hui

David K. (@ncd_leen) 's Twitter Profile Photo

Just returned from #BHEU. I presented my research on how server-side HTML sanitization is a security nightmare due to the mess that is HTML parsing. Huge thanks to Black Hat, Vandana Verma, and all the other great folks who made this such an amazing experience.

Just returned from #BHEU. I presented my research on how server-side HTML sanitization is a security nightmare due to the mess that is HTML parsing.

Huge thanks to <a href="/BlackHatEvents/">Black Hat</a>, <a href="/InfosecVandana/">Vandana Verma</a>, and all the other great folks who made this such an amazing experience.
USENIX WOOT Conference on Offensive Technologies (@wootsecurity) 's Twitter Profile Photo

USENIX WOOT Conference on Offensive Technologies 2025 (WOOT '25) CFP is online! Deadlines: - Up-and-coming track: March 4th, 2025 - Academic track: March 11, 2025 usenix.org/conference/woo…

CASA - Cluster of Excellence for Cyber Security (@casa_exc) 's Twitter Profile Photo

At the beginning of December, CASA PhD David Klein was at BlackHat Europe Black Hat to present ‘Parse Me, Baby, One More Time: Bypassing HTML Sanitizer via Parsing Differentials’. Of course, the Casafant joined this talk. Full paper ➡️ ias.cs.tu-bs.de/publications/p…

At the beginning of December, CASA PhD David Klein was at BlackHat Europe <a href="/BlackHatEvents/">Black Hat</a> to present ‘Parse Me, Baby, One More Time: Bypassing  HTML Sanitizer via Parsing Differentials’. Of course, the Casafant joined this talk. 
Full paper ➡️ ias.cs.tu-bs.de/publications/p…
James Kettle (@albinowax) 's Twitter Profile Photo

Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: portswigger.net/polls/top-10-w…

RuhrSec – IT Security Conference (@ruhrsec) 's Twitter Profile Photo

The amazing last talk for today: "Parse Me, Baby, One More Time: Bypassing HTML Sanitizer via Parsing Differentials." by David K.. 🌐 #RuhrSec Website ruhrsec.de/2025/ 📖 RuhrSec Program ruhrsec.de/2025/index.htm… #itsecurity #itsicherheit #cybersecurity

The amazing last talk for today:
"Parse Me, Baby, One More Time: Bypassing HTML Sanitizer via Parsing Differentials." by <a href="/ncd_leen/">David K.</a>.

🌐 #RuhrSec Website
ruhrsec.de/2025/

📖 RuhrSec Program
ruhrsec.de/2025/index.htm…

#itsecurity #itsicherheit #cybersecurity
Daniel Weber (@weber_daniel) 's Twitter Profile Photo

Heading to Black Hat Asia now! Leon Trampert and I will give a briefing about deanonymizing users not only on the web but also in their email clients! #BHASIA

RuhrSec – IT Security Conference (@ruhrsec) 's Twitter Profile Photo

Enjoy our great speakers in action with Keynotes by Ben Stock – Ben Stock and Daniel Gruss – Daniel Gruss. Playlist of #RuhrSec 2025 – 14 Talks 🌐 youtube.com/playlist?list=… Our YouTube Channel – Like and Subscribe 👍 🌐 youtube.com/@hackmanit-it-… #itsecurity #itsicherheit

Enjoy our great speakers in action with Keynotes by Ben Stock – <a href="/kcotsneb/">Ben Stock</a> and Daniel Gruss – <a href="/lavados/">Daniel Gruss</a>.

Playlist of #RuhrSec 2025 – 14 Talks
🌐 youtube.com/playlist?list=…

Our YouTube Channel – Like and Subscribe 👍
🌐 youtube.com/@hackmanit-it-…

#itsecurity #itsicherheit