Sebastian Salla (@sebsalla) 's Twitter Profile
Sebastian Salla

@sebsalla

Founder & CEO at CanIPhish.com • Cloud Security Architect at Palo Alto Networks • Finding ways to sneak into your Inbox

ID: 941079512007110656

linkhttps://caniphish.com calendar_today13-12-2017 22:56:54

14 Tweet

94 Takipçi

29 Takip Edilen

Tavis Ormandy (@taviso) 's Twitter Profile Photo

I finally wrote a small tool I've wanted for a long time: A parallel testcase minimizer. It's called halfempty, and I'm already finding it useful as part of my fuzzing workflow. /cc lcamtuf github.com/googleprojectz…

I finally wrote a small tool I've wanted for a long time: A parallel testcase minimizer. It's called halfempty, and I'm already finding it useful as part of my fuzzing workflow. /cc <a href="/lcamtuf/">lcamtuf</a> github.com/googleprojectz…
Tim Medin @timmedin.bsky.social 🇺🇦 (@timmedin) 's Twitter Profile Photo

What a brilliant idea! Phishious provides the ability to see how various Secure Email Gateway technologies behave when presented with phishing material. github.com/Rices/Phishious

Have I Been Pwned (@haveibeenpwned) 's Twitter Profile Photo

New breach: Online booking service FlexBooker had 3.7M accounts breached last month. Data included email addresses, names, phone numbers and for some accounts, partial credit card data. 69% were already in Have I Been Pwned haveibeenpwned.com

Sebastian Salla (@sebsalla) 's Twitter Profile Photo

Over the past month I've been researching IP-takeover vulnerabilities specific to email sender supply chains. After some initial testing I decided scan 1.8 Million Australian domains... and found some pretty interesting results. Check it out the blog! caniphish.com/phishing-resou…

Sebastian Salla (@sebsalla) 's Twitter Profile Photo

I learnt something new just now. If you want the #privacy protection of DuckDuckGo but your search results from #Google then just prepend "!Google" to your DuckDuckGo search. Et voila, your google search gets laundered and your privacy remains respected.

Sebastian Salla (@sebsalla) 's Twitter Profile Photo

Maintaining control over all the IPs in your SPF record are crucial to ensuring you're not vulnerable to IP takeover attacks!

Sebastian Salla (@sebsalla) 's Twitter Profile Photo

Checkout our latest blog post! After scanning 1.7 million Australian domains we found 1.62 million SPF and DMARC security issues. 542 domains were misconfigured to such an extent that any public IP address could send SPF authenticated emails as them! caniphish.com/phishing-resou…

Sebastian Salla (@sebsalla) 's Twitter Profile Photo

Next week I'll be presenting two talks at two conferences! If you're at the AWS Public Sector Summit in Canberra or CrikeyCon in Brisbane, please come by and say hello! AWS Public Sector Summit Talk: Cloud-focused security for speed and scale CrikeyCon Talk: The Art of Phishing

Sebastian Salla (@sebsalla) 's Twitter Profile Photo

In my latest security research I found that due to severe misconfigurations, I was able to deliver SPF authenticated emails on behalf of the Ukrainian MoD, MIT and 1000+ others. caniphish.com/phishing-resou…