
mackowski
@kubamackowski
I help developers write secure code. | co-leader of OWASP Cheat Sheet Series project. | Application Security Engineer
ID: 1201794682868682752
https://cheatsheetseries.owasp.org/ 03-12-2019 09:26:00
121 Tweet
181 Followers
379 Following





It's been a year since Damian Rusinek wrote a series of articles about #OAuth. We hope you still keep it secure 🛡 securing.pl/en/secure-oaut… #ITSecurity #appsec

I highly recommend check out this new OWASP® Foundation project github.com/commjoen/wrong… Kudos for Ben D. DeHaan Jeroen for creating this! #appsec #owasp

Sometimes you get to scratch an itch and take something off your backlog that's been bugging you! We're now using CSP nonces in an enforced policy over at Report URI 😎 scotthelme.co.uk/report-uri-is-…



Thank you Maria Ines Parnisari 🇨🇦🇦🇷 for adding Relationship-Based Access Control (ReBAC) to the Authorization cheatsheet! cheatsheetseries.owasp.org/cheatsheets/Au… #AppSec #OWASP #owaspcheatsheetseries OWASP® Foundation Jim Manico from Manicode Security




🤬 XML Security in Java Turns out, it's crazy! Varying mitigations, security features that don't work as documented, and more Pieter De Cremer and Vasilii Ermilov give probably the most through treatment of Java XML security I've seen semgrep.dev/blog/2022/xml-…






Chris Wysopal Jim Manico from Manicode Security Reachability is not exploitabiity. And even if we consider technically reachable, exploitable data flows, the security impact is encoded in the threat model, not code (is it in internal tool? Is the functionality only exposed to admin roles? Would anyone benefit from exploiting?)

Catch the replay of Xavier René-Corail's talk about #CodeQL at #CNSCon! To shift security left, empower your developers with the Security as Code approach. youtu.be/aKv08sAUNUs