Tanner Prynn (@tannerprynn) 's Twitter Profile
Tanner Prynn

@tannerprynn

Mostly appsec @[email protected]

ID: 19841574

calendar_today01-02-2009 01:32:03

140 Tweet

232 Takipçi

120 Takip Edilen

Pinboard (@pinboard) 's Twitter Profile Photo

Notorious great slate supporter @spdevlin has offered to match the next $13,500 in donations! Post donations you want matched to this thread and I will do the bookkeeping. secure.actblue.com/donate/great_s…

Jason Meltzer (@_jmeltzer) 's Twitter Profile Photo

I don’t talk about the work I do much but here’s a fun thing... security.googleblog.com/2018/10/google… The report we wrote is linked in the blog entry. @BearSSLnews @finderoffail David Wong Keegan Ryan Mason Hemmel NCC Group Research & Technology NCC Group Cryptography Services

Thomas H. Ptacek (@tqbf) 's Twitter Profile Photo

At the same time: PAKEs are only really valuable when your root of trust is a human-memorable password. If you factor out web applications, that doesn’t leave much else. You can do better than a PAKE in most non-browser applications.

Thomas H. Ptacek (@tqbf) 's Twitter Profile Photo

I’m the wrong person to ask; I’ve been offering NCC Group North America InfoSec to take it over (as have the other μC hackers), as it goes down for extended periods of time, repeatedly. Without their permission, I can’t stand up a reliable version. I wish they’d hand it off to me or Hans Nielsen.

Tanner Prynn (@tannerprynn) 's Twitter Profile Photo

Starting to write some blogs, here's one about Apple's App-Site Association standard that leaks web app routes (think robots.txt) NCC Group Research & Technology nccgroup.trust/us/about-us/ne…

NCC Group Research & Technology (@nccgroupinfosec) 's Twitter Profile Photo

Blog: A Novel CSP Bypass Using data: URI nccgroup.trust/us/about-us/ne… - or how to find an XSS payload which executes JavaScript from a data: URI, without using a <script> tag from a different domain. by Tanner Prynn

NCC Group North America InfoSec (@nccsecurityus) 's Twitter Profile Photo

Our new blog from Tanner Prynn makes your life a bit easier when it comes to #Frida - giving tips and tricks that other documentation doesn't cover. Read the whole post here --> bit.ly/2NEf7kT #android #JavaScript #java #application #secureapplications #appsec

Our new blog from Tanner Prynn makes your life a bit easier when it comes to #Frida - giving  tips and tricks that other  documentation doesn't cover. Read the whole post here --&gt; bit.ly/2NEf7kT #android #JavaScript #java #application #secureapplications #appsec
Tanner Prynn (@tannerprynn) 's Twitter Profile Photo

New Frida blog! If you've ever wanted to play puppetmaster to a reluctant Android app, you could do worse than stuffing it with Express.js and turning it into its own API 🤖

Tanner Prynn (@tannerprynn) 's Twitter Profile Photo

Hey! I wrote a new blog post on what safe & secure code looks like when writing authorization checks in web applications. Check it out: research.nccgroup.com/2020/04/21/cod…

Clint Gibler (@clintgibler) 's Twitter Profile Photo

🗒️ An Opinionated Web #Pentesting Guide by Tanner Prynn Covers a broad range of topics including * Application mapping * Reviewing the design * AuthN/AuthZ * Frontend attacks, input handling, & crypto #bugbountytips #websecurity github.com/tprynn/web-met…

NCC Group Research & Technology (@nccgroupinfosec) 's Twitter Profile Photo

Blog: Using UUIDs for Authorization is Dangerous (even if they’re cryptographically random) - UUIDv4 for unguessable IDs are not safe to use for traditional object-based access control - research.nccgroup.com/2021/05/10/usi… by Tanner Prynn

Blog: Using UUIDs for Authorization is Dangerous (even if they’re cryptographically random) - UUIDv4 for unguessable IDs are not safe to use for traditional object-based access control - research.nccgroup.com/2021/05/10/usi… by <a href="/tannerprynn/">Tanner Prynn</a>
Tanner Prynn (@tannerprynn) 's Twitter Profile Photo

Multiple vulnerabilities in Flower (CVE-2022-30034) and downstream attacks on Apache Airflow tprynn.github.io/2022/05/26/flo…

Tanner Prynn (@tannerprynn) 's Twitter Profile Photo

Tailscale has a feature called Tailscale Funnel that kind of does the opposite of everything else Tailscale does? It exposes nodes directly to the Internet. And all the hostnames are published in CT, so I scanned it #tailscale #nmap #appsec tprynn.github.io/2023/07/10/tai…