Stephen Rees-Carter
@valorin
Friendly Hacker, Speaker, and PHP & Laravel Security Specialist.π΅οΈ I write securinglaravel.com and hack stuff on stage for fun. π (he/him)
ID: 21135677
https://pinkary.com/@valorin 17-02-2009 21:55:52
9,9K Tweet
5,5K TakipΓ§i
1,1K Takip Edilen
β οΈ New CRITICAL vulnerability disclosed in Livewire v3, you need to update ASAP! β οΈ This is a rather sneaky one that gives an attacker RCE (under the right conditions), and can be done unauthenticated with no user input... hence CRITICAL. π± securinglaravel.com/security-noticβ¦ #Laravel
This affects Laravel Pulse and Filament π¦ users so update if youβre using either package!
We've all heard about SQLi and XSS, but what about another big injection vector: Command Injection? It's less common but just as critical if your app does anything on the command line. Plus, it's not as easy to blindly escape be done... π― securinglaravel.com/security-tip-wβ¦ #Laravel
Off to a good start this week: I thought Michael Dyrynda was supposed to be in the air already, but I got my timing slightly wrong... π€¦ Still, it's not all bad, now he'll spend his entire 15 hour flight wondering what I'm up to. π