RSSAmplifier

Blog

/dev/alias – Hack. Dev. Transcend.

Follow me into the rabbit hole that is my mind and learn about topics including.. security, technology, efficiency, biohacking, health, personal growth and probably a whole lot more.

devalias.netRSS feed ↗10 posts

Latest posts

Forming Serverless Clouds with AWS: CloudFormation, SAM, CDK, Amplify

Recently I have been playing around with a few little side projects, and trying out different ways of getting them IntoTheCloud(tm). If you know me, you know that I'm pretty big on increasing efficiency, reducing boilerplate/time to start, automation, infrastructure as code (IaC), and similar fun things.

Presenting at DEF CON 26 - Bug Bounty Hunting on Steroids

(Update: The talk recording is now up on YouTube, latest links to related content in this tweet)

USB Reverse Engineering: Down the rabbit hole

Thanks for the featured writeup Hackaday! Make sure to check out the comments over there as well. Looks like Hackernoon picked it up as well, make sure to check in with the comments there too. It would be great if you could also head over to Hacker News, give an upvote, and join in the comments there. Let's get this information out there!

Imagine a world..

Imagine a world driven by the strive for progress, improvement and innovation, rather than fuelled by corporate greed. Ideas and breakthroughs are shared freely and openly. Where instead of multiple separate entities having to expend the same effort to unlock the same benefits time and time again, locking them away inside their own corporate silos to ration out to the masses at overly inflated…

DIY Light Therapy (Red/Near Infrared, Cold/Low Level Laser, Blue/UV, etc)

I tend to dive down rabbit holes a lot, and given the cost of context switching and memory deteriorating over time, sometimes the state I build up in my mind gets lost between the chances I get to dive in. These 'linkdump' posts are an attempt to collate at least some of that state in a way that I can hopefully restore to my brain at a later point.

Biohacked Box #6 (Spring, March 2018)

Time for another Bulletproof Biohacked.com quarterly box.

Biohacked Box #5 (Winter, December 2017)

Time for another Bulletproof Biohacked.com quarterly box.

Atlassian Confluence: Cross-Site Scripting (XSS) (CVE-2017-16856)

Earlier this year I spent some time delving into Atlassian Confluence to see if I could dig up any bugs that had slipped through the cracks. I wasn't really expecting to turn up much, but I was super excited and surprised when I managed to find an issue within the RSS feed plugin leading to Cross-Site Scripting (XSS) (Twitter: 1, 2; LinkedIn: 1, 2; BugCrowd: 1, 2).

Presenting all the things! (BSides Wellington, CSides Canberra, SecTalks Canberra)

Recently I had the opportunity to present at a few local security meetups, and one international security conference.

Squiz Matrix: Multiple vulnerabilities

Earlier this year I had an opportunity to spend some time looking at Squiz Matrix, a Content Management System (CMS) used across a number of sectors including higher eduction, media and publishing, goverment, finance, health, and utilities. With a huge number of features, a massive PHP codebase, and a numbr of high profile sectors as clients, I set out to see if I could find any interesting little…