3 cookie related CVEs!!
Back in June my team and I found a vulnerability in the way multiple languages parse cookies which could allow a potential attacker to bypass cookie prefixes. ( CVE-2020-8184 , CVE-2020-7070 , CVE-2020-1045 )
A technical blog
Back in June my team and I found a vulnerability in the way multiple languages parse cookies which could allow a potential attacker to bypass cookie prefixes. ( CVE-2020-8184 , CVE-2020-7070 , CVE-2020-1045 )
Back in August I found a vulnerability in Slack which allowed me to keylog slack input via custom themes.
What an amazing summer of festivals! I made some awesome new friendships as well as reunited with some old friends all for one reason: music!
This past weekend a co-worker bought his son a Minecraft mod and unfortunately, even after payment, it still refused to allow them to use it! This was nothing a bit of simple reverse engineering couldn’t solve.
Last month I watched music bring the french alps alive for the first ever edition of Tomorrowland Winter.
Four years ago I could only dream of working at a company like GitHub and now I’m here.
This past weekend I watched music unite thousands of people from around the world for a weekend of happiness at Tomorrowland.
About a month ago I went NothSec, Canada’s premier cyber security conference & CTF. I was lucky enough to go with the SomRandomName team.
Its hard to believe I’m finishing up my undergrad this month! The past four years of my life flew by. Looking back on this past semester I was able to accomplish quite a bit!
What a year 2017 has been! I’ve been doing so many awesome adventures I’ve had hardly any time to maintain my blog.
A little over a month ago I landed in sunny San Francisco for a summer of adventure as the product security intern at GitHub!
Over the last month I had the chance to roadtrip out to the west coast of Canada with my friend Jurre!
A few weeks ago I got to participate in the 2017 edition of CSGames on the uOttawa Series A team. We managed to place second overall!
It has been a while since I’ve blogged, so I thought I would use this post to recap my 2016 and outline my goals for 2017.
Last month Rob and I found a vulnerability in the Pebble app ecosystem which enabled us to spoof a Pebble appstore application. This was assigned CVE-2016-10702.
This past weekend I had the opportunity to participate in Hack Western 3 and while I didn’t win I still learned alot!
Last thursday and friday I had the chance to participate in my first professional level CTF at BSides Ottawa. Hopeless.carleton, the team I was on, came second overall with a remarkable 3600 points!
About 3 months ago a component on my motherboard broke, so off I went to contact ASUS for an RMA only to find something completely unexpected…
Come check out my current build & setup!
For the last month or so my aluminum body keyboard has been shocking me for intervals of about 10 seconds. I’ve finally figured out why…