<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security, Tech, And Ramblings</title>
    <link>/</link>
    <description>Recent content on Security, Tech, And Ramblings</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <copyright>Copyright © {year} Sean Marpo. All Rights Reserved.</copyright>
    <lastBuildDate>Wed, 15 Jun 2022 11:20:46 -0700</lastBuildDate><atom:link href="/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>XSS, Swagger UI, and Java - A Story in Three Parts</title>
      <link>/posts/2022/2022-06-15-springfox-xss-via-outdated-swagger-ui/</link>
      <pubDate>Wed, 15 Jun 2022 11:20:46 -0700</pubDate>
      
      <guid>/posts/2022/2022-06-15-springfox-xss-via-outdated-swagger-ui/</guid>
      <description>I got my weekly TL;DR Sec newsletter  on Thursday morning. I regularly browse the headlines for fun things to check out whenever I might have some actual downtime. I noticed a post about XSS in Swagger UI at: Hacking Swagger-UI - from XSS to account takeovers 
I did the usual perusal, noted down the concerns, and popped right on over to Sourcegraph to determine the future of my Thursday.</description>
    </item>
    
    <item>
      <title>Keeshare: Syncing Your Keepass Database Between Devices</title>
      <link>/posts/2022/2022-03-17-keeshare-sharing-your-keepass-database-between-devices/</link>
      <pubDate>Tue, 22 Mar 2022 14:41:15 -0700</pubDate>
      
      <guid>/posts/2022/2022-03-17-keeshare-sharing-your-keepass-database-between-devices/</guid>
      <description>Password managers are all the craze nowadays. The general advice seems to be something along the lines of: &amp;ldquo;use a password manager, set a unique password for every site, and be less stressed about remembering a million things&amp;rdquo;. It&amp;rsquo;s safe to say that more and more people are being pushed to use password managers. And by all means, you absolutely should use a password manager. Today&amp;rsquo;s post outlines a particularly useful feature of KeepassXC  that makes it behave more like a cloud-based password manager.</description>
    </item>
    
    <item>
      <title>Atlassian Connect: Using Cloudflare to Meet Security Requirements</title>
      <link>/posts/atlassian-connect-using-cloudflare-to-meet-security-requirements/</link>
      <pubDate>Thu, 10 Mar 2022 14:57:33 -0800</pubDate>
      
      <guid>/posts/atlassian-connect-using-cloudflare-to-meet-security-requirements/</guid>
      <description>Writing an app for the Atlassian cloud platform? Were you aware you need to meet security requirements  for your app? Does this all seem oddly specific for a random blog post? Is it truly a cliche to start a post with a collection of questions? &amp;ndash; Probably. I&amp;rsquo;ll stop now.
In today&amp;rsquo;s post, I&amp;rsquo;m going to describe how you can meet (most) of the Atlassian Security Requirements by simply fronting your Atlassian connect app  with Cloudflare.</description>
    </item>
    
    <item>
      <title>Path Traversal and SSRF</title>
      <link>/posts/path-traversal-and-ssrf/</link>
      <pubDate>Sat, 12 Feb 2022 12:09:08 -0800</pubDate>
      
      <guid>/posts/path-traversal-and-ssrf/</guid>
      <description>I was recently working on a security review, and I came across an anti-pattern I&amp;rsquo;ve seen time and time again. Sure, it might be obvious, but this was a relatively tenured developer who suggested this particular solution. It&amp;rsquo;s seemingly pervasive enough that it warrants digging into. So, with that in mind, let&amp;rsquo;s chat about path traversal and SSRF.
The Context I was performing an app/code review of a new &amp;ldquo;thing&amp;rdquo; to keep this vague enough.</description>
    </item>
    
    <item>
      <title>Presearch Node Utils</title>
      <link>/posts/presearch-node-utils/</link>
      <pubDate>Sun, 24 Oct 2021 19:32:38 -0700</pubDate>
      
      <guid>/posts/presearch-node-utils/</guid>
      <description>👋 Hello, hello.
I&amp;rsquo;ve recently become more and more involved with a few different crypto projects. Presearch  was one of the first few I came across that I truly liked. It&amp;rsquo;s definitely in its infancy, but I love the idea of a better search solution that tracks less of you. And hey, you get rewarded PRE tokens for searching which is equivalent to a small amount of real money. Win, win, I suppose.</description>
    </item>
    
    <item>
      <title>Hello World</title>
      <link>/posts/hello-world/</link>
      <pubDate>Tue, 05 Oct 2021 13:13:38 -0700</pubDate>
      
      <guid>/posts/hello-world/</guid>
      <description>📣 Hello, hello. 📣
Don&amp;rsquo;t mind me, just a stray first post rolling through.
Nothing was planned for this post, so now this is all we have. Sorry to disappoint.</description>
    </item>
    
    <item>
      <title>About</title>
      <link>/about/</link>
      <pubDate>Tue, 05 Oct 2021 00:00:00 +0000</pubDate>
      
      <guid>/about/</guid>
      <description>👋 Hi there, I&amp;rsquo;m Sean.
I work primarily as a Security Engineer focusing on web application security. In my spare time, I do a few things&amp;hellip;
 Spend time with my wife and doggo Play video games Break other people&amp;rsquo;s software for fun &amp;ndash; https://bugcrowd.com/arcaneanomie  Fix/repair computers and do technical support, albeit I do a lot less of this anymore &amp;ndash; https://marptech.com  Code things that are likely not production ready in any capacity &amp;ndash; https://github.</description>
    </item>
    
  </channel>
</rss>
