<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>vulns on Security, Tech, And Ramblings</title>
    <link>/series/vulns/</link>
    <description>Recent content in vulns on Security, Tech, And Ramblings</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <copyright>Copyright © {year} Sean Marpo. All Rights Reserved.</copyright>
    <lastBuildDate>Wed, 15 Jun 2022 11:20:46 -0700</lastBuildDate><atom:link href="/series/vulns/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>XSS, Swagger UI, and Java - A Story in Three Parts</title>
      <link>/posts/2022/2022-06-15-springfox-xss-via-outdated-swagger-ui/</link>
      <pubDate>Wed, 15 Jun 2022 11:20:46 -0700</pubDate>
      
      <guid>/posts/2022/2022-06-15-springfox-xss-via-outdated-swagger-ui/</guid>
      <description>I got my weekly TL;DR Sec newsletter  on Thursday morning. I regularly browse the headlines for fun things to check out whenever I might have some actual downtime. I noticed a post about XSS in Swagger UI at: Hacking Swagger-UI - from XSS to account takeovers 
I did the usual perusal, noted down the concerns, and popped right on over to Sourcegraph to determine the future of my Thursday.</description>
    </item>
    
    <item>
      <title>Path Traversal and SSRF</title>
      <link>/posts/path-traversal-and-ssrf/</link>
      <pubDate>Sat, 12 Feb 2022 12:09:08 -0800</pubDate>
      
      <guid>/posts/path-traversal-and-ssrf/</guid>
      <description>I was recently working on a security review, and I came across an anti-pattern I&amp;rsquo;ve seen time and time again. Sure, it might be obvious, but this was a relatively tenured developer who suggested this particular solution. It&amp;rsquo;s seemingly pervasive enough that it warrants digging into. So, with that in mind, let&amp;rsquo;s chat about path traversal and SSRF.
The Context I was performing an app/code review of a new &amp;ldquo;thing&amp;rdquo; to keep this vague enough.</description>
    </item>
    
  </channel>
</rss>
