~ryan

~ryan

<3

© 2023

Dark Mode

  • posts

  • HTML Over the Wire

    Jul 30, 2023
    • bugbounty

    A new web app architecture pattern is being adopted by many popular frameworks. Let’s talk about risk!

  • Opinions are like Bugs - Every Spec has one.

    Jul 24, 2023
    • bugbounty

    When two specifications have differing opinions on how something should be parsed: here be dragons.

  • Bypassing Safe-Redirect in Rails 7.0

    Mar 3, 2023
    • bugbounty

    Yet another parsing differential bug

  • Cracking a Christmas Story

    Dec 25, 2019
    • puzzles

    There’s a scene in the classic Christmas movie “A Christmas Story” where nine-year-old Ralphie uses a secret decoder pin to decode a secret message from his favorite radio program Little Orphan Annie.

  • A Novel Approach to Subdomain Takeover

    Dec 6, 2019
    • bugbounty

    *Subdomain takeover and DNS hijacking have been covered at length by Franz Rosen, Patrik Hudak, and plenty of other people. Rather than rehashing those traditional techniques, this post will explore a novel approach to finding dangling CNAME records. *

© 2023

Dark Mode