Profile avatar
digi.ninja
Hacker, coder, climber, runner, triathlete. Always learning. Co-flounder of SteelCon
351 posts 1,556 followers 41 following
Prolific Poster
Conversation Starter

Anyone I know going to the UK Games Expo tomorrow?

Just been told by HSBC that Paypal don't meet Visa's requirements for taking payments and so I can't use my Visa card to pay for something through Paypal. Seems like rubbish to me, but they say it isn't the bank's side that is declining the payment.

I've just recorded an episode of the Alice and Bob podcast, that was a lot of fun. It will hopefully be out just before @steelcon

It's interesting to see how many people ask me for help with DVWA without giving information then don't come back when asked to do a bit of work to answer some basic questions. Its whole point is to be a learning platform, so put in some work and do some learning.

143 days into the year and I've just ticked over 1000km of running.

If I can get my reports finished before 10 I can go watch the new Mission Impossible film. I've never written findings so fast!

@joswr1ght.bsky.social Happy birthday. Hope you get plenty of fun things to hack today.

Just had to cancel someone's workshop orders so a couple of spaces have just opened up. Grab them if you want them, but only if you have a main event ticket and they don't overlap! ti.to/steelcon/2025

I would highly recommend @coffeefueled.org's "Do you want to build a think tank"

Just two sets of workshop tickets left, "Do you wanna build a think tank?" with ‪@coffeefueled.org and "Intro to .NET Exploitation" with @sinsinology.bsky.social Get them before they are gone: ti.to/steelcon/2025

@patrick.risky.biz the Avanti vuln that they claim is in open source code, don't they have to publish a list of imports and give credit somewhere? If so, is anyone watching those repos for security related PRs?

Anyone got any tips on testing server-side Blazor apps? No WASM file to decode before it is suggested, it is all server side.

An EU equivalent of the CVE database. euvd.enisa.europa.eu it will be interesting to see how long it lasts and how it competes

We have just one place left on the Intro to Windows kernel workshop, two on Burp extensions and threat modelling and not that many on the others. If you are around on Friday 11th, come along and get hands on with our amazing teachers. ti.to/steelcon/2025

Pippa has now joined Sam in the Junior Parkrun 250 runs club. Thanks Graves Juniors for a great 8 years.

Another reminder, when getting workshop tickets, you must have a main event ticket. Also, you can only be in one place at a time, so do not take tickets for overlapping sessions. Sales open at 12. ti.to/steelcon/2025

I'm thrilled to announce my talk "Cookie Chaos: Exploiting Parser Discrepancies" at @steelcon.info ! Catch it live in Sheffield, or later on YoutTube. Check out the full abstract here: portswigger.net/research/tal...

Cookie parsing is an absolute disaster - tune in to this talk to find out how to exploit it!

Workshop tickets locked and loaded, all ready for sale at 12pm tomorrow. Just 20 tickets for each session except the lock sport which is only 12, so grab them quick, they will sell out. ti.to/steelcon/2025 But please remember, you must have a main con ticket to come, and don't do any overlapping.

To celebrate it being a Wednesday morning, we've just launched our shiny new website: www.steelcon.info Thanks to the amazing @synstalker.bsky.social for all the design work and getting stuff shifted over. There are still a few bits that need tidying up, but it's good for now.

What's that I hear you say, you want to know about the workshops? Well, why not have a look at our shiny new website for all the details: www.steelcon.info/2025-steelco... Tickets will go on sale here tomorrow at 12: ti.to/steelcon/2025

I want to ban "yes", "maybe later" as the only options. No is my answer, not now, not later, not ever, no.

Ha! Nice DVWA meme in latest WatchTowr blog post cc @digi.ninja

Just five minutes till the most important ticket drop of the day, the kids tickets. ti.to/steelcon/2025 This one will sell out quickly so get in there as soon as it opens.

And my inbox is going ping ping again, it must be 12pm.

The badges have just arrived and the look good! 10 minutes till the next ticket drop if you want to guarantee you get one. ti.to/steelcon/2025

Out of 576,000 AI-generated code samples studied, 440,000 contained "hallucinated" dependencies—packages that don't actually exist. This creates a perfect opportunity for supply chain attacks. - Register these non-existent packages - Plant malicious code - Wait (and profit) go.j4vv4d.com/xEkzJM

If you want to see my latest talk/Story Time With Finux, & trust me, this 1 is a wild ride, then I suggest you get on the ticket drop and come see us in Sheffield. If you've followed my talks over the years, you know i don't have many recorded & i'd guess this is probably your only chance to see it

Trying to work out my my PC has just started binging like mad. It is gmail alerts for all the @steelcon.info ticket sales.

Today is our last big ticket drop. 9am, 12pm, 7pm main event tickets 1pm kids track tickets ti.to/steelcon/2025 You can see our speaker list here: www.steelcon.info/the-event/ta... Workshops tickets will be next week once the dust settles.

Google has added a whole load of AI guff to their accounts, stuff I've no intention of using, and are now using it to justify price rises

This just arrived with a big box.

Good friend of the con @finux.bsky.social needs somewhere to stay while in Sheffield for the event, does anyone have a spare hotel bed or room he could use for a couple of days while over here?

SteelCon is superb and you should go:

We have a list of all our speakers and workshop who have confirmed so far up on our site: www.steelcon.info/the-event/ta... www.steelcon.info/the-event/wo... If any of these excite you (they excite us) then the last ticket drop will be this Friday, May 2nd. ti.to/steelcon/2025

@patrick.risky.biz You had/have a sponsor who does website bot detection and blocking, who were they? I've got a client who really needs that type of service now!

On a come down after my last big race so cheered myself up my entering a few more. Two Roses Ultra 100k in June, Manchester Half in October and Manchester marathon next April. And now to go for a run to start training.