Profile avatar
insider.phd
Dr, apparently. Lecturer & Hacker exbugcrowd. #BugBounty hunter & #infosec YouTuber. Research: API sec, #MLsec, #offsec data+hacking. she/her.
315 posts 4,875 followers 1,306 following
Regular Contributor
Active Commenter

Just dropped another completely free API security lesson on JustHacking, this time we’re looking at WebSocket APIs. In this 30min lesson you’ll learn what a WebSocket is and the types of apps that use them, how to communicate to WebSockets and some of the security issues in them!

Are you interested in API security, no fluff, no marketing just technical API experts sharing what they know? The eyJ webinar series is just that, I am joined by my colleagues for an hour of deep technical analysis, breakdowns of breaches and the latest in API security tooling 1/2

Just completed my second exciting project - a 3D printed knitting machine for socks! Check out it out! I do need to do some manual processing to finish the socks off since I am just making a big tube, but this is going to really speed up vanilla socks!

I can tell I’m improving at CAD because this only took 2 failures not 20

How are people vibe coding entire multiplayer games and I have to beg chatGPT to help me put wires in the right place 😭😭😭

Are you interested in API security, no fluff, no marketing just technical API experts sharing what they know? The eyJ webinar series is just that, I am joined by my colleagues for an hour of deep technical analysis, breakdowns of breaches and the latest in API security tooling 1/2

So you're interested in hardware hacking and tinkering? Me too let me share my top resources for getting started with solidering, CAD, electrical engineering etc... DISCLAIMER I am still a noob but I wanted to share anyway 1/12

New toy day 👀👀👀👀

Can’t believe it’s taken me this long to pick up ESP32 they are fantastic little pieces of kit for building on top of APIs I just bought 4 more 😂

If you don’t own a copy of World of Warcraft Programming, I don’t want to hear your coding opinions.

Do you have the same 2.13 inch eink displays as me? Good news I CAD'd some housing for it which I have put on @BambulabGlobal's Makerworld. The design includes 2 10x2mm magnets so you can attach the label to any mount.

I guess I’ll need a MMR booster before I go to the US but if I have autism will getting a MMR booster give me double autism? Do they cancel each other out so I am cured of autism? Or will its effects be a moot point because I already have autism? Lots to think about

The more I get into hardware tinkering the more I’m learning there is nothing better than an Ali Express delivery 😂

So what does make APIs special and different? #apisecurity #apihacking #apis #pentesting 1) Interconnectedness, even if you're sure you don't have APIs, I bet your suppliers do 2) Large attack surfaces that are poorly documented, they balloon into hundreds of endpoints quickly

The biggest mistake I see in API security will probably surprise you... Whether in offensive security or defending APIs, most teams make one fundamental mistake that leaves their APIs vulnerable, they forget that APIs are web applications. #apisecurity #apihacking #apis

IRL student submitted his first HackerOne report before we’d even covered the vulnerability he found in class 😂

Someone should go audit US shipping companies, you’re telling me it’s going to cost $50 to ship something that weighs less than a kilogram and fits into a letter? When Royal Mail can go the other direction for £7? Like do you need a little extra to pay a bribe or something?

My favourite thing about 3D printing has been creating the nichest solution to problems no one else has

Looks like Amazon is cracking down on people removing the DRM from their Kindle library so they can read their books on another apps/platforms