| 
	     You are here  | 
        vin01.github.io | ||
| | | | | 
            
              www.jenkins.io
             | 
        |
| | | | | The Jenkins project's response to a critical security vulnerability in the "Spring" framework. | |
| | | | | 
            
              aboulton.blogspot.com
             | 
        |
| | | | | From time to time, I get an opportunity to do some independent research. Something that has always particularly peaked my interest is Lotus ... | |
| | | | | 
            
              hjr265.me
             | 
        |
| | | | | On April 3, 2023, I received an email from a "security researcher". The "security researcher" and his/her "expert team" scanned one of my sites and found a "critical urgent" vulnerability. The web application in question links to a subdomain under the same domain from the footer without the rel="noreferer noopener" attribute. Some will say that a subdomain is not an internal link and it must have that attribute. Fine. But this email led to a very fun and eye-opening exchange of 36 emails. | |
| | | | | 
            
              itwont.work
             | 
        |
| | | in which I complain about blogging. (imported post) | ||