You are here |
vin01.github.io | ||
| | | |
hjr265.me
|
|
| | | | On April 3, 2023, I received an email from a "security researcher". The "security researcher" and his/her "expert team" scanned one of my sites and found a "critical urgent" vulnerability. The web application in question links to a subdomain under the same domain from the footer without the rel="noreferer noopener" attribute. Some will say that a subdomain is not an internal link and it must have that attribute. Fine. But this email led to a very fun and eye-opening exchange of 36 emails. | |
| | | |
www.jenkins.io
|
|
| | | | The Jenkins project's response to a critical security vulnerability in the "Spring" framework. | |
| | | |
aboulton.blogspot.com
|
|
| | | | From time to time, I get an opportunity to do some independent research. Something that has always particularly peaked my interest is Lotus ... | |
| | | |
kersed.net
|
|
| |