Search posts, tags, users, and pages
Paul MK
I write the vulnerable code, exploit it, then ship the patch — so your team can see all three. Software engineer first, AppSec by consequence.
I have a line I use a lot: a finding is a snapshot, a rule is a ratchet. Find a bug once and you've closed one instance. Write the rule and you've closed the class, including in code nobody will ever
No responses yet.