Spelunking in Comments and Documentation for Security Footguns

Join us as we explore seemingly safe but deceptively tricky ground in Elixir, Python, and the Golang standard library. We cover officially documented, or at least previously discussed, code functionality that could unexpectedly introduce vulnerabilities. Well-documented behavior is not always what it appears!

Hunting For Mass Assignment Vulnerabilities Using GitHub CodeSearch and grep.app

Hacked freeCodeCamp Certification

This post discusses the process of searching top GitHub projects for mass assignment vulnerabilities. This led to a fun finding in the #1 most starred GitHub project, freeCodeCamp, where I was able to acquire every coding certification – supposedly representing over 6000 hours of study – in a single request. Searching GitHub For Vulnerabilities With … Read more