Father & husband
#AppSec @AWScloud
#OWASP & #CVE contributor.
Accidental cert collector:
#CISSP, #GWAPT, #GPYC, #OSWE, #CEH, #MCP, A+
Opinions are my own.
Aug 25, 2020 • 18 tweets • 8 min read
4.5 months ago I told a "HIPAA compliant" telemedicine company they were vulnerable to cross-site scripting. if a user is authenticated; + session hijacking. telemed is interesting in COVID times.
Can you guess if they fixed either vuln yet?
#appsec#infosec#HIPAA#nobodycares
So, it's been more than six months now. This is why CVEs and reporting directly to vendors is pointless and soul crushing. @Bugcrowd is pointless too if you're not interested in money for reports. Reference this current thread and
I don't get paid to hack, I get paid to write reports. 👍#Pentesting
#infosec#appsec
@MrErickMars I’m sure there’s more qualified people with fresh ideas that can give you a better answer. Additionally, there’s no short answer. There's the canned response “you just have to work hard!”. Instead I’m going to ramble off a few things to hopefully help someone along.