Robert Gilbert (amroot) Profile picture
Father & husband #AppSec @AWScloud #OWASP & #CVE contributor. Accidental cert collector: #CISSP, #GWAPT, #GPYC, #OSWE, #CEH, #MCP, A+ Opinions are my own.
Aug 25, 2020 18 tweets 8 min read
4.5 months ago I told a "HIPAA compliant" telemedicine company they were vulnerable to cross-site scripting. if a user is authenticated; + session hijacking. telemed is interesting in COVID times.
Can you guess if they fixed either vuln yet?

#appsec #infosec #HIPAA #nobodycares So, it's been more than six months now. This is why CVEs and reporting directly to vendors is pointless and soul crushing. @Bugcrowd is pointless too if you're not interested in money for reports. Reference this current thread and
Oct 13, 2018 14 tweets 3 min read
I don't get paid to hack, I get paid to write reports. 👍#Pentesting

#infosec #appsec @MrErickMars I’m sure there’s more qualified people with fresh ideas that can give you a better answer. Additionally, there’s no short answer. There's the canned response “you just have to work hard!”. Instead I’m going to ramble off a few things to hopefully help someone along.