CVE-2024-22513
In djangorestframework-simplejwt, a user whose account had been disabled could keep using a still-valid token to reach protected resources, because the library didn't check whether the user was still active. Read the write-up.
Security clearance dossier
No. CVE-2024-22513
I secure software supply chains, build zero trust access and write the tools security teams use every day. I lead OWASP OFFAT, and I've found account takeover bugs in government and startup APIs.
I break things for a living so they don't break in production. At BrowserStack I work on zero trust access, supply chain security and the internal tools our security team runs every day. I also lead OWASP OFFAT, an open source tool that turns an OpenAPI spec into security tests and runs them against your API.
Most of what I know came from building offensive tools in the open, hunting account takeover bugs in the APIs of government bodies, companies and startups, and then automating each finding so the same class of bug can't come back.
I studied Electronics and Telecommunication, which is why I still reach for C, assembly and an Arduino when a problem gets interesting.
Live from GitHub, sorted by stars.
Automatically tests your API for common vulnerabilities, using tests generated from an OpenAPI spec.
A Python hacking library: network scanner, ARP and DNS spoofers, packet sniffer, credential harvesters and more.
Set up an SSH server on Android with Termux.
In djangorestframework-simplejwt, a user whose account had been disabled could keep using a still-valid token to reach protected resources, because the library didn't check whether the user was still active. Read the write-up.
I'm always happy to talk about API security, supply chain attacks, security tooling or a project you'd like to collaborate on. The best way to reach me is a message on LinkedIn.
When I'm not staring at a terminal, I'm producing music and playing whichever instrument is closest. I write long-form notes on my blog.