🦞🌯 Lobster Roll

Thread

Moonpig vulnerability (ifc0nfig.com)
What is really bad about this story is that the company had 17 months to fix the issue and did nothing about it.

Stories related to "Moonpig vulnerability" across the full archive.

Moonpig vulnerability (ifc0nfig.com)
What is really bad about this story is that the company had 17 months to fix the issue and did nothing about it.
Zenbleed - Zen 2 hardware vulnerability
The rise of a new Java vulnerability - CVE-2012-1723 (blogs.technet.com)
Chromium Vulnerability Rewards Program: larger rewards! (blog.chromium.org)
Twitter API Changes Set Maximum User Cap for 3rd Parties (thenextweb.com)
Ripping OAuth tokens (or other secrets) out of Twitter clients (timetobleed.com)
Google Kills Weather API (thenextweb.com)
OAuth2: One access_token To Rule Them All (homakov.blogspot.com)
Lambda Labs Releases Face Recognition API βeta (api.lambdal.com)
Current status: API v1.1 | Twitter Developers (dev.twitter.com)
Amazon Maps API (amazonappstoredev.com)
Restful API framework for Flask / MongoEngine (github.com)
OAuth 2.0 finalized (dickhardt.org)
Instagram 3.1.2 For iOS, Session Riding Vulnerability (PoC) (reventlov.com)
Notes on the USE paradigm for API design (hjr3.tumblr.com)
SQL Injection Vulnerability in all versions of Ruby on Rails/ActiveRecord (CVE-2012-5664) (groups.google.com)
Analysis of Rails XML Parameter Parsing Vulnerability (insinuator.net)
Optimizing the Netflix API (techblog.netflix.com)
A Rest DNS API allowing to perform DNS queries over HTTP, outputting JSON (statdns.com)
CRIME: A vulnerability in the SPDY protocol (imperialviolet.org)
This vulnerability no longer exists, but it's a good description of a non-obvious bug.
A Guide to Designing API Client Libraries (kev.inburke.com)
OAuth1, OAuth2, OAuth...? (homakov.blogspot.com)
Ask Lobsters: What is the general consensus on the best API authentication these days?
I liked Flickr's now-deprecated [hash-the-params](http://www.flickr.com/services/api/auth.howto.web.html) authentication because it was simple (though [flawed](http://vnhacker.blogspot.com/2009/09/flickrs-api-signature-forgery.html), it is fixable). Now it seems like most sites are using OAuth 1....
Hypermedia API for Industrial Applications (projexsys.com)
Show Lobsters: Yardbase, free and open API of local, community-based data (yardbase.org)
Still very alpha... developed during a Startup Weekend event.
Google Glass' The Mirror API - How It Works (i-programmer.info)
Indicating Problems in HTTP APIs (mnot.net)
Show Lobsters: Scalabitz, content discovery through Bit.ly's API (branchandbound.net)
Unauthenticated Remote Code Execution Vulnerability in Puppet - CVE-2013-3567 (puppetlabs.com)
Debugging the Stripe API using Runscope (blog.epanastasi.com)