Skip to content
war + code
AboutSearch

The 'malignant genie' problem

2024-11-20 — 3 min read
#appsec 

A thought exercise, good for security engineers, threat modeling, introverted get-togethers...

Read more →

No you can't 'WAF patch' curl vulns CVE-2023-38545 and CVE-2023-38546

2023-10-11 — 4 min read
#curl  #cves  #perimeter security  #waf 

Conditions for today's curl CVE releases (CVE-2023-38545, CVE-2023-38546) and why you've got to say 'NO' to WAF patching them. For the good of all mankind.

Read more →

What can you do with Web3 anyway?

2022-07-24 — 5 min read
#arweave  #blockchain  #crypto  #emerging 

Some 'Web 3.0' developments that may be of interest to hackers.

Read more →

Filecoin and Arweave vs. copyright enforcers

2022-07-10 — 6 min read
#arweave  #blockchain  #copyright  #crypto  #drm  #emerging 

Contemporary decentralized file storage seems like an unrealized threat to copyright enforcers and brand-protectors.

Read more →

2021 OWASP Global AppSec talk on open source for anti-bot

2021-11-11 — 2 min read
#appsec  #botting  #talks 

Information on my 2021 OWASP Global AppSec US talk 'How to Thwart Malicious Automation and Kick Bot Butt for $0'.

Read more →
Older posts →
war + code
© 2026 warandcode.comRSS