PinnedInbored.engineerbyLuke Young·May 4Building GitHub Canarytokens: A rant about Audit Log gapsInsights from my (mostly) successful attempt to create API tokens and SSH keys for github.com that trigger an alert (including source…
PinnedInbetter appsecbyLuke Young·Jun 10, 2021Building a WebAuthn Click Farm — Are CAPTCHAs Obsolete?How I built a click farm to “bypass” Cloudflare’s CAPTCHA killer with some cheap USB security keys, an Arduino, and a bit of python.A response icon3A response icon3
Inbored.engineerbyLuke Young·Dec 1, 2022XSS on account.leagueoflegends.com via easyXDM [2016]This post contains a chain of vulnerabilities I responsibly disclosed to Riot Games in November of 2016. I’m publicly disclosing it now as…A response icon1A response icon1
Inbored.engineerbyLuke Young·Aug 6, 2016DEF CON 24: Slides and ExploitHere’s the slides and exploits from the DEF CON 24 talk in Las Vegas, NV. Video to follow in a few weeks.
Inbored.engineerbyLuke Young·Jul 22, 2016git init && git commit -a -m “Initial Commit”I decided to relaunch my blog with my recent domain name change. It’s unlikely I will migrate the old content, but look forward to my…A response icon1A response icon1