<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>[blog].javan.de | Security Engineering</title>
    <link>https://blog.javan.de</link>
    <description>Writing on advanced web security, proactive security engineering, AI, and secure-by-design architecture.</description>
    <language>en-GB</language>
    <lastBuildDate>Tue, 09 Jun 2026 22:49:53 GMT</lastBuildDate>
    <atom:link href="https://blog.javan.de/feed.xml" rel="self" type="application/rss+xml" />
      <item>
        <title>The Future Security Engineer: Why AI Makes Secure-by-Design More Important Than Ever</title>
        <link>https://blog.javan.de/the-future-security-engineer/</link>
        <guid isPermaLink="true">https://blog.javan.de/the-future-security-engineer/</guid>
        <pubDate>Tue, 09 Jun 2026 22:38:50 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Over the last two years, a consistent narrative has taken hold across the software industry: AI will write the code, review pull requests, perform architecture reviews, conduct threat modelling, and ultimately secure applications. Recent industry data supports that direction. In GitLab’s 2026 Global DevSecOps research, 76% of respondents believe AI-assisted coding will require more engineers rather than fewer, and 43% rank implementing… Continue reading The Future Security Engineer: Why AI Makes…</description>
      </item>
      <item>
        <title>The Reality Shift in Vulnerability Management</title>
        <link>https://blog.javan.de/reality-shift-in-vulnerability-management/</link>
        <guid isPermaLink="true">https://blog.javan.de/reality-shift-in-vulnerability-management/</guid>
        <pubDate>Wed, 13 May 2026 12:41:32 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>The Signal Behind the Noise Skepticism toward AI security announcements is reasonable. The industry has seen enough hype. But this shift is not about positioning. It is about volume, capability, and what you can measure in your own programme. We are entering a phase where vulnerability remediation becomes the dominant constraint. Whether AI is the trigger or the accelerator does… Continue reading The Reality Shift in Vulnerability Management</description>
      </item>
      <item>
        <title>Inside my Black Hat USA Trainings: Full Agenda &amp; Hands-On Labs</title>
        <link>https://blog.javan.de/inside-my-black-hat-usa-trainings-full-agenda-hands-on-labs/</link>
        <guid isPermaLink="true">https://blog.javan.de/inside-my-black-hat-usa-trainings-full-agenda-hands-on-labs/</guid>
        <pubDate>Mon, 09 Mar 2026 13:04:20 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>When designing these trainings, my goal was simple: Create the kind of courses I wish had existed earlier in my own career. Many experienced security practitioners reach a point where basic vulnerability discovery is no longer enough. The real challenge becomes designing systems that prevent entire classes of vulnerabilities from appearing in the first place. 2-Day Core Training Sat, August… Continue reading Inside my Black Hat USA Trainings: Full Agenda &amp; Hands-On Labs</description>
      </item>
      <item>
        <title>Announcing My Black Hat USA 2026 Trainings</title>
        <link>https://blog.javan.de/announcing-my-new-courses-for-black-hat-usa-2026/</link>
        <guid isPermaLink="true">https://blog.javan.de/announcing-my-new-courses-for-black-hat-usa-2026/</guid>
        <pubDate>Sat, 07 Mar 2026 00:54:39 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Last year at DEF CON 33, I ran a 4-hour workshop on browser defenses. The response afterwards was incredibly motivating. Many participants told me two things: this was the kind of training they wished had existed earlier in their careers; and the material content is so up-to-date some stuff discussed was just a few weeks old. Over the following months… Continue reading Announcing My Black Hat USA 2026 Trainings</description>
      </item>
      <item>
        <title>2025: A Year of Growth, Gratitude, and Perspective</title>
        <link>https://blog.javan.de/2025-a-year-of-growth-gratitude-and-perspective/</link>
        <guid isPermaLink="true">https://blog.javan.de/2025-a-year-of-growth-gratitude-and-perspective/</guid>
        <pubDate>Thu, 01 Jan 2026 12:49:50 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Professionally, it was a year of growth. Personally, it was one of the most intense years of my life. And none of what follows would have been possible without the support, trust, and patience of the people around me, starting at home with my wife. The biggest change came early in the year: our second child was born. Navigating work,… Continue reading 2025: A Year of Growth, Gratitude, and Perspective</description>
      </item>
      <item>
        <title>From Conference Energy to Reality: The Story of Alex, Security Culture, and Why It Resonated</title>
        <link>https://blog.javan.de/from-conference-energy-to-reality-the-story-of-alex-security-culture-and-why-it-resonated/</link>
        <guid isPermaLink="true">https://blog.javan.de/from-conference-energy-to-reality-the-story-of-alex-security-culture-and-why-it-resonated/</guid>
        <pubDate>Wed, 17 Dec 2025 09:29:45 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>You know that feeling after a good conference week. You talk to smart people doing impressive work. You find one or two talks that really hit home. You fly back motivated, notebooks full, head buzzing. For the next two or three months, your energy is back. And sometimes, weeks later, one of those ideas actually turns into a real project.… Continue reading From Conference Energy to Reality: The Story of Alex, Security Culture, and Why It Resonated</description>
      </item>
      <item>
        <title>Coming Full Circle: Teaching Ethical Hacking at Aalen University</title>
        <link>https://blog.javan.de/coming-full-circle-teaching-ethical-hacking-at-aalen-university/</link>
        <guid isPermaLink="true">https://blog.javan.de/coming-full-circle-teaching-ethical-hacking-at-aalen-university/</guid>
        <pubDate>Sun, 30 Nov 2025 09:12:06 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>I was 14 when I found my first vulnerability. It was an online game. I had no idea what responsible disclosure, bug bounty, or legal boundaries were supposed to mean. I just knew something was broken, and someone should probably know about it. So I did what made sense at the time: I joined the vendor’s IRC channel and reported… Continue reading Coming Full Circle: Teaching Ethical Hacking at Aalen University</description>
      </item>
      <item>
        <title>Recap of Hacker Summer Camp 2025</title>
        <link>https://blog.javan.de/recap-of-hacker-summer-camp-2025/</link>
        <guid isPermaLink="true">https://blog.javan.de/recap-of-hacker-summer-camp-2025/</guid>
        <pubDate>Sat, 23 Aug 2025 14:17:28 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Two weeks after DEFCON, I’m still buzzing from an unforgettable week in Vegas — one that kicked off at the Tuscany for my very first BSidesLV. And wow, what an experience. In this recap, I’ll take you through: BSidesLV has roots going back to 2009, when a bunch of talks rejected from Black Hat and DEFCON needed a home. Instead… Continue reading Recap of Hacker Summer Camp 2025</description>
      </item>
      <item>
        <title>My Password Vault Was Hacked, but 2FA Saved My Ass! – Ongoing Bitwarden Incident</title>
        <link>https://blog.javan.de/my-password-vault-was-hacked-but-2fa-saved-my-ass-ongoing-bitwarden-incident/</link>
        <guid isPermaLink="true">https://blog.javan.de/my-password-vault-was-hacked-but-2fa-saved-my-ass-ongoing-bitwarden-incident/</guid>
        <pubDate>Thu, 21 Aug 2025 07:38:58 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Right now, as I’m writing this, Bitwarden is still under a mass attack. Many users (including me) are stuck in a weird deadlock state where logging into the vault is close to impossible. This made me stop and think: Luckily, I did. I found my 2FA recovery code (yep, printed on paper). But then another thought hit me: What if… Continue reading My Password Vault Was Hacked, but 2FA Saved My Ass! – Ongoing Bitwarden Incident</description>
      </item>
      <item>
        <title>From Firefighting to Prevention: Taking Browser-Native Defences to Hacker Summer Camp</title>
        <link>https://blog.javan.de/from-firefighting-to-prevention-taking-browser-native-defences-to-hacker-summer-camp/</link>
        <guid isPermaLink="true">https://blog.javan.de/from-firefighting-to-prevention-taking-browser-native-defences-to-hacker-summer-camp/</guid>
        <pubDate>Thu, 10 Jul 2025 14:35:00 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Over the past few years, I’ve spent more time than I’d like to admit in the weeds — reviewing reports, fixing recurring bugs, writing guidance that never scales. Like many in AppSec, I’ve asked myself: Why are we still fixing the same bug classes in 2025 that we were in 2015? This frustration was the starting point for something more… Continue reading From Firefighting to Prevention: Taking Browser-Native Defences to Hacker Summer Camp</description>
      </item>
      <item>
        <title>AI Tools in the Classroom: What I Learned from 12 Student Projects on Secure Coding</title>
        <link>https://blog.javan.de/ai-tools-in-the-classroom-what-i-learned-from-12-student-projects-on-secure-coding/</link>
        <guid isPermaLink="true">https://blog.javan.de/ai-tools-in-the-classroom-what-i-learned-from-12-student-projects-on-secure-coding/</guid>
        <pubDate>Wed, 09 Jul 2025 09:39:13 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>This week, the students in my Security Hackathon class at DHBW presented their final projects. The format was simple: each group selected one of the OWASP Top 10 Proactive Controls and explored it in depth. The results were more than I had hoped for. While it wasn’t required to build a working project, many groups chose to go beyond expectations,… Continue reading AI Tools in the Classroom: What I Learned from 12 Student Projects on Secure Coding</description>
      </item>
      <item>
        <title>How to send HTTP-Requests from Cloudflare’s IP Range</title>
        <link>https://blog.javan.de/how-to-send-http-requests-from-cloudflares-ip-range/</link>
        <guid isPermaLink="true">https://blog.javan.de/how-to-send-http-requests-from-cloudflares-ip-range/</guid>
        <pubDate>Thu, 03 Jul 2025 12:06:19 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>This is Part 3 of a series of multiple Cloudflare-related blog posts. Now that we have Cursor and vibe coding simple ideas into a working MVP is fun and gives you fast results, I gave it a try, one of the projects I created is: https://cf-relay.javan.de Advanced HTTP proxy using Cloudflare’s IP range to bypass IP-based restrictions, rate limiting, and… Continue reading How to send HTTP-Requests from Cloudflare’s IP Range</description>
      </item>
      <item>
        <title>How to prevent Cloudflare Proxy Bypasses</title>
        <link>https://blog.javan.de/how-to-prevent-cloudflare-proxy-bypasses/</link>
        <guid isPermaLink="true">https://blog.javan.de/how-to-prevent-cloudflare-proxy-bypasses/</guid>
        <pubDate>Thu, 03 Jul 2025 11:48:16 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>First two search results for “blocking origin access directly” on Google showed me two misleading Cloudflare community threads, with wrong security assumption, which is why I decided to write this guide. [1] [2] The best and recommended solution is using Authenticated Origin Pulls with custom certs per domain, but as this is not trivial to set up I decided write about… Continue reading How to prevent Cloudflare Proxy Bypasses</description>
      </item>
      <item>
        <title>Hacking the LEDA LUC2 Fireplace: Reading CAN Bus Data with ESP32 and ESPHome</title>
        <link>https://blog.javan.de/hacking-the-fireplace/</link>
        <guid isPermaLink="true">https://blog.javan.de/hacking-the-fireplace/</guid>
        <pubDate>Thu, 03 Jul 2025 11:04:45 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Ever since I installed a LEDA LUC2 fireplace, I wanted deeper insights into how it operates — particularly pressure difference, exhaust temperature, and ventilation state. Unfortunately, the vendor doesn’t provide any integration options, and the only external interface is a mysterious RJ12 port on the controller. So I decided to reverse engineer it myself. In this post, I’ll walk you… Continue reading Hacking the LEDA LUC2 Fireplace: Reading CAN Bus Data with ESP32 and ESPHome</description>
      </item>
      <item>
        <title>We’ve Normalised AI. But Not Secure Code.</title>
        <link>https://blog.javan.de/weve-normalised-ai-but-not-secure-code/</link>
        <guid isPermaLink="true">https://blog.javan.de/weve-normalised-ai-but-not-secure-code/</guid>
        <pubDate>Wed, 02 Jul 2025 10:25:00 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Reflections from BSides Canberra 2023 to the Securing Sage Summit 2025 Last month at the Securing Sage Summit, I watched Sonya M. from Snyk give a slick, fast-paced live demo using GitHub Copilot. It was exactly the kind of session that draws a crowd — showing how quickly AI can help generate code from natural language prompts. But then it… Continue reading We’ve Normalised AI. But Not Secure Code.</description>
      </item>
      <item>
        <title>Is it just me – or is 2025 the year of scale?</title>
        <link>https://blog.javan.de/is-it-just-me-or-is-2025-the-year-of-scale/</link>
        <guid isPermaLink="true">https://blog.javan.de/is-it-just-me-or-is-2025-the-year-of-scale/</guid>
        <pubDate>Wed, 18 Jun 2025 19:19:22 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Maybe it’s just the talks I’ve attended and articles I read. Maybe it’s just my rabbit hole that I went into. Or maybe… we’re all collectively realising the same thing. I hit a wall. At the end of 2024, I went all-in on automation. I built MVPs, tested capabilities, and made it my mission to influence others to do the… Continue reading Is it just me – or is 2025 the year of scale?</description>
      </item>
      <item>
        <title>From mysql_real_escape_string() to AI Firewalls: Are We Repeating History with Prompt Injection?</title>
        <link>https://blog.javan.de/prompt-inj-ai-firewalls-waf/</link>
        <guid isPermaLink="true">https://blog.javan.de/prompt-inj-ai-firewalls-waf/</guid>
        <pubDate>Fri, 06 Jun 2025 07:17:07 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>In the early days of web development, PHP developers often relied on functions like mysql_escape_string() to sanitize user inputs. However, this approach was fraught with pitfalls. Misuse, incorrect character encoding handling, and a lack of awareness led to numerous vulnerabilities. To address these issues, mysql_real_escape_string() was introduced, which considered the current character set of the database connection, offering a more… Continue reading From mysql_real_escape_string() to AI…</description>
      </item>
      <item>
        <title>Scaling AppSec in High-Velocity Engineering: My Take</title>
        <link>https://blog.javan.de/scaling-appsec-in-high-velocity-engineering-my-take/</link>
        <guid isPermaLink="true">https://blog.javan.de/scaling-appsec-in-high-velocity-engineering-my-take/</guid>
        <pubDate>Wed, 04 Jun 2025 19:44:03 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Jason Chan’s article “Security for High Velocity Engineering” hit me hard. It captures a reality many of us in Product Security face: engineering teams move fast, and unless your security program evolves beyond one-off engagements and reactive fixes, you’ll constantly be playing catch-up. The Fragile Model: When 1:1 Investment Walks Out the Door When I started out as an AppSec… Continue reading Scaling AppSec in High-Velocity Engineering: My Take</description>
      </item>
      <item>
        <title>Hacking your not-so-smart doorbell – Home Assistant and Gemini AI</title>
        <link>https://blog.javan.de/hacking-your-not-so-smart-doorbell-home-assistant-and-gemini-ai/</link>
        <guid isPermaLink="true">https://blog.javan.de/hacking-your-not-so-smart-doorbell-home-assistant-and-gemini-ai/</guid>
        <pubDate>Thu, 14 Nov 2024 13:23:45 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>At DEFCON32, my colleague Andra Lezza and I presented a talk on building and securing LLM applications – particularly chatbots – drawing from our work at Sage. One of the highlights of our talk was a practical proof of concept: a smart home setup using Home-Assistant.io, which we showcased to demonstrate safety implications and security considerations of AI-integrated applications. In… Continue reading Hacking your not-so-smart doorbell – Home Assistant and Gemini AI</description>
      </item>
      <item>
        <title>AppSec Team Topologies Explained: Structure in Matrix Organisations</title>
        <link>https://blog.javan.de/appsec-team-topologies/</link>
        <guid isPermaLink="true">https://blog.javan.de/appsec-team-topologies/</guid>
        <pubDate>Thu, 14 Nov 2024 09:53:20 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>In a world where security needs to move as fast as software delivery, how we structure our AppSec (Application Security) teams is more critical than ever. The right team topology can make the difference between a well-secured application and a bottlenecked security process. Before looking in detail into these structures, let’s break down some essential team types that shape how… Continue reading AppSec Team Topologies Explained: Structure in Matrix Organisations</description>
      </item>
      <item>
        <title>Rethinking Shift-Left: More Than Just Eliminating Vulnerabilities?</title>
        <link>https://blog.javan.de/rethinking-shift-left-more-than-just-eliminating-vulnerabilities/</link>
        <guid isPermaLink="true">https://blog.javan.de/rethinking-shift-left-more-than-just-eliminating-vulnerabilities/</guid>
        <pubDate>Wed, 06 Nov 2024 21:32:57 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Over the past few years, the concept of “shift-left” has dominated software security. The idea seems intuitive – catch vulnerabilities as early as possible in the development process, allowing teams to remediate issues long before they ever reach production. But after a recent discussions, I started thinking more critically about what shift-left actually delivers and, more importantly, where it might… Continue reading Rethinking Shift-Left: More Than Just Eliminating Vulnerabilities?</description>
      </item>
      <item>
        <title>Relying solely on IP Allowlisting with Cloudflare is WRONG</title>
        <link>https://blog.javan.de/relying-solely-on-ip-allowlisting-with-cloudflare-is-wrong/</link>
        <guid isPermaLink="true">https://blog.javan.de/relying-solely-on-ip-allowlisting-with-cloudflare-is-wrong/</guid>
        <pubDate>Tue, 01 Oct 2024 10:37:58 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>The Misconception IP allowlisting involves configuring your origin server to accept connections only from specific IP addresses – in this case, Cloudflare’s IP ranges. The logic seems sound: by allowing only trusted IPs, you reduce the risk of unauthorized access. Unfortunately, this method overlooks several attack cases that can be exploited. My Observation Over the years, I’ve noticed numerous security… Continue reading Relying solely on IP Allowlisting with Cloudflare is WRONG</description>
      </item>
      <item>
        <title>10 Practices to secure a WordPress site [Updated 2024]</title>
        <link>https://blog.javan.de/10-practices-to-secure-a-wordpress-site-updated-2024/</link>
        <guid isPermaLink="true">https://blog.javan.de/10-practices-to-secure-a-wordpress-site-updated-2024/</guid>
        <pubDate>Tue, 30 Jan 2024 14:03:23 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>WordPress is the most widely used CMS of all. But after the setting it up, most do not think further about security. Therefore, vulnerabilities in WordPress are particularly lucrative. Outdated versions, for which public vulnerabilities are known, are detected and attacked by so-called crawlers and bots. This usually happens fully automatically. Often the goal of these automated attacks is to… Continue reading 10 Practices to secure a WordPress site [Updated 2024]</description>
      </item>
      <item>
        <title>OWASP Frankfurt Chapter Meetup #63 – Recap</title>
        <link>https://blog.javan.de/owasp-frankfurt-chapter-meetup-63-recap/</link>
        <guid isPermaLink="true">https://blog.javan.de/owasp-frankfurt-chapter-meetup-63-recap/</guid>
        <pubDate>Mon, 11 Dec 2023 08:38:17 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>I had a great time last week at OWASP Frankfurt’s 63rd meetup all about #GenerativeAI and #Security! We dived into deep fake detection and ways to bypass it – truly eye-opening.We also explored the impact of AI generated code on software security with a GitHub Copilot case study. Plus, plenty of pizza and some fantastic home-brewed beer by Check24. If… Continue reading OWASP Frankfurt Chapter Meetup #63 – Recap</description>
      </item>
      <item>
        <title>Recap of SecTor Security conference</title>
        <link>https://blog.javan.de/recap-of-sector-security-conference/</link>
        <guid isPermaLink="true">https://blog.javan.de/recap-of-sector-security-conference/</guid>
        <pubDate>Wed, 15 Nov 2023 09:38:14 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>During my time in Toronto, it was not just about security of LLMs but also a lot about reunion and meeting fantastic people, one story I definitely wanted to share with you: Four years ago, in my previous role at EXXETA in Stuttgart I was mentoring Fabian, an enthusiastic working student. Since then, it’s almost as if fate keeps bringing… Continue reading Recap of SecTor Security conference</description>
      </item>
      <item>
        <title>Secure Coding Workshop at DHBW CAS University</title>
        <link>https://blog.javan.de/secure-coding-workshop-at-dhbw-cas-university/</link>
        <guid isPermaLink="true">https://blog.javan.de/secure-coding-workshop-at-dhbw-cas-university/</guid>
        <pubDate>Fri, 20 Oct 2023 08:13:00 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Just wrapped up my second session on Software Quality Engineering co-lecturing with Prof. Dr. Katja Wengler at DHBW Center for Advanced Studies in Heilbronn, Germany, and I’m once again struck by the incredible dynamism of these lectures. The level of engagement always astounds me. 👉 Day 1 was all about DevSecOps and Secure-SDLC, where we dived into secure coding practices,… Continue reading Secure Coding Workshop at DHBW CAS University</description>
      </item>
      <item>
        <title>The Dark Side of Large Language Models: Uncovering and Overcoming of Code Vulnerabilities</title>
        <link>https://blog.javan.de/the-dark-side-of-large-language-models-uncovering-and-overcoming-of-code-vulnerabilities/</link>
        <guid isPermaLink="true">https://blog.javan.de/the-dark-side-of-large-language-models-uncovering-and-overcoming-of-code-vulnerabilities/</guid>
        <pubDate>Wed, 20 Sep 2023 08:29:00 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>I had a great time speaking at ThreatCon.io Hacking Conference in beautiful Kathmandu, Nepal. During my talk we discussed the new world of LLM auto-suggested code and therefore it’s influence on secure coding. One of the key findings I demoed is, that while tools like GitHub Copilot can speed things up, they sneak in various vulnerabilities. But we also discussed… Continue reading The Dark Side of Large Language Models: Uncovering and Overcoming of Code Vulnerabilities</description>
      </item>
      <item>
        <title>The Ticking Time Bomb: When Features Turn into Unexpected Vulnerabilities</title>
        <link>https://blog.javan.de/the-ticking-time-bomb-when-features-turn-into-unexpected-vulnerabilities/</link>
        <guid isPermaLink="true">https://blog.javan.de/the-ticking-time-bomb-when-features-turn-into-unexpected-vulnerabilities/</guid>
        <pubDate>Sun, 18 Jun 2023 21:34:41 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>These vulnerabilities have a common characteristic: they are inherent features of programming languages or libraries. However, it took a considerable amount of time for them to be recognized as attack vectors and actual vulnerabilities. The existence of these vulnerabilities, previously unknown until their public disclosure, resulted in a substantial and previously unidentified attack surface for malicious actors. This discovery had… Continue reading The Ticking Time Bomb: When Features Turn…</description>
      </item>
      <item>
        <title>Unleashing the Power of GitHub Copilot: A Critical Review of Its Impact on Secure Coding</title>
        <link>https://blog.javan.de/security-concerns-with-github-copilot/</link>
        <guid isPermaLink="true">https://blog.javan.de/security-concerns-with-github-copilot/</guid>
        <pubDate>Fri, 28 Apr 2023 13:33:07 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Today I developed a python tool to automate some processes in our vulnerability management. For this task I decided to use GitHub Copilot. Mostly by using code comments (#, //) Copilot wrote the code for me, so I did not have to care much about syntax or function names, which I keep forgetting when I am not coding in Python… Continue reading Unleashing the Power of GitHub Copilot: A Critical Review of Its Impact on Secure Coding</description>
      </item>
      <item>
        <title>Privacy Engineering: The Missing Piece in Application Security and AI</title>
        <link>https://blog.javan.de/privacy-engineering-the-missing-piece-in-application-security/</link>
        <guid isPermaLink="true">https://blog.javan.de/privacy-engineering-the-missing-piece-in-application-security/</guid>
        <pubDate>Fri, 31 Mar 2023 13:01:25 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>In today’s digital age, data has become a valuable asset for organizations, and it is collected, processed, and stored at an unprecedented rate. This data contains sensitive personal information that should be kept private, and if not handled with care, can cause severe consequences for individuals and organizations. As a result, privacy engineering has emerged as a crucial discipline that… Continue reading Privacy Engineering: The Missing Piece in Application Security and AI</description>
      </item>
      <item>
        <title>Recap of OWASP AppSec conference</title>
        <link>https://blog.javan.de/re-cap-of-owasp-appsec-san-fran-conference-2022/</link>
        <guid isPermaLink="true">https://blog.javan.de/re-cap-of-owasp-appsec-san-fran-conference-2022/</guid>
        <pubDate>Sat, 17 Dec 2022 16:32:43 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Last month I attended the OWASP Global AppSec conference in San Francisco. The OWASP conference focuses exclusively on application security, and that’s what I liked about it. The people I met there have the same job description as me: we support software development teams in securing the software development lifecycle and we help to deliver secure products for our customers.… Continue reading Recap of OWASP AppSec conference</description>
      </item>
      <item>
        <title>My talk at Ekoparty security conference</title>
        <link>https://blog.javan.de/my-talk-at-ekoparty-security-conference-2022/</link>
        <guid isPermaLink="true">https://blog.javan.de/my-talk-at-ekoparty-security-conference-2022/</guid>
        <pubDate>Thu, 03 Nov 2022 19:01:00 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>I just finished my talk at Ekoparty Security Conference Maintrack. It’s day 2 of three and the conference is just a blast. It is such a great selection of presentations and I am looking forward to the new connections I’ve made! Ya está disponible la charla de @javanrasokat: &quot;A race against time&quot; ▶️ https://t.co/dI6OoMwleO#MainTrackTalk #EKO2022 pic.twitter.com/GjmTqrWda2 — Ekoparty | Hacking… Continue reading My talk at Ekoparty security conference</description>
      </item>
      <item>
        <title>Software Quality Engineering Vorlesung am DHBW CAS</title>
        <link>https://blog.javan.de/software-quality-engineering-vorlesung-am-dhbw-cas/</link>
        <guid isPermaLink="true">https://blog.javan.de/software-quality-engineering-vorlesung-am-dhbw-cas/</guid>
        <pubDate>Wed, 26 Oct 2022 14:02:06 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Mit großer Freude durfte ich vergangenen Samstag Prof. Dr. Katja Wengler bei der Mastervorlesung “Software Quality Engineering” am DHBW Center for Advanced Studies (CAS) unterstützten. Das Modul “Software Quality Engineering” beschäftigt sich mit der Analyse von Softwaresystemen und deren Optimierung. Was ist Softwarequalität, wie kann Softwarequalität bewertet oder verbessert werden? Je nach Vorkenntnissen der Teilnehmer werden Themen wie Refactoring, Clean… Continue reading Software Quality…</description>
      </item>
      <item>
        <title>My upcoming talks at #Eko2022 and #GlobalAppSecSanFran</title>
        <link>https://blog.javan.de/my-upcoming-talks-at-eko2022-and-globalappsecsanfran/</link>
        <guid isPermaLink="true">https://blog.javan.de/my-upcoming-talks-at-eko2022-and-globalappsecsanfran/</guid>
        <pubDate>Fri, 14 Oct 2022 10:50:13 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>I am already very excited that I will be giving a talk at Ekoparty security conference 2022 in Buenos Aires. #Eko2022 My talk outline: https://ekoparty.org/en_US/eko2022/main-track-talks-a-race-against-time-javan-rasokat Get your tickets here: https://ekoparty.org (free) #GlobalAppSecSanFran I am also looking forward to be part of the OWASP Global AppSec in San Francisco. My talk is on the last day of the conference. Check out… Continue reading My upcoming talks at #Eko2022 and…</description>
      </item>
      <item>
        <title>My keynote on “beekeeping and technology” at PLCnext Technology Community Summit</title>
        <link>https://blog.javan.de/my-keynote-on-beekeeping-and-technology-at-plcnext-technology-community-summit/</link>
        <guid isPermaLink="true">https://blog.javan.de/my-keynote-on-beekeeping-and-technology-at-plcnext-technology-community-summit/</guid>
        <pubDate>Sat, 01 Oct 2022 13:22:00 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Beekeeping is a fantastic hobby, which I have been doing for over 8 years. I never thought I would get to combine the technical world of sensors and automation in one talk from a beekeeper’s perspective. But it gave me great pleasure to give my keynote on beekeeping and technology at PLCnext Technology Community Summit. With my contribution to this… Continue reading My keynote on “beekeeping and technology” at PLCnext Technology Community Summit</description>
      </item>
      <item>
        <title>My talk on “Exploiting Race Condition Vulnerabilities in Web Applications” at #HITB2022SIN conference</title>
        <link>https://blog.javan.de/my-talk-on-exploiting-race-condition-vulnerabilities-in-web-applications-at-hitb2022sin-conference/</link>
        <guid isPermaLink="true">https://blog.javan.de/my-talk-on-exploiting-race-condition-vulnerabilities-in-web-applications-at-hitb2022sin-conference/</guid>
        <pubDate>Sat, 27 Aug 2022 03:34:15 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>I was very pleased to give my presentation on race condition vulnerabilities in web applications at this year’s HITB conference in Singapore. The talks with the participants, the other presentations, the organisation, everything was very well done and I was able to exchange ideas with the security community in Singapore and internationally.The people, the city and the food are amazing.Many… Continue reading My talk on “Exploiting Race Condition Vulnerabilities in Web Applications” at…</description>
      </item>
      <item>
        <title>Secure Coding Vorlesung an der Hochschule</title>
        <link>https://blog.javan.de/secure-coding-vorlesung-an-der-hochschule/</link>
        <guid isPermaLink="true">https://blog.javan.de/secure-coding-vorlesung-an-der-hochschule/</guid>
        <pubDate>Sat, 12 Jun 2021 06:09:57 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Mit dem Thema Informationssicherheit und der sicheren Softwareentwicklung kann man nicht früh genug beginnen. Deshalb ist in diesem Sommersemester 2021 an der DHBW Karlsruhe im Studiengang Wirtschaftsinformatik ein Teil des Studiums das Secure Coding. Als Ent­wick­ler von Weban­wen­dun­gen ist man heu­te mit viel­fäl­ti­gen Ge­fah­ren­po­ten­tia­len kon­fron­tiert. Die Be­dro­hun­gen zu ken­nen, Fall­stri­cke zu ver­mei­den und mit den rich­ti­gen Maß­nah­men ent­ge­gen­zu­wir­ken ge­hört…</description>
      </item>
      <item>
        <title>Scraping is not a crime</title>
        <link>https://blog.javan.de/scraping-is-not-a-crime/</link>
        <guid isPermaLink="true">https://blog.javan.de/scraping-is-not-a-crime/</guid>
        <pubDate>Tue, 20 Apr 2021 15:53:31 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>In the past two weeks some news articles about “data breaches” affecting Clubouse, LinkedIn and Facebook have been shared. I’d like to add my two cents on two points that keep coming up and clarify the following. Scraping is not a crime Scraping is not a data leakage Scraping is not a crime The first time I read about scraping… Continue reading Scraping is not a crime</description>
      </item>
      <item>
        <title>Race Condition leads to MS Account Takeover</title>
        <link>https://blog.javan.de/race-condition-leads-to-ms-account-takeover/</link>
        <guid isPermaLink="true">https://blog.javan.de/race-condition-leads-to-ms-account-takeover/</guid>
        <pubDate>Sat, 06 Mar 2021 18:51:04 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>This week security researcher Laxman Muthiyah published his bugbounty write-up “How I Might Have Hacked Any Microsoft Account“. For his finding, he was paid a bugbounty of $50,000 by Microsoft. The researcher describes a vulnerability that theoretically can be used to bypass a rate limit which results in brute-forcing a code. Theoretically, a 6-digit code (1 million necessary attempts) can… Continue reading Race Condition leads to MS Account Takeover</description>
      </item>
      <item>
        <title>Review – My path to CSSLP</title>
        <link>https://blog.javan.de/review-my-path-to-certified-secure-software-lifecycle-professional-csslp/</link>
        <guid isPermaLink="true">https://blog.javan.de/review-my-path-to-certified-secure-software-lifecycle-professional-csslp/</guid>
        <pubDate>Tue, 16 Feb 2021 13:39:27 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>This month I passed the (ISC)² Certified Secure Software Lifecycle Professional (CSSLP) exam. As I have been studying with the new version revised in late 2020 and have taken the revised exam, I would like to share my experience with you. My previous security certifications were always practically applied certifications, for example for pentesting. For me, the CSSLP was the… Continue reading Review – My path to CSSLP</description>
      </item>
      <item>
        <title>Review – My path to GXPN</title>
        <link>https://blog.javan.de/review-sec660-giac-exploit-researcher-and-advanced-penetration-tester-gxpn/</link>
        <guid isPermaLink="true">https://blog.javan.de/review-sec660-giac-exploit-researcher-and-advanced-penetration-tester-gxpn/</guid>
        <pubDate>Tue, 16 Feb 2021 10:27:36 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>After 3 months of good preparation I passed a challenging GIAC Certification for the GXPN – GIAC Exploit Researcher and Advanced Penetration Tester. The highlights for me were to learn and really understand how to defeat Windows and Linux stack protection, find common mistakes in cryptography implementation and in general to create and customize the tools to make them work… Continue reading Review – My path to GXPN</description>
      </item>
      <item>
        <title>Install Kali Linux Subsystem on Windows</title>
        <link>https://blog.javan.de/install-kali-linux-subsystem-on-windows/</link>
        <guid isPermaLink="true">https://blog.javan.de/install-kali-linux-subsystem-on-windows/</guid>
        <pubDate>Fri, 18 Dec 2020 01:19:49 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Since Kali Linux is not available as an app in the Microsoft App Store, the installation as subsystem requires to run a few commands. 1. First, the subsystem feature must be activated via PowerShell (if not already activated). Enable-WindowsOptionalFeature -Online -FeatureName Microsoft-Windows-Subsystem-Linux 2. Kali Linux is downloaded as an AppX file. We can find a file that is always up… Continue reading Install Kali Linux Subsystem on Windows</description>
      </item>
      <item>
        <title>Monitoring your WordPress Blog with Sqreen</title>
        <link>https://blog.javan.de/monitoring-your-wordpress-blog-with-sqreen/</link>
        <guid isPermaLink="true">https://blog.javan.de/monitoring-your-wordpress-blog-with-sqreen/</guid>
        <pubDate>Thu, 22 Oct 2020 08:33:34 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>This article is about installing Sqreen on the hosting and web server management system Plesk. Sqreen is a Web-Application-Firewall (WAF) and Runtime-Application-Self-Protection (RASP) solution. Sqreen is easy to install and works out of the box. The onboarding process guides you very well step-by-step through the whole setup and while setting up your first application you learn about each config. This… Continue reading Monitoring your WordPress Blog with Sqreen</description>
      </item>
      <item>
        <title>WordPress Security – 7 Schritte zur Absicherung eines WordPress Blogs</title>
        <link>https://blog.javan.de/wordpress-security-7-schritte-zur-absicherung-eines-wordpress-blogs/</link>
        <guid isPermaLink="true">https://blog.javan.de/wordpress-security-7-schritte-zur-absicherung-eines-wordpress-blogs/</guid>
        <pubDate>Fri, 28 Aug 2020 19:01:24 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>WordPress ist das weit verbreitetste CMS überhaupt. Doch nach der ersten Betriebsnahme denken die meisten nicht weiter an die Sicherheit. Deshalb sind Schwachstellen in WordPress besonders lukrativ. Veraltete Versionen, für welche öffentliche Schwachstellen bekannt sind, werden durch sogenannte Crawler und Bots erkannt und angegriffen. Dies passiert meist vollautomatisch. Oft ist das Ziel dieser automatisierten Angriffe das CMS dazu zu missbrauchen,… Continue reading WordPress Security – 7…</description>
      </item>
      <item>
        <title>Hacking Lotto 😈 – Mein Fazit nach einem Jahr LOTTO [Data Mining, Data Tampering]</title>
        <link>https://blog.javan.de/hacking-lotto-%f0%9f%98%88-mein-fazit-nach-einem-jahr-lotto-data-mining-data-tampering/</link>
        <guid isPermaLink="true">https://blog.javan.de/hacking-lotto-%f0%9f%98%88-mein-fazit-nach-einem-jahr-lotto-data-mining-data-tampering/</guid>
        <pubDate>Sun, 09 Aug 2020 18:50:21 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Nachdem ich ein Jahr mit meinen Dauerscheinen keine einzige Lottoziehung verpassen konnte, wird es nun Zeit für eine Auswertung der Daten und ein Fazit. Wie viel kostet mich das Lottospielen effektiv? In diesem Beitrag zeige ich, wie mit Hilfe der Firefox-Entwicklerwerkzeugen eine Auswertung erstellt werden kann und wie Webseiten sich manipulieren lassen. Vielleicht lässt sich ja auch eine ganz typische… Continue reading Hacking Lotto 😈 – Mein Fazit nach einem Jahr LOTTO [Data Mining, Data…</description>
      </item>
      <item>
        <title>Securing TYPO3 CMS [New Scanner]</title>
        <link>https://blog.javan.de/securing-typo3-cms-new-security-scanner/</link>
        <guid isPermaLink="true">https://blog.javan.de/securing-typo3-cms-new-security-scanner/</guid>
        <pubDate>Sat, 20 Jun 2020 20:08:32 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>For WordPress there are very comprehensive scanning tools like WPScan. Unfortunately it is not quite the same with the CMS TYPO3. Typo3 describes in its Security Guideline detailed measures to secure the Typo3 instance. Beside the use of secure passwords, always current versions etc. there is also a great area about permissions and access restriction. Let’s hope people are following… Continue reading Securing TYPO3 CMS [New Scanner]</description>
      </item>
      <item>
        <title>Raspberry Pi: Improve your Pi-hole with great adlists and an auto updater</title>
        <link>https://blog.javan.de/pihole-dns-blocklists-adlists-auto-updater/</link>
        <guid isPermaLink="true">https://blog.javan.de/pihole-dns-blocklists-adlists-auto-updater/</guid>
        <pubDate>Sat, 23 May 2020 18:42:49 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>I installed the Pi-hole on a Raspberry Pi. Pi-hole is a DNS server for your home network. I have it running on a Raspberry Pi 1, so it’s nice to have a use for my old Raspberry here. It also runs on a Raspberry Zero. Pi-hole is a DNS sinkhole (/blackhole) and is used to block unwanted domains without installing… Continue reading Raspberry Pi: Improve your Pi-hole with great adlists and an auto updater</description>
      </item>
      <item>
        <title>Firefox bug #1608687 “Master password prompt can be bypassed, once it was already unlocked”</title>
        <link>https://blog.javan.de/firefox-bug-1608687/</link>
        <guid isPermaLink="true">https://blog.javan.de/firefox-bug-1608687/</guid>
        <pubDate>Sat, 07 Mar 2020 22:14:30 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>Two months ago I found a security issue in the Firefox integrated Password Manager and reported it. It was so obvious that I was really surprised. Of course, I was not the first to find this vulnerability. After I reported it, I was informed that it was known and that a bugfix for Firefox 73 was already available in beta.… Continue reading Firefox bug #1608687 “Master password prompt can be bypassed, once it was already unlocked”</description>
      </item>
      <item>
        <title>Raspberry Pi: Eigene Raspbian Images bauen mit pi-gen</title>
        <link>https://blog.javan.de/raspbian-images-selbst-bauen/</link>
        <guid isPermaLink="true">https://blog.javan.de/raspbian-images-selbst-bauen/</guid>
        <pubDate>Sat, 07 Mar 2020 14:44:44 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Mit dem Raspberry Pi 4 hat die Raspberry Foundation einen leistungsstarken Computer auf den Markt gebracht. Wer sich mit seinem Raspberry Pi beschäftigt, wird mit hoher Wahrscheinlichkeit die von der Raspberry Foundation bereitgestellte Linux Distribution Raspbian bereits einmal installiert haben. Hier gab es über die Jahre immer wieder verschiedene Versionen im zugrundeliegendem Debian-System. Daher trägt das Raspbian-System je nach Versionsstand… Continue reading Raspberry Pi: Eigene Raspbian…</description>
      </item>
      <item>
        <title>Run a targeted watering hole attack with your WordPress Blog</title>
        <link>https://blog.javan.de/condition-injection/</link>
        <guid isPermaLink="true">https://blog.javan.de/condition-injection/</guid>
        <pubDate>Sun, 17 Nov 2019 14:53:00 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>en</dc:language>
        <description>By chance I found in my Google Analytics analysis that my blog was visited by Google employees. My blog must have been linked to their internal “Mentor” page, because the HTTP referrer shows the domain “mentor.corp.google.com”, which comes from Google’s intranet. A browser automatically sends the last visited page in the header field “Referer”. A tracking service, in this case… Continue reading Run a targeted watering hole attack with your WordPress Blog</description>
      </item>
      <item>
        <title>Wie auf einen Spear-Phishing Angriff reagieren?</title>
        <link>https://blog.javan.de/wie-auf-einen-spear-phishing-angriff-reagieren/</link>
        <guid isPermaLink="true">https://blog.javan.de/wie-auf-einen-spear-phishing-angriff-reagieren/</guid>
        <pubDate>Tue, 15 Oct 2019 15:46:32 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Letztens wurde mir die folgende SMS an mein Handy gesendet. Auf der verlinkten Seite war eine Nachbildung der Postbank Banking Seite erreichbar. Also eine Phishing-Seite, die versucht hat mein Kennwort abzufangen. Durch die richtigen Gegenmaßnahmen konnte die Phishing-Seite schnell vom Netz genommen werden. Der Inhalt der SMS war wie folgt: Aufgrund einer Änderung unserer Geschäftsbedingungen müssen Sie ihr BestSign-Gerät erneut… Continue reading Wie auf einen Spear-Phishing Angriff reagieren?</description>
      </item>
      <item>
        <title>Open-Source Pricetracker für Amazon Artikel 📉 (PHP, MySql, jQuery)</title>
        <link>https://blog.javan.de/open-source-pricetracker-fuer-amazon-artikel-php-mysql-jquery/</link>
        <guid isPermaLink="true">https://blog.javan.de/open-source-pricetracker-fuer-amazon-artikel-php-mysql-jquery/</guid>
        <pubDate>Tue, 01 Oct 2019 18:00:17 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Ein Preiswächter benachrichtigt dich per E-Mail, wenn ein Produkt, welches du auf Amazon.de kaufen möchtest, die von dir gewählte Preisschwelle durchbrochen hat. Durch durchwegs wechselnde Marketplace Händler und wechselnde Angebote geschehen solche Preisschwankungen im Onlinehandel sehr häufig. Ein geeignetes Mittel, vor allem um bei teuren Elektronikprodukten, Geld zu sparen. Aus eigener Erfahrung kann ich sagen, wenn es nicht gerade dringend… Continue reading Open-Source Pricetracker für…</description>
      </item>
      <item>
        <title>Bienenstand-Monitoring 🐝 🔍 mit R</title>
        <link>https://blog.javan.de/bienenstand-monitoring-%f0%9f%90%9d-%f0%9f%94%8d-mit-r/</link>
        <guid isPermaLink="true">https://blog.javan.de/bienenstand-monitoring-%f0%9f%90%9d-%f0%9f%94%8d-mit-r/</guid>
        <pubDate>Fri, 06 Sep 2019 09:23:17 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Im Rahmen einer Mastervorlesung zu Business Analytics und Anwendungsentwicklung durfte ich ein mir bisher unbekanntes Framework erproben: RStudio und Shiny. Trotz anfänglicher Skepsis, die darin begründet lag, dass das gesteckte Ziel auch mit mir bekannten Frameworks und Sprachen erreicht werden würde, lernte ich recht schnell die Vorteile von R und Shiny kennen. R ist eine funktionale Sprache, die rein für… Continue reading Bienenstand-Monitoring 🐝 🔍 mit R</description>
      </item>
      <item>
        <title>Installationsanleitung: Automatische Vulnerability Scans mit OWASP ZAP in SonarQube und Jenkins (CI, DevSecOps)</title>
        <link>https://blog.javan.de/automatische-vulnerability-scans-mit-owasp-zap-in-sonarqube-und-jenkins-ci-devsecops/</link>
        <guid isPermaLink="true">https://blog.javan.de/automatische-vulnerability-scans-mit-owasp-zap-in-sonarqube-und-jenkins-ci-devsecops/</guid>
        <pubDate>Wed, 07 Aug 2019 06:35:47 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Um die dynamischen Scans von OWASP Zed Attack Proxy (ZAP) in die Build-Pipeline zu integrieren kann das SonarQube ZAP Plugin eingesetzt werden. Der folgenden Beitrag dient als Schritt-für-Schritt Installationsanleitung vom Aufsetzen der VM bis zum fertigen Report. Passend zu diesem Beitrag auch: Dynamische Analyse mit OWASP ZAP Übersicht verwendeter Programmversionen Zur Übersicht werden hier die Versionsnummern der verwendeten Programme aufgelistet.… Continue reading Installationsanleitung:…</description>
      </item>
      <item>
        <title>OWASP AppSensor – Erkennen und Reagieren auf Angriffe in der Anwendungsebene.</title>
        <link>https://blog.javan.de/owasp-appsensor-detect-and-respond-to-attacks-on-application-level/</link>
        <guid isPermaLink="true">https://blog.javan.de/owasp-appsensor-detect-and-respond-to-attacks-on-application-level/</guid>
        <pubDate>Sun, 21 Jul 2019 11:05:03 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Sicherheit in Web-Anwendungen ist eines der Top-Themen im Security-Umfeld. Ist doch die Web-Anwendung an vorderster Front die Schnittstelle ins Internet. Die OWASP Top-10, die 10 gefährlichsten Schwachstellen in Webapplikationen, beinhalten eine Schwachstelle, die genau genommen gar keine ist. Durch das „Unzureichende Logging und Monitoring“ werden Kompromittierungen teilweise gar nicht oder viel zu spät erkannt. Es dauert im Durchschnitt bis zu… Continue reading OWASP AppSensor – Erkennen und…</description>
      </item>
      <item>
        <title>Trainingsanwendung: SQL-Injection innerhalb eines Node.js Projekts</title>
        <link>https://blog.javan.de/trainingsanwendung-sql-injection-innerhalb-eines-node-js-projekts/</link>
        <guid isPermaLink="true">https://blog.javan.de/trainingsanwendung-sql-injection-innerhalb-eines-node-js-projekts/</guid>
        <pubDate>Mon, 10 Dec 2018 08:05:58 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Im Repository befindet sich ein verwundbares NodeJS Projekt. In dieses Projekt wurde eine SQL-Injection Schwachstelle eingebaut. In der Datei „/routes/users.js“ befindet sich die Applikationslogik für die Fälle „User einloggen“, „User registrieren“ und „User anzeigen“. Die Informationen werden über die REST-API im JSON-Format übertragen. Die Datenhaltung der Applikation erfolgt in einer MySql-Datenbank. Download Anwendung Zur Installation der Entwicklungsumgebung kann den Schritten… Continue…</description>
      </item>
      <item>
        <title>Dynamische Analyse mit OWASP Zed Attack Proxy (ZAP)</title>
        <link>https://blog.javan.de/dynamische-analyse-mit-owasp-zed-attack-proxy-zap/</link>
        <guid isPermaLink="true">https://blog.javan.de/dynamische-analyse-mit-owasp-zed-attack-proxy-zap/</guid>
        <pubDate>Sat, 08 Dec 2018 07:23:57 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Der OWASP Zed Attack Proxy (ZAP) ist eines der weltweit beliebtesten, kostenlosen Sicherheitstools und wird von hunderten internationalen Freiwilligen aktiv betreut. OWASP ZAP kann dabei helfen, automatisch Sicherheitslücken in Webanwendungen zu finden, während die Anwendungen noch entwickelt und getestet werden. ZAP ist ein sehr umfangreiches Tool, mit sehr vielen Funktionalitäten. Es gibt eigens dafür veröffentlichte Schulungen und Workshops. Durch die… Continue reading Dynamische Analyse mit…</description>
      </item>
      <item>
        <title>ESP32 Projekt: Messdaten vom BME680 Sensor mit Webinterface visualisieren.</title>
        <link>https://blog.javan.de/esp32-bme680-sensor-in-webinterface-visualisieren/</link>
        <guid isPermaLink="true">https://blog.javan.de/esp32-bme680-sensor-in-webinterface-visualisieren/</guid>
        <pubDate>Fri, 30 Nov 2018 15:28:43 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Dieser Blogbeitrag widmet sich einem schnellen Setup, um die Messwerte des BME680 Sensors in einer Weboberfläche sichtbar zu machen. Notwendige Downloads Zunächst muss die Arduino Entwicklungsumgebung vorbereitet werden und benötigte Librarys (falls noch nicht vorhanden) importiert werden. Hier die wichtigsten Downloadlinks: Installation des Treibers: Download USB to UART Bridge VCP Drivers Genutzte Arduino Librarys Adafruit_Sensors Arduino Library BSEC Arduino Library… Continue reading ESP32…</description>
      </item>
      <item>
        <title>Naturathon 2018. Wir haben gewonnen! 🎉</title>
        <link>https://blog.javan.de/naturathon-2018-wir-haben-gewonnen-%f0%9f%8e%89/</link>
        <guid isPermaLink="true">https://blog.javan.de/naturathon-2018-wir-haben-gewonnen-%f0%9f%8e%89/</guid>
        <pubDate>Thu, 15 Nov 2018 15:30:01 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Schon wieder Feinstaubalarm in Stuttgart? 🤣 Wir haben beim Naturathon 2018 den Preis für die “innovativste digitale Lösung” gewonnen. Mit unserem Smartphone Gadget ist es jedem möglich selbst und mobil die Luftqualität zu messen. Das hat Potential! Wir haben beim Naturathon 2018 in Stuttgart mit unserem Team den Preis für die “innovativste digitale Lösung” gewonnen. Der Naturathon ist ein digitaler… Continue reading Naturathon 2018. Wir haben gewonnen! 🎉</description>
      </item>
      <item>
        <title>Der Unterschied liegt im Detail. Rich-Internet-Application vs. Single-Page-Application</title>
        <link>https://blog.javan.de/rich-internet-application-vs-single-page-application/</link>
        <guid isPermaLink="true">https://blog.javan.de/rich-internet-application-vs-single-page-application/</guid>
        <pubDate>Mon, 30 Apr 2018 17:53:31 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Für Rich-Internet-Application, welches zu Deutsch als “reichhaltige Internet-Anwendung” übersetzt werden kann, gibt es keine eindeutige Definition, da der Begriff RIA aus der Entwicklung des Internets entstanden ist. Rich-Internet-Application (RIA) Eine Herkunft des Begriffs wird in grauer Literatur durch die vielfältigen, „reichen“ Interaktionsmöglichkeiten begründet. Denn eine RIA ähnelt mehr einer dynamischen Desktopanwendung, als einer klassischen, statischen Webseite. Das liegt daran, dass……</description>
      </item>
      <item>
        <title>Angriffsvektoren durch IoT-Devices. Internet of Insecure Things.</title>
        <link>https://blog.javan.de/angriffsvektoren-durch-iot-devices-internet-of-insecure-things/</link>
        <guid isPermaLink="true">https://blog.javan.de/angriffsvektoren-durch-iot-devices-internet-of-insecure-things/</guid>
        <pubDate>Mon, 08 Jan 2018 13:16:04 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Im September 2016 trat ein, wovor Sicherheitsexperten schon länger gewarnt hatten, was aber noch nicht sonderlich ernst genommen wurde. Der Größte bisher gemessene DDos-Angriff mit Rekordhöhe von über 1 Terabit pro Sekunde ging von Tausenden Embedded- und IoT-Geräten aus. Ein Angriff mit bislang unbekanntem Ausmaß. Das dafür verantwortliche Botnetz trägt den Namen „Mirai“ und kaperte aus Tausenden Haushalten und Unternehmen… Continue reading Angriffsvektoren durch IoT-Devices. Internet of…</description>
      </item>
      <item>
        <title>Entwicklung eines browserbasierten Keyloggers mit Steuerungsinterface (PoC, Download)</title>
        <link>https://blog.javan.de/greasemonkey-keylogger-mit-steuerungs-interface/</link>
        <guid isPermaLink="true">https://blog.javan.de/greasemonkey-keylogger-mit-steuerungs-interface/</guid>
        <pubDate>Sun, 01 Nov 2015 20:59:04 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Im Rahmen meiner mündlichen Abschlussprüfung in Computertechnik (Abitur 2015) entwickelte ich diesen Proof of Concept für einen browserbasierten Keylogger. Der Keylogger beinhaltet ein umfangreiches Steuerungsinterface, womit die Nutzer verwaltet werden können. Ein Keylogger in Form von JavaScript Quellcode wird vom Webserver bereitgestellt und anschließend bei den Nutzern im Browser ausgeführt. Es findet eine rund um die Uhr Überwachung der Cookies,… Continue reading Entwicklung eines…</description>
      </item>
      <item>
        <title>Prinzip von Code Injection. Beispiele für SQL und HTML.</title>
        <link>https://blog.javan.de/it-sicherheit-code-injection-grundsaetzliches-prinzip-und-beispiele-fuer-sql-und-html/</link>
        <guid isPermaLink="true">https://blog.javan.de/it-sicherheit-code-injection-grundsaetzliches-prinzip-und-beispiele-fuer-sql-und-html/</guid>
        <pubDate>Sun, 01 Nov 2015 20:08:18 GMT</pubDate>
        <dc:creator>Javan Rasokat</dc:creator>
        <dc:language>de</dc:language>
        <description>Als Injection wird das Einfügen fremden Codes zu einem bereits bestehenden Programmcode bezeichnet. Injection ist also eine Manipulation bestehender Programmierung. Mittels Code Injection wird dabei neuer Programmcode injectiert, also eingefügt und sogar bestehender Programmcode so manipuliert, dass dieser nicht mehr das macht, was er eigentlich sollte. Damit eine Injection funktioniert, muss eine Schwachstelle existieren. Diese Schwachstelle besteht darin, dass zum… Continue reading Prinzip von…</description>
      </item>
  </channel>
</rss>
