[su_panel border="1px solid #ddd" radius="3" text_align="center"] [/su_panel]
armoredcode.com – the application security blog that gets the job done
Railsberry chronicles: day 2 – The English penetration test (eventually the day I talk to 450+ oustanding developers)
Finally the day I gave the talk is arrived and it’s gone. Going on stage in front a more than 450 talented developers was an astonishing experience. It drove me crazy. My ...
Railsberry chronicles: day 0 – the trip
I’m too tired, even for rest. It’s a sunny sunday afternoon here in Cracow and I’m on my hotel room writing this post. This night was almost sleepless so I had the ...
I don’t care if app is unsecure, it’s friday I’m in love
A month ago I opened a “one question only” survey on surveytmonkey. I asked “Why you don’t make any web application penetration test when I deploy a new web application (or a ...
Being nervous and anxious before a talk
It happens all the time I have to deliver a talk. Some days before my anxiety-meter level goes out of scale. It will last until slide number 4 when I will recall ...
Untold: nobody will make a cinema story over this blog and I’m fine
Julie Powell is an American writer who creates a blog back in 2002. She wrote about an American woman lived in Paris in 1949-or-something that innovates American cooking scenario writing a book ...
Happy birthday armoredcode and 4 rails advisories
It was a year ago when I started the armoredcode.com project. The goal, it’s useful to recall it, is to talk to developers about application security. And this evening there are three ...
Creating awereness on an hostile environment
With a colleague we were wondering about how much difficult is to create an application security awareness climate in big corporate development team. Please bear in mind that since I’m working in ...
Ruby on Rails cheatsheet: the review
Jim Manico is a friend and a rinomated security professional. He announced in Owasp mailing list that a Ruby on Rails cheatsheet is available. I asked Jim to introduce himself. Jim Manico ...
Exploiting SSH weak passwords the ruby way
Even before starting writing complex input filters to manage your users’ input, you must care about the password you use on your servers. If they are poor, no application security on Earth ...
Is Vulnerability Management a buzz word?
Some days ago, on a Facebook.com group about Italian startups, a smart guy said he had a breakthrough product he is going to develop: a cloud based solution to store people sensitive ...

