#xdev — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #xdev, aggregated by home.social.
-
We support @jcon_conference as #XDEV Gold Partner! Dive into the world of Java development & join #JCON2026: 100+ sessions, 100+ speakers, 4 parallel streams & 1:1 speaker meetings. JCON EUROPE 2026 – the opportunity to think outside the box. Get tickets:
https://2026.europe.jcon.one/tickets -
We support @jcon_conference as #XDEV Gold Partner! Dive into the world of Java development & join #JCON2026: 100+ sessions, 100+ speakers, 4 parallel streams & 1:1 speaker meetings. JCON EUROPE 2026 – the opportunity to think outside the box. Get tickets:
https://2026.europe.jcon.one/tickets -
È disponibile gratuitamente su Steam Airborne, un platform frenetico e di precisione in cui schivare decine e decine di ostacoli.
https://n2s.altervista.org/blog/airborne-steam/
-
È disponibile gratuitamente su Steam Airborne, un platform frenetico e di precisione in cui schivare decine e decine di ostacoli.
https://n2s.altervista.org/blog/airborne-steam/
-
Wie bleibt #OAuth2 sicher nach dem Login? #XDEV SSE löst das per Auto-Revalidierung statt komplexem Backchannel-Logout – effizient, fail-safe, frontend-ready.
Mehr von Alexander Bierler: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
@xdevsoftware #OpenSource #Vaadin @vaadin #JAVAPRO #SpringSecurity
-
Wie bleibt #OAuth2 sicher nach dem Login? #XDEV SSE löst das per Auto-Revalidierung statt komplexem Backchannel-Logout – effizient, fail-safe, frontend-ready.
Mehr von Alexander Bierler: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
@xdevsoftware #OpenSource #Vaadin @vaadin #JAVAPRO #SpringSecurity
-
You log users in, but can you log them out—across instances, reliably, after revocation? A #SpringSecurity add-on closes critical gaps in #OAuth2/OIDC session control.
Learn what #XDEV SSE solves: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
-
You log users in, but can you log them out—across instances, reliably, after revocation? A #SpringSecurity add-on closes critical gaps in #OAuth2/OIDC session control.
Learn what #XDEV SSE solves: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
-
Mehr Sicherheit für verteilte Spring-Anwendungen? #XDEV SSE schützt Sessions über Instanzen hinweg, integriert Frontends wie #Vaadin & liefert Metriken via Actuator. Mehr dazu von Alexander Bierler: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
#OAuth2 #OpenSource #Vaadin @vaadin #SpringSecurity
-
Mehr Sicherheit für verteilte Spring-Anwendungen? #XDEV SSE schützt Sessions über Instanzen hinweg, integriert Frontends wie #Vaadin & liefert Metriken via Actuator. Mehr dazu von Alexander Bierler: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
#OAuth2 #OpenSource #Vaadin @vaadin #SpringSecurity
-
When every second counts — in hospitals or airports — IT must not fail.
Why off-the-shelf software often falls short, and how custom #Java solutions ensure full control and resilience:
Read #BestPractices now: https://javapro.io/2025/06/02/java-in-critical-operations-how-custom-development-ensures-control-and-secures-mission-critical-systems/
-
When every second counts — in hospitals or airports — IT must not fail.
Why off-the-shelf software often falls short, and how custom #Java solutions ensure full control and resilience:
Read #BestPractices now: https://javapro.io/2025/06/02/java-in-critical-operations-how-custom-development-ensures-control-and-secures-mission-critical-systems/
-
#SpringSecurity works—until you need distributed logout, token checks, & frontend feedback. Read what #XDEV SSE adds & how it simplifies what’s usually hard to implement.
A must-read for security-conscious teams: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
@xdevsoftware @vaadin #Vaadin #OAuth2
-
#SpringSecurity works—until you need distributed logout, token checks, & frontend feedback. Read what #XDEV SSE adds & how it simplifies what’s usually hard to implement.
A must-read for security-conscious teams: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
@xdevsoftware @vaadin #Vaadin #OAuth2
-
Entertaining and inspiring #pwn2own #xdev writeup 👏 (also from a few months back)
#Lorex 2K Indoor Wi-Fi Security Camera: RCE #Exploit Chain
-
Entertaining and inspiring #pwn2own #xdev writeup 👏 (also from a few months back)
#Lorex 2K Indoor Wi-Fi Security Camera: RCE #Exploit Chain
-
Wenn in Klinik oder Flughafen Sekunden zählen, darf IT nicht versagen. Warum Standardsoftware oft nicht reicht — und wie maßgeschneiderte #Java-Lösungen hier volle Kontrolle und Resilienz sichern:
Jetzt #BestPractices lesen: https://javapro.io/de/java-im-ernstfall-wie-eigenentwicklung-kontrolle-schafft-und-kritische-systeme-sichert/
-
Wenn in Klinik oder Flughafen Sekunden zählen, darf IT nicht versagen. Warum Standardsoftware oft nicht reicht — und wie maßgeschneiderte #Java-Lösungen hier volle Kontrolle und Resilienz sichern:
Jetzt #BestPractices lesen: https://javapro.io/de/java-im-ernstfall-wie-eigenentwicklung-kontrolle-schafft-und-kritische-systeme-sichert/
-
#SpringSecurity reicht oft nicht aus – besonders bei #OAuth2 & verteilten Systemen. #XDEV SSE liefert automatische Token-Revalidierung, Frontend-Logout-Handling & Security-Metriken. Wie es funktioniert? Lese #JAVAPRO: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
#OpenSource #Vaadin @vaadin
-
#SpringSecurity reicht oft nicht aus – besonders bei #OAuth2 & verteilten Systemen. #XDEV SSE liefert automatische Token-Revalidierung, Frontend-Logout-Handling & Security-Metriken. Wie es funktioniert? Lese #JAVAPRO: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
#OpenSource #Vaadin @vaadin
-
Session Handling, OIDC, verteilte Logins: #XDEV SSE erweitert #SpringSecurity um das, was in komplexen Systemen oft fehlt. Alexander Bierler zeigt das #OpenSource-Toolkit – inkl. Revalidierung, Metriken & #Vaadin-Support.
Code & Docs: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
#OAuth2 @vaadin
-
Session Handling, OIDC, verteilte Logins: #XDEV SSE erweitert #SpringSecurity um das, was in komplexen Systemen oft fehlt. Alexander Bierler zeigt das #OpenSource-Toolkit – inkl. Revalidierung, Metriken & #Vaadin-Support.
Code & Docs: https://javapro.io/de/xdev-sse-verbesserung-der-spring-security-fuer-moderne-anwendungen/
#OAuth2 @vaadin
-
Struggling with secure session handling in multi-instance Spring apps? This deep dive shows how #XDEV SSE automates token revalidation, prevents stale sessions, & improves frontend sync.
Read it if #SpringSecurity alone isn’t enough: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
@xdevsoftware #Vaadin -
Struggling with secure session handling in multi-instance Spring apps? This deep dive shows how #XDEV SSE automates token revalidation, prevents stale sessions, & improves frontend sync.
Read it if #SpringSecurity alone isn’t enough: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
@xdevsoftware #Vaadin -
Session expiry, user revocation, token validation: #SpringSecurity doesn’t cover it all. #XDEV SSE adds practical, production-ready solutions—without complex back-channel workarounds. Secure distributed apps with less code!
Read #JAVAPRO: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
-
Session expiry, user revocation, token validation: #SpringSecurity doesn’t cover it all. #XDEV SSE adds practical, production-ready solutions—without complex back-channel workarounds. Secure distributed apps with less code!
Read #JAVAPRO: https://javapro.io/2025/07/25/exploring-xdev-sse-enhancing-spring-security-for-modern-applications/
-
-
-
As a side note, since somebody asked… 20 years ago I would’ve (and I have in multiple occasions) recommended the legendary #abo series by gera https://web.archive.org/web/20150418052653/http://community.coresecurity.com/~gera/InsecureProgramming/
-
As a side note, since somebody asked… 20 years ago I would’ve (and I have in multiple occasions) recommended the legendary #abo series by gera https://web.archive.org/web/20150418052653/http://community.coresecurity.com/~gera/InsecureProgramming/
-
As an old fart in #xdev, I get asked often, mostly by young coworkers, how to get into binary exploitation in 2025. I looked around, and here’s my recommendation:
#pwncollege is a huge collection of free #lectures and practical #challenges maintained by a team of #hackers at the Arizona State University. Check it out!
-
As an old fart in #xdev, I get asked often, mostly by young coworkers, how to get into binary exploitation in 2025. I looked around, and here’s my recommendation:
#pwncollege is a huge collection of free #lectures and practical #challenges maintained by a team of #hackers at the Arizona State University. Check it out!
-
Standard software isn’t enough when every second counts. In safety-critical environments, deeply integrated, robust solutions are essential.
Why resilient, controllable IT architecture is a must & how #Java provides the foundation: https://javapro.io/2025/06/02/java-in-critical-operations-how-custom-development-ensures-control-and-secures-mission-critical-systems/
-
Standard software isn’t enough when every second counts. In safety-critical environments, deeply integrated, robust solutions are essential.
Why resilient, controllable IT architecture is a must & how #Java provides the foundation: https://javapro.io/2025/06/02/java-in-critical-operations-how-custom-development-ensures-control-and-secures-mission-critical-systems/
-
When IT fails, no one notices — until everyone does. Why custom #Java beats off-the-shelf in mission-critical ops:
• Real-time communication
• Legacy system migration
• Full data ownership & control -
When IT fails, no one notices — until everyone does. Why custom #Java beats off-the-shelf in mission-critical ops:
• Real-time communication
• Legacy system migration
• Full data ownership & control -
JavaOne 2025 is almost here! Don’t miss Richard Fichtner’s talk:
📅 March 19 | 🕐 1:00 PM PDT | Room 203
💡 "Apache Maven Survival Guide – Bring it on! -Mode"Master Maven with standard plugins – no external tools needed!
-
We support @jcon_conference as #XDEV Gold Partner! Dive into the world of Java development & join #JCON2025: 100+ sessions, 100+ speakers, 4 parallel streams & 1:1 speaker meetings. JCON EUROPE 2025 - the opportunity to think outside the box. Get tickets: https://2025.europe.jcon.one/tickets
-
We are proud to announce a milestone for our #IntelliJ plugin “Save Actions”. It has cracked the 100,000 downloads mark! We are currently averaging around 400 downloads per day. 🤯
More details » https://xdev.software/news
-
We support JCON EUROPE 2024 as #XDEV Gold Partner! Dive into the world of Java development & join #JCON2024: 100+ sessions, 100+ speakers, 4 parallel streams & 1:1 speaker meetings. JCON - the opportunity to think outside the box.
Get tickets: https://2024.europe.jcon.one/tickets
-
Ready to optimize your #CloudStorage costs & maximize efficiency? Dive into the innovative realm of #SpringData-#EclipseStore! Learn more about this game-changing solution. Read Johannes Rabauer´s article: https://foojay.io/today/minimize-costs-by-utilizing-cloud-storage-with-spring-data-eclipse-store/ #TechInnovation #XDEV #SpringBoot #EclipseStore
-
Very good intro to modern memory corruption #xdev by @kevinbackhouse
Cueing up a calculator: an introduction to #exploit development on #Linux
-
Very good intro to modern memory corruption #xdev by @kevinbackhouse
Cueing up a calculator: an introduction to #exploit development on #Linux
-
We support JCON WORLD ONLINE 2023 as #XDEV Gold Partner! Dive into the world of Java development & join #JCON2023: 120+ sessions, 100+ speakers, 5 parallel streams & 2600+ attendees.
JCON WORLD ONLINE 2023 - the opportunity to think outside the box.
Tickets: https://2023.world.jcon.one
#JAVAPRO -
CW: New followers
Since the stream of new followers has increased these past few days, I thought to say hello to all newcomers!
As with my old feed @[email protected], I post about #infosec, mostly offensive technical stuff. I hope you enjoy it. Hack the planet!
-
CW: New followers
Since the stream of new followers has increased these past few days, I thought to say hello to all newcomers!
As with my old feed @[email protected], I post about #infosec, mostly offensive technical stuff. I hope you enjoy it. Hack the planet!
-
📣 Join #Gradle's Vincent Mayers and #XDEV Software’s Richard Fritchner at 2pm on March 21 in the Phantasialand Brühl #Javaland Community Room for an exciting session on Developer Productivity Engineering (#DPE) 🚀
🧠 Discover how to reduce interruptions and frustrations during long build cycles to increase developer happiness and save costs
Check out their session here - https://en.shop.doag.org/events/javaland/2023/agenda/#eventDay.all#textSearch.dpe
-
📣 Join #Gradle's Vincent Mayers and #XDEV Software’s Richard Fritchner at 2pm on March 21 in the Phantasialand Brühl #Javaland Community Room for an exciting session on Developer Productivity Engineering (#DPE) 🚀
🧠 Discover how to reduce interruptions and frustrations during long build cycles to increase developer happiness and save costs
Check out their session here - https://en.shop.doag.org/events/javaland/2023/agenda/#eventDay.all#textSearch.dpe
-
Of course the master heap #xdev at #Qualys managed to achieve significant progress in #exploiting the recent double-free #vulnerability in #OpenSSH server 9.1 (CVE-2023-25136) 💚
“Quick update: we were able to gain arbitrary control of the rip register through this bug (i.e., we can jump wherever we want in sshd's address space) on an unpatched installation of OpenBSD 7.2 (which runs OpenSSH 9.1 by default). This is by no means the end of the story: this was only step 1, bypass the malloc and double-free protections.”
“The trick to bypass malloc's double-free and use-after-free protections is to re-allocate the memory that was occupied by options.kex_algorithms as soon as it is free: from malloc's point of view, no attempt is made to free, read, or write memory that is already free; from sshd's point of view, however, an aliasing attack occurs: two different pointers to two different objects refer to the same chunk of memory, and a write to one object overwrites the other object. This opens up a world of possibilities.”
-
Awesome @githubsecurity articles by @anticomputer on recognizing and exploiting the hidden attack surface of interpreted languages
Now you C me, now you don't: An introduction to the hidden #attack surface of interpreted languages
https://securitylab.github.com/research/now-you-c-me/Now you C me, now you don't, part two: #exploiting the in-between
https://securitylab.github.com/research/now-you-c-me-part-two/For historical context on the ret2dlresolve #xdev technique, see also Nergal's "The advanced return-into-lib(c) exploits"
http://phrack.org/issues/58/4.html