home.social

#xdev — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #xdev, aggregated by home.social.

fetched live
  1. We support @jcon_conference as #XDEV Gold Partner! Dive into the world of Java development & join #JCON2026: 100+ sessions, 100+ speakers, 4 parallel streams & 1:1 speaker meetings. JCON EUROPE 2026 – the opportunity to think outside the box. Get tickets:
    2026.europe.jcon.one/tickets

  2. We support @jcon_conference as #XDEV Gold Partner! Dive into the world of Java development & join #JCON2026: 100+ sessions, 100+ speakers, 4 parallel streams & 1:1 speaker meetings. JCON EUROPE 2026 – the opportunity to think outside the box. Get tickets:
    2026.europe.jcon.one/tickets

  3. È disponibile gratuitamente su Steam Airborne, un platform frenetico e di precisione in cui schivare decine e decine di ostacoli.

    n2s.altervista.org/blog/airbor

    #Airborne #Free #Steam #bl4ck #XDev #FreeToPlay #Indie

    @giochi

  4. È disponibile gratuitamente su Steam Airborne, un platform frenetico e di precisione in cui schivare decine e decine di ostacoli.

    n2s.altervista.org/blog/airbor

    #Airborne #Free #Steam #bl4ck #XDev #FreeToPlay #Indie

    @giochi

  5. Wie bleibt #OAuth2 sicher nach dem Login? #XDEV SSE löst das per Auto-Revalidierung statt komplexem Backchannel-Logout – effizient, fail-safe, frontend-ready.

    Mehr von Alexander Bierler: javapro.io/de/xdev-sse-verbess

    @xdevsoftware #OpenSource #Vaadin @vaadin #JAVAPRO #SpringSecurity

  6. Wie bleibt #OAuth2 sicher nach dem Login? #XDEV SSE löst das per Auto-Revalidierung statt komplexem Backchannel-Logout – effizient, fail-safe, frontend-ready.

    Mehr von Alexander Bierler: javapro.io/de/xdev-sse-verbess

    @xdevsoftware #OpenSource #Vaadin @vaadin #JAVAPRO #SpringSecurity

  7. You log users in, but can you log them out—across instances, reliably, after revocation? A #SpringSecurity add-on closes critical gaps in #OAuth2/OIDC session control.

    Learn what #XDEV SSE solves: javapro.io/2025/07/25/explorin

    @xdevsoftware #OpenSource #Vaadin

  8. You log users in, but can you log them out—across instances, reliably, after revocation? A #SpringSecurity add-on closes critical gaps in #OAuth2/OIDC session control.

    Learn what #XDEV SSE solves: javapro.io/2025/07/25/explorin

    @xdevsoftware #OpenSource #Vaadin

  9. Mehr Sicherheit für verteilte Spring-Anwendungen? #XDEV SSE schützt Sessions über Instanzen hinweg, integriert Frontends wie #Vaadin & liefert Metriken via Actuator. Mehr dazu von Alexander Bierler: javapro.io/de/xdev-sse-verbess

    #OAuth2 #OpenSource #Vaadin @vaadin #SpringSecurity

  10. Mehr Sicherheit für verteilte Spring-Anwendungen? #XDEV SSE schützt Sessions über Instanzen hinweg, integriert Frontends wie #Vaadin & liefert Metriken via Actuator. Mehr dazu von Alexander Bierler: javapro.io/de/xdev-sse-verbess

    #OAuth2 #OpenSource #Vaadin @vaadin #SpringSecurity

  11. When every second counts — in hospitals or airports — IT must not fail.

    Why off-the-shelf software often falls short, and how custom #Java solutions ensure full control and resilience:

    Read #BestPractices now: javapro.io/2025/06/02/java-in-

    #MicroServices #XDEV

  12. When every second counts — in hospitals or airports — IT must not fail.

    Why off-the-shelf software often falls short, and how custom #Java solutions ensure full control and resilience:

    Read #BestPractices now: javapro.io/2025/06/02/java-in-

    #MicroServices #XDEV

  13. #SpringSecurity works—until you need distributed logout, token checks, & frontend feedback. Read what #XDEV SSE adds & how it simplifies what’s usually hard to implement.

    A must-read for security-conscious teams: javapro.io/2025/07/25/explorin

    @xdevsoftware @vaadin #Vaadin #OAuth2

  14. #SpringSecurity works—until you need distributed logout, token checks, & frontend feedback. Read what #XDEV SSE adds & how it simplifies what’s usually hard to implement.

    A must-read for security-conscious teams: javapro.io/2025/07/25/explorin

    @xdevsoftware @vaadin #Vaadin #OAuth2

  15. Wenn in Klinik oder Flughafen Sekunden zählen, darf IT nicht versagen. Warum Standardsoftware oft nicht reicht — und wie maßgeschneiderte #Java-Lösungen hier volle Kontrolle und Resilienz sichern:

    Jetzt #BestPractices lesen: javapro.io/de/java-im-ernstfal

    #MicroServices #XDEV

  16. Wenn in Klinik oder Flughafen Sekunden zählen, darf IT nicht versagen. Warum Standardsoftware oft nicht reicht — und wie maßgeschneiderte #Java-Lösungen hier volle Kontrolle und Resilienz sichern:

    Jetzt #BestPractices lesen: javapro.io/de/java-im-ernstfal

    #MicroServices #XDEV

  17. #SpringSecurity reicht oft nicht aus – besonders bei #OAuth2 & verteilten Systemen. #XDEV SSE liefert automatische Token-Revalidierung, Frontend-Logout-Handling & Security-Metriken. Wie es funktioniert? Lese #JAVAPRO: javapro.io/de/xdev-sse-verbess

    #OpenSource #Vaadin @vaadin

  18. #SpringSecurity reicht oft nicht aus – besonders bei #OAuth2 & verteilten Systemen. #XDEV SSE liefert automatische Token-Revalidierung, Frontend-Logout-Handling & Security-Metriken. Wie es funktioniert? Lese #JAVAPRO: javapro.io/de/xdev-sse-verbess

    #OpenSource #Vaadin @vaadin

  19. Session Handling, OIDC, verteilte Logins: #XDEV SSE erweitert #SpringSecurity um das, was in komplexen Systemen oft fehlt. Alexander Bierler zeigt das #OpenSource-Toolkit – inkl. Revalidierung, Metriken & #Vaadin-Support.

    Code & Docs: javapro.io/de/xdev-sse-verbess

    #OAuth2 @vaadin

  20. Session Handling, OIDC, verteilte Logins: #XDEV SSE erweitert #SpringSecurity um das, was in komplexen Systemen oft fehlt. Alexander Bierler zeigt das #OpenSource-Toolkit – inkl. Revalidierung, Metriken & #Vaadin-Support.

    Code & Docs: javapro.io/de/xdev-sse-verbess

    #OAuth2 @vaadin

  21. Struggling with secure session handling in multi-instance Spring apps? This deep dive shows how #XDEV SSE automates token revalidation, prevents stale sessions, & improves frontend sync.

    Read it if #SpringSecurity alone isn’t enough: javapro.io/2025/07/25/explorin
    @xdevsoftware #Vaadin

  22. Struggling with secure session handling in multi-instance Spring apps? This deep dive shows how #XDEV SSE automates token revalidation, prevents stale sessions, & improves frontend sync.

    Read it if #SpringSecurity alone isn’t enough: javapro.io/2025/07/25/explorin
    @xdevsoftware #Vaadin

  23. Session expiry, user revocation, token validation: #SpringSecurity doesn’t cover it all. #XDEV SSE adds practical, production-ready solutions—without complex back-channel workarounds. Secure distributed apps with less code!

    Read #JAVAPRO: javapro.io/2025/07/25/explorin

    @xdevsoftware

  24. Session expiry, user revocation, token validation: #SpringSecurity doesn’t cover it all. #XDEV SSE adds practical, production-ready solutions—without complex back-channel workarounds. Secure distributed apps with less code!

    Read #JAVAPRO: javapro.io/2025/07/25/explorin

    @xdevsoftware

  25. Daydreaming
    Of heap layouts
    The joys of #xdev
    😶‍🌫️

  26. Daydreaming
    Of heap layouts
    The joys of #xdev
    😶‍🌫️

  27. As an old fart in #xdev, I get asked often, mostly by young coworkers, how to get into binary exploitation in 2025. I looked around, and here’s my recommendation:

    pwn.college

    #pwncollege is a huge collection of free #lectures and practical #challenges maintained by a team of #hackers at the Arizona State University. Check it out!

  28. As an old fart in #xdev, I get asked often, mostly by young coworkers, how to get into binary exploitation in 2025. I looked around, and here’s my recommendation:

    pwn.college

    #pwncollege is a huge collection of free #lectures and practical #challenges maintained by a team of #hackers at the Arizona State University. Check it out!

  29. Standard software isn’t enough when every second counts. In safety-critical environments, deeply integrated, robust solutions are essential.

    Why resilient, controllable IT architecture is a must & how #Java provides the foundation: javapro.io/2025/06/02/java-in-

    #Microservices #XDEV

  30. Standard software isn’t enough when every second counts. In safety-critical environments, deeply integrated, robust solutions are essential.

    Why resilient, controllable IT architecture is a must & how #Java provides the foundation: javapro.io/2025/06/02/java-in-

    #Microservices #XDEV

  31. When IT fails, no one notices — until everyone does. Why custom #Java beats off-the-shelf in mission-critical ops:

    • Real-time communication
    • Legacy system migration
    • Full data ownership & control

    Learn more: javapro.io/2025/06/02/java-in-

    #Microservices #BestPractices #XDEV

  32. When IT fails, no one notices — until everyone does. Why custom #Java beats off-the-shelf in mission-critical ops:

    • Real-time communication
    • Legacy system migration
    • Full data ownership & control

    Learn more: javapro.io/2025/06/02/java-in-

    #Microservices #BestPractices #XDEV

  33. JavaOne 2025 is almost here! Don’t miss Richard Fichtner’s talk:

    📅 March 19 | 🕐 1:00 PM PDT | Room 203
    💡 "Apache Maven Survival Guide – Bring it on! -Mode"

    Master Maven with standard plugins – no external tools needed!

    🔗 oracle.com/javaone

    #JavaOne #Java30Years #XDEV

  34. We support @jcon_conference as #XDEV Gold Partner! Dive into the world of Java development & join #JCON2025: 100+ sessions, 100+ speakers, 4 parallel streams & 1:1 speaker meetings. JCON EUROPE 2025 - the opportunity to think outside the box. Get tickets: 2025.europe.jcon.one/tickets

  35. We are proud to announce a milestone for our #IntelliJ plugin “Save Actions”. It has cracked the 100,000 downloads mark! We are currently averaging around 400 downloads per day. 🤯

    More details » xdev.software/news

    #Plugin #XDEV #SaveActions #Jetbrains

  36. We support JCON EUROPE 2024 as #XDEV Gold Partner! Dive into the world of Java development & join #JCON2024: 100+ sessions, 100+ speakers, 4 parallel streams & 1:1 speaker meetings. JCON - the opportunity to think outside the box.

    Get tickets: 2024.europe.jcon.one/tickets

  37. We support JCON WORLD ONLINE 2023 as #XDEV Gold Partner! Dive into the world of Java development & join #JCON2023: 120+ sessions, 100+ speakers, 5 parallel streams & 2600+ attendees.

    JCON WORLD ONLINE 2023 - the opportunity to think outside the box.

    Tickets: 2023.world.jcon.one
    #JAVAPRO

  38. CW: New followers

    Since the stream of new followers has increased these past few days, I thought to say hello to all newcomers!

    As with my old feed @[email protected], I post about #infosec, mostly offensive technical stuff. I hope you enjoy it. Hack the planet!

    #hacking #vulnerability #exploit #0day #xdev

  39. CW: New followers

    Since the stream of new followers has increased these past few days, I thought to say hello to all newcomers!

    As with my old feed @[email protected], I post about #infosec, mostly offensive technical stuff. I hope you enjoy it. Hack the planet!

    #hacking #vulnerability #exploit #0day #xdev

  40. Still thinking about yesterday’s insanely awesome #xdev display by #Qualys

  41. Still thinking about yesterday’s insanely awesome #xdev display by #Qualys

  42. 📣 Join #Gradle's Vincent Mayers and #XDEV Software’s Richard Fritchner at 2pm on March 21 in the Phantasialand Brühl #Javaland Community Room for an exciting session on Developer Productivity Engineering (#DPE) 🚀

    🧠 Discover how to reduce interruptions and frustrations during long build cycles to increase developer happiness and save costs

    Check out their session here - en.shop.doag.org/events/javala

  43. 📣 Join #Gradle's Vincent Mayers and #XDEV Software’s Richard Fritchner at 2pm on March 21 in the Phantasialand Brühl #Javaland Community Room for an exciting session on Developer Productivity Engineering (#DPE) 🚀

    🧠 Discover how to reduce interruptions and frustrations during long build cycles to increase developer happiness and save costs

    Check out their session here - en.shop.doag.org/events/javala

  44. Of course the master heap #xdev at #Qualys managed to achieve significant progress in #exploiting the recent double-free #vulnerability in #OpenSSH server 9.1 (CVE-2023-25136) 💚

    “Quick update: we were able to gain arbitrary control of the rip register through this bug (i.e., we can jump wherever we want in sshd's address space) on an unpatched installation of OpenBSD 7.2 (which runs OpenSSH 9.1 by default). This is by no means the end of the story: this was only step 1, bypass the malloc and double-free protections.”

    “The trick to bypass malloc's double-free and use-after-free protections is to re-allocate the memory that was occupied by options.kex_algorithms as soon as it is free: from malloc's point of view, no attempt is made to free, read, or write memory that is already free; from sshd's point of view, however, an aliasing attack occurs: two different pointers to two different objects refer to the same chunk of memory, and a write to one object overwrites the other object. This opens up a world of possibilities.”

    seclists.org/oss-sec/2023/q1/9

  45. Awesome @githubsecurity articles by @anticomputer on recognizing and exploiting the hidden attack surface of interpreted languages

    Now you C me, now you don't: An introduction to the hidden #attack surface of interpreted languages
    securitylab.github.com/researc

    Now you C me, now you don't, part two: #exploiting the in-between
    securitylab.github.com/researc

    For historical context on the ret2dlresolve #xdev technique, see also Nergal's "The advanced return-into-lib(c) exploits"
    phrack.org/issues/58/4.html