<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Travis Peters on The Trail of Bits Blog</title><link>https://miscreants.github.io/blog.trailofbits.com/authors/travis-peters/</link><description>Recent content in Travis Peters on The Trail of Bits Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 09 Dec 2024 09:00:43 -0500</lastBuildDate><atom:link href="https://miscreants.github.io/blog.trailofbits.com/authors/travis-peters/index.xml" rel="self" type="application/rss+xml"/><item><title>35 more Semgrep rules: infrastructure, supply chain, and Ruby</title><link>https://miscreants.github.io/blog.trailofbits.com/2024/12/09/35-more-semgrep-rules-infrastructure-supply-chain-and-ruby/</link><pubDate>Mon, 09 Dec 2024 09:00:43 -0500</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2024/12/09/35-more-semgrep-rules-infrastructure-supply-chain-and-ruby/</guid><description>We are publishing another set of custom Semgrep rules, bringing our total number of public rules to 115. This blog post will briefly cover the new rules, then explore two Semgrep features in depth: regex mode (especially how it compares against generic mode), and HCL language support for technologies […]</description></item><item><title>Security flaws in an SSO plugin for Caddy</title><link>https://miscreants.github.io/blog.trailofbits.com/2023/09/18/security-flaws-in-an-sso-plugin-for-caddy/</link><pubDate>Mon, 18 Sep 2023 08:00:42 -0400</pubDate><guid>https://miscreants.github.io/blog.trailofbits.com/2023/09/18/security-flaws-in-an-sso-plugin-for-caddy/</guid><description>We identified 10 security vulnerabilities within the caddy-security plugin for the Caddy web server that could enable a variety of high-severity attacks in web applications, including client-side code execution, OAuth replay attacks, and unauthorized access to resources. During our evaluation, Caddy was deployed as a reverse proxy […]</description></item></channel></rss>