Sign in

Dominique Righetto

@righettod.eu
1.3K followers 139 following 198 posts

👨‍💻 AppSec enthusiast | 🐶 Addicted to Shetland Sheepdogs | 🌏 Open Source/AppSec/OWASP junkie | 🐝 OWASP Secure Headers Project Leader. 🚩 Opinions mentioned are mine.

PostsRepliesMedia
Dominique Righetto @righettod.eu · 13/09/2026
📡 OWASP Secure Headers Project: The web user interface is back, we worked all weekend, after the OWAP Foundation's new website went live, to get it back online 😉 #appsec #appsecurity #owasp_shp
UI rendering overview
100
Dominique Righetto @righettod.eu · 06/09/2026
🔬 The goal of this open source project is to propose them to help DevOps teams with which I have a chance to work with to handle issues identified during secure code review I perform for them. Currently, the collection includes 14 skills, that isn't very many yet, but the number will grow over time.
Overview
110
Dominique Righetto @righettod.eu · 01/08/2026
🧑‍🎓 Learning of the day for me, once again thanks to @pentesterlab.com (for the presentation of the behavior and the lab) and Claude (for more detailed explanation). #appsec #appsecurity
POC
110
Dominique Righetto @righettod.eu · 19/07/2026
📡 OWASP Secure Headers Project - update: 1) We added info about the header "Integrity-Policy". 2) We defined the rules about GenIA usage. 3) We also developed a AI agent to help us (beta). 📖 github.com/OWASP/www-pr... 🤖 github.com/righettod/os... #appsec #appsecurity #owasp_shp
000
Dominique Righetto @righettod.eu · 12/04/2026
📡 OWASP Secure Headers Project: We have refactored the section on the browser’s "Local Network Access" feature. #appsec #appsecurity #owasp_shp 📖 owasp.org/www-project-...
110
Dominique Righetto @righettod.eu · 26/03/2026
To make it visual, I made an example with a fictional function used to compare if two hosts have the same FQDN:
Example of execution
000
Dominique Righetto @righettod.eu · 14/03/2026
🧑‍🎓 Learning of the day for me thanks to @pentesterlab.com (for the presentation of the behavior and the code review lab) and Claude (for the detailed explanation): #appsec #appsecurity
Example of execution.
111
Dominique Righetto @righettod.eu · 26/02/2026
🧑‍🎓 As part of my homework on AI from an AppSec perspective, I have decided to gather all my content on GitHub so that I can share it in case anyone is interested. 📖 Cheat sheet, methodology and tools: github.com/righettod/to... 🔬 R&D: github.com/righettod/po... #appsec #appsecurity #ai
Overview of one repo
011
Dominique Righetto @righettod.eu · 02/02/2026
🧑‍🎓 Learning of the day for me thanks to @pentesterlab.com and Claude. 🔬 For the regular expression "[A-z]": In a character class [X-Y], it matches all characters with ASCII codes from X to Y inclusive. So [A-z] means all ASCII characters from 65 (A) to 122 (z). #appsec #appsecurity
Execution of the POC performed.
141
Dominique Righetto @righettod.eu · 21/01/2026
🧑‍🎓 Learning of the day for me: I discovered that browsers (at least Chromium) display an SVG image even if the specified content type is set to XML. The contained JS script is also executed. #appsec #appsecurity
POC performed.
362
Dominique Righetto @righettod.eu · 12/01/2026
📡 OWASP Secure Headers Project: We have added information and examples regarding the Trusted Types feature of the Content-Security-Policy header. 📖 owasp.org/www-project-... #appsec #appsecurity #owasp_shp
Overview of the page.
001
Dominique Righetto @righettod.eu · 13/12/2025
🧑‍🎓 Learning of the day for me thanks to: - @pentesterlab.com for the presentation of the behavior and the code review lab. - ChatGPT for the detailed explanation. #appsec #appsecurity #python
Example of execution.
121
Dominique Righetto @righettod.eu · 29/11/2025
Therefore, if you know of or find an HTTP response header that we have missed, please feel free to share this information with us via a "Feature Request" issue: github.com/OWASP/www-pr... #appsec #appsecurity #owasp_shp #http #headers 📖 owasp.org/www-project-...
Content of the page.
110
Dominique Righetto @righettod.eu · 26/11/2025
Overview of the execution.
000
Dominique Righetto @righettod.eu · 14/11/2025
🧑‍💻 Since I often search for CWEs corresponding to a problem I have encountered and have not found a tool suited to my needs, I decided to create a small script that allows me to search for CWE records using a CWE identifier or a term. #appsec #appsecurity #cwe
Example of execution of the script.
110
Dominique Righetto @righettod.eu · 09/11/2025
🧑‍💻 During the secure code reviews I perform, I quite often find that sensitive information is included in messages intended to be written to event logs or error messages. I added a utility method to my "code-snippets-security-utils" project to help detection. #appsec #appsecurity
javadoc of the method.
100
Dominique Righetto @righettod.eu · 19/10/2025
POC results:
020
Dominique Righetto @righettod.eu · 15/09/2025
🧑‍🎓 Learning of the day for me: During my technical survey, I found a GitHub project offering a POC for CVE-2025-54988. I therefore decided to add a new check for this attack vector to my code snippet project for validating PDF files. github.com/righettod/co... #appsec #appsecurity
100
Dominique Righetto @righettod.eu · 17/08/2025
📡 OWASP Secure Headers Project: We added information about the response header "X-DNS-Prefetch-Control" based on technical tests we performed. #appsec #appsecurity #owasp_shp 📖 owasp.org/www-project-...
100
Dominique Righetto @righettod.eu · 19/07/2025
💻 Script: github.com/righettod/to... 📖 References & tools used: - deps.dev - owasp.org/www-project-... - docs.npmjs.com/cli/v9/comma... - classic.yarnpkg.com/lang/en/docs... #appsec #appsecurity #cve #maven #npm
110
Dominique Righetto @righettod.eu · 05/07/2025
🔬 When I perform a secure code review, I also check whether the external components used are affected by public vulnerabilities (CVE). Recently, after a advice from my manager on this subject, I tried to go further and check whether the CVEs identified had a POC/Exploit. #appsec #appsecurity #cve
121
Dominique Righetto @righettod.eu · 26/06/2025
🧑‍🎓 Learning of the day for me: I discovered that it is possible to leverage the instruction "include" in a XSD schema to perform a SSRF when the schema is parsed by the schema factory. #appsec #appsecurity #java
192
Dominique Righetto @righettod.eu · 12/06/2025
📡 OWASP Secure Headers Project: We've reworked the section providing code snippets for configuring different web/application servers to leverage "LLM as a Service" providers. #appsec #appsecurity #owasp_shp 📖 owasp.org/www-project-...
000
Dominique Righetto @righettod.eu · 15/04/2025
📡 OWASP Secure Headers Project: Spring updates n°1. 1) Several updates were made to the content. 2) A redirection from previous links was implemented. #appsec #appsecurity #owasp_shp 📖 owasp.org/www-project-... 💡 Related pull requests: - github.com/OWASP/www-pr... - github.com/OWASP/owasp....
Content updates
000
Dominique Righetto @righettod.eu · 13/04/2025
💡Discovery of the day for me: Mozilla's new tool for checking a website's configuration in terms of HTTP headers and other aspects of its security. 💻GitHub Repository: github.com/mdn/mdn-http... 🔬Site: developer.mozilla.org/en-US/observ... #appsec #appsecurity #web
Overview of the site
074
Dominique Righetto @righettod.eu · 18/03/2025
Thank you very x1000000 much @shehackspurple.bsky.social 😊 It is time for me to learn new things in secure code review activity 👨‍💻
171
Dominique Righetto @righettod.eu · 16/03/2025
👨‍💻 Addition of a new method for checking a regular expression against the “ReDOS” attack. 🌍 righettod.github.io/code-snippet... 💻 github.com/righettod/co... #appsec #appsecurity 📖 Every resources used are referenced into the code.
120
Dominique Righetto @righettod.eu · 22/02/2025
📡 OWASP Secure Headers Project: We've redesigned the way statistics are generated and presented. They are now integrated into the main site. #appsec #appsecurity #owasp_shp 📊 owasp.org/www-project-...
Overview of the tab.
195
Dominique Righetto @righettod.eu · 16/02/2025
✅I ran a quick test, and the default behavior seems secure against this attack vector, which is good news from an AppSec point of view. #appsec #appsecurity #web #python
POC executed.
100
Dominique Righetto @righettod.eu · 09/02/2025
🤔 Based on issues that I have seen during recent assessments, I updated my code sharing project with a method related to JWT based tokens: #appsec #appsecurity #jwt #web 🌍 URL: github.com/righettod/co... righettod.github.io/code-snippet...
011
Dominique Righetto @righettod.eu · 19/01/2025
Indeed and, to be honest, I was wrong until your message 😱 So, I performed a tiny POC that fully confirmed your remark. Thanks a lot for your very useful remark 👍
000
Dominique Righetto @righettod.eu · 18/01/2025
📡If you use TestSSL to check the TLS configuration of several services, you may find this set of scripts useful: github.com/righettod/to... github.com/righettod/to... #appsec #appsecurity #tls #testssl
0142
Dominique Righetto @righettod.eu · 14/01/2025
📡 OWASP Secure Headers Project: Section about Content-Security-Policy bypasses prevention updated with information related to the "base-uri" directive. #appsec #appsecurity #owasp_shp #csp 📖 owasp.org/www-project-...
2102
Dominique Righetto @righettod.eu · 22/12/2024
Thanks a lot, we already referenced it 😉
Reference to the DrHEADER project
010
Dominique Righetto @righettod.eu · 20/12/2024
📡 OWASP Secure Headers Project: We played around with some popular artificial intelligence systems to generate cool new OSHP logos that better fit our mantra. #appsec #appsecurity #oshp #logo 📖 github.com/OWASP/owasp-... 💡 AI systems used: - chatgpt.com - copilot.microsoft.com 👀 Example:
031
Dominique Righetto @righettod.eu · 19/12/2024
Thank you very much @pentesterlab.com and @snyff.pentesterlab.com 🥰🥰🥰🥰
141
Dominique Righetto @righettod.eu · 18/12/2024
📡 OWASP Secure Headers Project: To close the 2024 roadmap and prepare for 2025, discussion/issue management has been moved to the main repository. #appsec #appsecurity #oshp 📖 github.com/OWASP/www-pr...
110
Dominique Righetto @righettod.eu · 07/12/2024
Is it normal?
110
Dominique Righetto @righettod.eu · 06/12/2024
📡 OWASP Secure Headers Project: The "Response Headers" section has been updated with a series of very interesting blog posts about the "Cross-Origin-Embedder-Policy", "Cross-Origin-Opener-Policy" and "Cross-Origin-Resource-Policy" headers. #appsec #appsecurity #oshp 📖 owasp.org/www-project-...
1256
Dominique Righetto @righettod.eu · 27/11/2024
I share an image, that I found on Twitter some month ago, that I uses in my "toolkit" to handle my ASD+ADHD: 🌏Source: twitter.com/milan_milano... #autism #asd #adha
071
Dominique Righetto @righettod.eu · 25/11/2024
📡 OWASP Secure Headers Project: Addition of a new section on modern browsers' support for a large Content-Security-Policy policy. #appsec #appsecurity #oshp 📖 owasp.org/www-project-...
050
Dominique Righetto @righettod.eu · 17/11/2024
010
Dominique Righetto @righettod.eu · 16/11/2024
📡 OWASP Secure Headers Project: For information, we provide a Venom test suite to check the security headers of HTTP responses defined in your web application. #appsec #appsecurity #oshp 📖 github.com/oshp/oshp-va...
191