which gives white-hats the opportunity to patch your system without exploiting. The why I see it, a malicious person is going to exploit your server anyway. This way white-hats could patch your system and not be prosecuted. With this, someone who discovered the patch could scan the internet, look for servers that say "yes, please patch me" and deploy a quick patch and nothing else.
> The all-you-can-eat is capped (small print) at a "fair usage" of 25 Gb/month.
I can tell you that this is wrong, I've personally had months where I've used 100GB+ of data over 3G and had no problems (this is on a £15 top-up). I don't know if they throttle or not, I've never really noticed it.
> Tethering is disabled while roaming overseas on "feel at home", but not prevented at home.
I didn't get my handset from Three but I've been able to tether in Paris and used at least 2GB when I was there.
Hi, thanks for the feedback. I've asked for credit card details to prevent the abuse of this service since you can scan any website.
However, I'm currently in the process of working with the Google Analytics API to provide free scans for verified websites where the user can prove ownership -- this should roll out in about a week or so. Would you like me to drop you a PM when I release this feature?
Hi everyone, this is the MVP I have been working on. It's almost 5am in the UK right now and I just wanted to launch as soon as possible and stop procrastinating (and waiting for my A-level results). It's funded entirely by my Google bug bounties, so thank you Google. I have not done any design stuff for it yet -- the site is very bare bones but functional.
Current solutions to vulnerability scanning such as WPscan are good but not user-friendly -- which is what I believe what WordPress users want. I've already got my first 5 customers prior to launch that wanted this product which I think is a good start, hopefully there is a market for this stuff.
I built a security scanner that scans WordPress installations for threats (plugin vulns, outdated installs, theme vulns, xss, sqli etc) without any installation or code knowledge required. I posted it on Reddit and got a few sign ups, after that I just got bored and I'm not sure what to do next. I'm thinking about partnering with WordPress tutorial websites and give them a recurring revenue cut or something. I really wish I was better at marketing products. Maybe I should just sell it or something. Any WordPress related websites with good amount of traffic please contact me if you're interested in partnering.
Simple logic: The defacement was amature at best. If the group has a 0-day in a hypervisor they would have gone to multiple hosting companies and multiple attacks would have taken place, there are many more targets that are worth much more than openSSL.
Most likely, the administration panel of the hosting company was comprimised through malware/phishing. Seriously, if a group like this had a 0-day in hypervisor then they would be doing much much more damage.
There is an easier way to solve this issue: Bug Bounty.
It worked for Google, it worked for Facebook and its working for Yahoo! Infact, it worked so well for Google that they recently increased the rewards. A venture-backed startup like Snapchat that stores private pictures (even temporarily) should have no trouble paying out $5k a few times for vulnerabities.