There is also a new documentation site at http://o2platform.com/fluentnode
Please take these for a test drive and let me know what you think of it
Public REST APIs have become mainstream. Now, almost every company that wants to expose services or an application programming interface does it using a publicly exposed REST API. This talk will give participants the skills they need to identify and understand REST vulnerabilities. The findings are a result of reviewing production REST applications as well as researching popular REST frameworks.
By Abraham Kang, Alvaro Muñoz and Dinis CruzIn addition to the original demos we did, Alvaro added a nice Metasploit PoC which really should drive home the problem with XStream and XMLDecoder.
firstname.lastname@example.org , ABC@def.ghi , abc@EDF.ghib) but these ones didn't:
abc@def.Ghi , email@example.comHi , abc@def.GHI