IT'S GIVEAWAY SEASON!
We will pick 6 winners to win one of the following:
1x Annual VIP Hack The Box Licence
5x Pentesterlab 3 Month Licences
To enter:
1️⃣ Follow us @BugBountyDefcon
2️⃣ Like this post ❤️
3️⃣ Tag 3 hacker friends in the comments
4️⃣ Retweet this post 🔁
Giveaway open until Thursday May 14th!
GOOD LUCK!
@TheSecOpsGroup Unprotected Metadata (No android:protectionLevel)
Impact: Custom permissions or metadata without protectionLevel are accessible to any app, potentially allowing malicious apps to interact in unintended ways.
Risk: Privilege escalation or unauthorized functionality access.
@TheSecOpsGroup Here's my view:
android:allowBackup="true"
Impact: Allows attackers with physical access or root access to back up app data (using tools like adb backup), potentially leading to credential or sensitive data exposure.
Risk: Data leakage or unauthorized access to user data.
@TheSecOpsGroup Hardcoded OAuth Credentials in <meta-data> Tags
Impact: Sensitive API keys or OAuth tokens are exposed in the manifest, making them trivially accessible to attackers via static analysis.
Risk: Unauthorized API access or impersonation, leading to misuse or data compromise.
@TheSecOpsGroup android:usesCleartextTraffic="true"
Impact: Permits HTTP (unencrypted) communication, making app traffic vulnerable to interception or manipulation via MITM (Man-In-The-Middle) attacks.
Risk: Data confidentiality breach and potential regulatory non-compliance.
@TheSecOpsGroup android:debuggable="true" in Production
Impact: Enables debugging on production builds, allowing attackers to attach debuggers and inspect app behavior or bypass controls.
Risk: Compromised app integrity, logic bypass, or information disclosure.
We are thrilled to announce Kaushik Pal as our speaker for the DEF CON Delhi 0x07 Conference!
He will be presenting his talk on the topic "Hunting Threat Actors: Leveraging IoT Search Engines for Infrastructure Analysis".
Stay Tuned!
Happy Hacking! ❤
#dc_9111#defcon#infosec