🔍 My ultimate workflow for simple and easy JavaScript Analysis
⚡️ Comprehensive JavaScript analysis in offensive security, appsec testing, and red teaming wins.
Often you can find juicy hidden endpoints, parameters, & domains buried JS!
A thread 🧵 1/x
👇
I recently investigated threat activity leveraging NetSupport Managar RAT and GitHub repository wiki pages with weak permissions to compromise unsuspecting victims. Read about it here: https://t.co/r0vhECYSSd
Welcome to Zero Day Engineering Links
Topics:
• vulnerability research
• reverse engineering
• system internals
• exploit engineering
We select, feature and comment mature, original, top quality community research and code which has a clear impact and practical applications
A few months ago Cellebrite announced that they would begin parsing data from Signal in their extraction tools. It seems they're not doing that very carefully.
Exploiting vulnerabilities in Cellebrite's software, from an app's perspective: https://t.co/9ar6ypnPe2
My mother-in-law thought she was sending me exercises to stretch when you work too many hours at your desk. Turns out she sent me a forensics 101 CTF challenge. #lifeisactf#base64#cyberchef
Two years ago, secret club member @floesen_ reported a remote code execution flaw affecting all source engine games. It can be triggered through a Steam invite. This has yet to be patched, and Valve is preventing us from publicly disclosing it.