The new https://t.co/8MsSa8MeD3 search allows for regex, which means brand **new** regex GitHub Dorks are possible!
Eg, find SSH and FTP passwords via connection strings with:
/ssh:\/\/.*:.*@.*target\.com/
/ftp:\/\/.*:.*@.*target\.com/
#BugBounty#bugbountytips#infosec
I used /goal + ASC + adb to analyze my phone. The agent pulled 50+ APKs with uid=1000, then used ASC to analyze them without exporting any pseudocode. After 10 hours, the agent had rooted my phone...😐
#mobile#bugbounty#security
https://t.co/OWoPj03lrz
https://t.co/vX9DChmHkP
Turns out my #PHRACK article is live! 🔥
> The Art of PHP — My CTF Journey and Untold Stories!
Kinda a love letter to those CTF players & PHP nerds! Hope all the credit goes to the right ppl. Also huge thanks to @0xdea for not forgetting me, @guitmz for the edits, and the @Phrack crew for keeping it real! 🎉
https://t.co/BMCLlHti7q
Finally, with @hw16, we managed to bypass the @Cloudflare mTLS protection after around 5 days of work. I'd like to share a few golden tips for bug bounty hunters who might face something similar in the future. But first, here's a quick summary:
The target was a banking app with multiple security layers:
• Heavy Frida detection mechanisms
• Strong root detection
• Google SafetyNet/Play Integrity checks
• Runtime hooking detection
• APK tampering protection (crashed immediately if repackaged/modified)
At first, @fridadotre was detected and crashed the app on my device but strangely worked on another device even though both had the same Android version, root method, Frida server version, and architecture. After investigation, we discovered the app had anti-hooking detection that triggered when using aggressive Frida hooks on sensitive KeyStore operations.
The Solution:
We wrote a minimal Frida script that:
1. Passively monitored certificate operations without modifying behavior
2. Intercepted KeyManagerFactory.init() - the exact moment when mTLS certificates are loaded
3. Extracted the X.509 client certificate and RSA private key (4096-bit)
4. Encoded them using Android's Base64 encoder
5. Formatted as PEM files ready for use
Found the mTLS certificate with a unique UUID-based alias in the Android KeyStore. The certificate was being dynamically loaded during the SSL handshake initialization
Extracted Files:
• client_cert.pem → Client certificate (valid for 2 years)
• client_key.pem → RSA private key (PKCS#8 format)
We then created a PKCS#12 bundle using OpenSSL to combine the certificate and key into a single file, which could be imported into various tools and browsers for testing or @Burp_Suite
Key Takeaway:
When facing anti-tampering mechanisms, be surgical hook only what you need, when you need it. Aggressive hooking triggers detection; passive monitoring flies under the radar.
This was an awesome challenge and my first time encountering such strong ssl Pinning defenses
Attached some image from the mobile api and frida output the certificates
#bugbountytips #frida #Magisk #mtls
Xbow raised $117M to build AI hacker agents, in @AliasRobotics open-sourced it and made it completely free.
Github: https://t.co/0LhmFhD9bT
Paper: https://t.co/UEUtCUefru
Okay so this is HUGE - our amazing AI red team have open sourced their AI red team labs so you can set up your own training!
https://t.co/brvdq6roHp
@ram_ssk
Researchers extend Flipper Zero with CAN Bus interface, connect it to RAMN (by Toyota) – and magically turn it into a powerful vehicle simulation platform. 🚗 🐬 🍜
Link to post: https://t.co/hGZ0pcKsWv
Attackers can use QR codes to bypass browser isolation and establish command and control.
Learn how the technique works, and recommendations on how to stay ahead of this threat: https://t.co/9egDx1nQpO