A bug that took 2 years in finding. Not because it was hard but because of pandemic.
I really hope that DMRC is going to take some action. #Delhi#Metro#security#DigitalIndia
.@thirdwaveindia where do I report a security vuln? I shouldn't be able to view all the users, let alone admin users. Also, accidentally made myself an admin. Remove that asw. Thanks!
.@thirdwaveindia where do I report a security vuln? I shouldn't be able to view all the users, let alone admin users. Also, accidentally made myself an admin. Remove that asw. Thanks!
@pjparties Late reply: I never thought people would gatekeep my findings haha. The document was written in public domain to educate others. Gatekeeping goes against it. :P
https://t.co/rUzLuhq9Sq
This is the updated blog.
.@amitgupta007 you might be interested in some of the findings :)
I must say, the obfuscation that I've seen in #Yulu's android app is top notch. Tho, obscurity is not #security :)
Mandatory tag, tho I know I'll be ghosted, @YuluBike
@YuluBike You wanna take this to DMs? I found a way to start Miracle bikes without opening the Yulu app. I can elaborate more here or DMs, you decide :).
Dear @HSBC how can you close an account without any notification. And now your officials are saying ‘you will get a demand draft worth of balance in the account’ .Is your mailing system is not working or you became so lazy to notify your customers. #fraud
Delhi Metro is yet to fix the bug reported by Nikhil (@dumbomason) that allows free top ups. Just shows the state of security awareness in India’s best run public utility. Shudder to think about the rest. https://t.co/Fgz36kBB3R
.@intel CEO @PGelsinger examines the Horse Creek @risc_v development platform at #IntelON
Features four @SiFive P550 cores at 2.2GHz with PCIe G5 & DDR5 in a 4mm x 4mm die using Intel 4 process.
Coming soon(tm) to a next generation HiFive dev board
#vlc#websiteban
Strange how @ACTFibernet's website ban technique changed from DNS tampering to just replying as the banned website. How ACT bans @videolan...
A small 🧵...