No jailbreak. No problem. 🔓
I built a tool that bypasses iOS SSL Pinning using OpenVPN + iptables — works with Burp Suite & mitmproxy out of the box.
👇 GitHub
https://t.co/N4QyCDaXvR
#CyberSecurity#BugBounty#iOS#Pentesting
Day 19 Proxy Contract Security Tips
Verify proxy contracts use the onlyInitializing modifier instead of initializer to ensure proper initialization.
Verify selfdestruct and delegatecall in implementation contracts do not introduce vulnerabilities.
#Web3#BlockchainSecurity#NFT
Day 18
#ThreatModeling for Blockchain in #STRIDE framework
S : Spoofing compromised private keys enables an attacker to masquerade as a user and generate #Blockchain transactions on their behalf.Blockchain malware can steal private keys or modify transactions on your behalf.
Just released a new recollapse version thanks to @ryancbarnett and @4ng3lhacker after their talk in @BlackHatEvents today.
What’s new?
💥Mode 6: Fuzz case folding/upper/lower
💥 Mode 7: Fuzz byte truncations
💥 Recollapse is now available to use as a python library and available on @pypi
Check it out 👇
CVE-2024-51466 (CVSS 9.0): Critical Vulnerability Found in IBM Cognos Analytics
Learn about the severe vulnerabilities in IBM Cognos Analytics platform (CVE-2024-51466 and CVE-2024-40695) and how to mitigate the risks.
https://t.co/FK72QattTT
CVE-2024-51466, a critical Expression Language (EL) Injection in IBM Cognos Analytics (11.2.0–11.2.4 FP4, 12.0.0–12.0.4).
What it does:
Allows remote, unauthenticated attacker to perform RCE
Severity: CVSS 3.1 , 9.0 (CRITICAL)
https://t.co/JZx9bmFhAr
When I was still a Teenager, I thought maybe my generation will be better at handling religion, racism and gender related discussion and opinions.
I'll be 30 next year, turns out it'll take another generation to be better.
Hopefully sooner.