Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @FrenchYeti
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @FrenchYeti
-
Prikvačeni tweet
Do u know Dexcalibur ? An automatic DBI tool for Android powered by Frida with a GUI.https://github.com/FrenchYeti/dexcalibur …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
Looking forward #r2con2020?
Here's a sneak peak on this year plans, so you can all start warming the engines! https://www.radare.org/con/2020/
pic.twitter.com/suIubjJJdA
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
Periodic service message:
#pts20 CFP is currently opened! {Offensive, blueteam, network, low level, privacy ...}#security +#FreeSoftware talks or workshops are welcome and will be evaluated with care
Everything is on: https://cfp.pass-the-salt.org RT appreciated
pic.twitter.com/rwm2nmgVPzPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
My talk at #r2con2019 has been published! "A journey through ESIL: understanding code emulation within radare2" is aimed to be a simple introduction to the inner workings, the power and the practical usage of@radareorg's ESIL. Hope you like it!
https://youtu.be/MaFafykTASw Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
Russia blocks encrypted email service ProtonMail https://buff.ly/2tZtUNW In other words "Russia validates the integrity of ProtonMail"
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
VSCode x
@fridadotre * VSCode based GUI * Interactive terminal * Remote file browser (Yes!) * Open source Not on market yet. But you can built it from the source: https://github.com/chichou/vscode-frida …pic.twitter.com/sG5UhDy2WdPrikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
I wrote a small tool to "recreate" AFL's mutation chain from a given seed/crash. It can also produce a graph that shows the relationship between seeds and the mutations that led to the creation of those seeds Hopefully it's useful to
#fuzzing peeps https://github.com/adrianherrera/afl-mutation-chain …pic.twitter.com/gLIk0oG6wg
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
“An Observational Investigation of Reverse Engineers’ Processes”, to appear at Usenix Security 2020https://twitter.com/krismicinski/status/1210379898440835073 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
バーコーダーセッション
バーコードリーダーのスキャン信号をレジではなく、スピーカーに直接接続することで音を鳴らす。
昼はバイトでレジ係、夜はクラブでバーコーディストになれます┃┃┃┃
#barcoder#electronicosfantasticospic.twitter.com/EZoDwlSsq0Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
Another day, another
#RIDL embargo and addendum! “New” (not really!) variants of the day: L1D evictions (Fig 6, RIDL paper) or#L1DES and vector registers or#VRS. See http://mdsattacks.com . As a bonus: a faster RIDL exploit that leaks a root hash in 4s:https://www.youtube.com/watch?v=4DQAcCfg3b8 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
This KCOV extension by Andrey allows syzkaller to collect coverage from background kernel threads e.g. parsing incoming USB packets and unambiguously associate it with one of multiple parallel test processes running. To some degree unique for fuzzing coverage. Moar bugs coming!https://twitter.com/andreyknvl/status/1221784089340121088 …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
GDA is a Dalvik bytecode decompiler written in C++. It supports APK, DEX, ODEX and OAT files. Looks really cool, especially if you don't have JEB, but it's not open source yet. https://buff.ly/2Gfmqc8
#AndroidSecurity#reversengineeringpic.twitter.com/YNoRaNYI6u
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
When you develop hook mechanism for a smali VM in order to generate Android frida hook
#dexcaliburpic.twitter.com/Yk6I1MGiZcHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
Automatic ROP chain generation using ROPgadget (gadgets finding) and Triton (sym. exec. part) by
@n0psledbyte https://github.com/d4em0n/exrop !!Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
Android (AOSP) Download Provider SQL Injection in Query Selection Parameter (CVE-2019-2198)
#MobileSecurity#AndroidSecurity by@IOActive Report: https://act-on.ioactive.com/acton/attachment/34793/f-0b1db136-6474-4c86-b944-0ba96a89283a/1/-/-/-/-/cve-2019-2198.pdf … PoC: https://github.com/IOActive/AOSP-DownloadProviderDbDumperSQLiWhere …pic.twitter.com/DP0Av43xYHHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
AFLplusplus + libprotobuf-mutator https://github.com/thebabush/afl-libprotobuf-mutator/ …
#fuzzing#securityHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
Happy new decade!
#android#security is still a thing, thus we will host the third edition of#AndroidSecuritySymposium in Linz, Austria on July 6-7, 2020 (at@jkulinz, co-located with@acm_wisec) More details and call for speakers: https://android.ins.jku.at/symposium/ pic.twitter.com/TozGDWk1jv
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
If you hope auto/semi-auto integration of external tools with an android static analyzer and hook into
#Dexcalibur, please send me suggests such as activity fuzzing using intent template generated by sast, ... :)Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
But…
The attacker tweaks a few strings in their frida-server binary using a hex editor, and the fun starts.
The user gets their battery drained quicker when such code has been pasted into many popular apps.
High price to pay for the illusion of slowing down attackers?
https://twitter.com/insitusec/status/1195464033249431553 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
Top
#Android#malware threats - Month of December, 2019 Full list - (link: http://skptr.me/malware_timeline_2019.html …) Download (most of the) samples - (link: https://github.com/sk3ptre/AndroidMalware_2019 …)#infosec#securitypic.twitter.com/JtJhLujejr
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
FrenchYeti proslijedio/la je Tweet
New blogpost: Sanitized Emulation with QEMU-AddressSanitizer https://andreafioraldi.github.io/articles/2019/12/20/sanitized-emulation-with-qasan.html … I just open-sourced my QEMU patches to fuzz binaries with ASan, QASan. You can also use it with ARM targets on Linux, a thing that you can't do with LLVM ASan!
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.