Please open Telegram to view this post
VIEW IN TELEGRAM
Labs Detectify
Account hijacking using "dirty dancing" in sign-in OAuth-flows
Combining response-type switching, invalid state and redirect-uri quirks using OAuth, with third-party javanoscript-inclusions has multiple vulnerable scenarios where authorization codes or tokens could leak to an attacker. This could be used in attacks for…
❤4🔥2 2 1
🔥3
Forwarded from Brut Security
Please open Telegram to view this post
VIEW IN TELEGRAM
❤3👍3
Please open Telegram to view this post
VIEW IN TELEGRAM
❤3
Please open Telegram to view this post
VIEW IN TELEGRAM
Writeups
Android web attack surface
The following is a writeup for some Android specific chromium behaviors.
❤3
👍2🔥2
Forwarded from Android Security & Malware
Malimite: iOS decompiler designed to analyze and decode IPA files
Built on top of Ghidra to offer direct support for Swift, Objective-C, and iOS resources
https://github.com/LaurieWired/Malimite
Built on top of Ghidra to offer direct support for Swift, Objective-C, and iOS resources
https://github.com/LaurieWired/Malimite
GitHub
GitHub - LaurieWired/Malimite: iOS and macOS Decompiler
iOS and macOS Decompiler. Contribute to LaurieWired/Malimite development by creating an account on GitHub.
❤3
BugBounty & Hacking Resources
https://x.com/garethheyes/status/1871540782328352965?s=46
این کاربردش کجاس(ff):
اگه تو هدر یا متا تگ charset تعریف ولی ست نشده باشه یا مقدارش اشتباه باشه
تو (chrome) به نظر باید حتما:
iso-2022-jp
باشه
اگه تو هدر یا متا تگ charset تعریف ولی ست نشده باشه یا مقدارش اشتباه باشه
تو (chrome) به نظر باید حتما:
iso-2022-jp
باشه
🔥6❤2👍1