abu bouli al boulali

764 posts

abu bouli al boulali banner
abu bouli al boulali

abu bouli al boulali

@searchspIoit

noob

Beigetreten Kasım 2009
208 Folgt56 Follower
Suresh
Suresh@Suresh_00S·
hey @grok which one is the best among these?
Suresh tweet media
English
586
162
12.5K
7.7M
ZeuPet
ZeuPet@ZeuPet·
c’est quoi ce grec qui suce l’état là comment ça -10% ratp condé mairie
ZeuPet tweet media
Français
60
526
9.3K
360.5K
abu bouli al boulali retweetet
xenu
xenu@xenumonero·
It's amazing that is the case, because none of Proton's X accounts even advertised this. I only became aware of it because I went to go check on what has been taking so long with the payment service. Monero is not even mentioned once on Proton's website as a payment option. We were told Proton would support Monero, but your solution was to close a support ticket and post a link to a third party reseller landing page on said support ticket (which literally sells services to your competitors), and then never mention Monero again. On your website you have numerous visual guides on how to send money for Proton using platforms that, from a privacy perspective, are atrocious. You guys couldnt spend an afternoon and spin up a payserver for Monero? There is no reason it should not be a payment option easily available on your payment method page like with Bitcoin.
David Peterson@davidgpeterson

@sebp888 People have been buying Proton VPN with Monero since September. We also added Proton Mail, Proton Unlimited, etc into the mix as well for good measure. x.com/davidgpeterson…

English
6
7
71
2.5K
Mae💆🏻‍♀️🇵🇸
@PupettaMassicot @SJ_TheWolvie Tu pense comme une privilégiée bien sûr que si, y’a des tonnes de gens en dépression qui sont pas diag, de femmes autistes pas diag, de gens bipolaires pas diag. Chercher des solutions ça passe aussi par l’auto diag des fois
Français
2
0
2
68
Iris‘
Iris‘@Iristarlpb·
@SJ_TheWolvie Comme tout le monde à la possibilité d’aller chez un psy et de se faire diag
Français
6
0
9
21.6K
Lee⋆ ˚。⋆୨♡୧⋆ ˚。⋆
MDRRR ok (j'ai arrêté au bout de 5 min quand le mec a dis qu'il fallait un diagnostic et un traitement et que les autodiag c'est de la merde, another day to hate la psychiatrie)
Lee⋆ ˚。⋆୨♡୧⋆ ˚。⋆ tweet media
Français
233
20
364
2M
abu bouli al boulali
abu bouli al boulali@searchspIoit·
Paul Moore - Security Consultant @Paul_Reviews

It's not easy to visualize the relay attack against the #EU #AgeVerification app from a user's perspective, so here it is. Even if the app works exactly as designed, the website & verification process is entirely decoupled & 'anonymous' The architecture assumes you'll send the request to your device, which contains your biometric data. But, it can go to any device, anywhere in the world... and because the phone has no way to know who initiated the process, the child still passes age verification. The assertion is the user is over 18. In reality, the app is responding to say the owner of this Android device is over 18. It doesn't know who the user is... how can it know their age? This is the current design, not a bug. They thought the ISO/IEC 18013-7 Annex C/DC API upgrade would protect against this, but CTAP only protects against external attackers, not the user wanting to bypass the system themselves - hence my description that we've replaced "I am over 18" with "someone is over 18" and it's supposedly better. If (more likely when) this is exploited, will company Directors/staff still face fines, legal action or imprisonment for not protecting children? Once you've signed in, websites are highly unlikely to ask for age verification again... so this attack, even if it could be mitigated in some way (I can't see how) only applies to new verifications. The EU #AgeVerification Relay Attack:

QME
0
0
0
47
abu bouli al boulali
abu bouli al boulali@searchspIoit·
@preppycx @fs0c131y le post de smelly parle d'un point de vue risque pour la victime, pas moi. Ca fonctionne comme ca, ce n'est pas une faille de securité. C'est juste de la merde et ca n'a aucun sens. Tu donnes ta CNI à une app qui fait la meme chose que tu faisais avant en cliquant sur 18+ ? : oui
Français
1
0
0
37
Baptiste Robert
Baptiste Robert@fs0c131y·
Je confirme, Paul is right
Paul Moore - Security Consultant @Paul_Reviews

Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

Português
13
67
472
90.5K
peine de maure 🇨🇼!
peine de maure 🇨🇼!@kippacabana75·
Mon rêve ça serait de créer un lazarus group mais pour la oummah zahma la noble continuité des pirates barbaresque mais contemporainement et on fais des pillages de wallet, des ordre de commande faramineux sans payer etc des pirates quoi
Français
8
3
25
1.6K
abu bouli al boulali
abu bouli al boulali@searchspIoit·
configureOpenId4Vp { withClientIdSchemes( listOf( ClientIdScheme.RedirectUri ) )
English
0
0
0
43
Rich
Rich@preppycx·
@searchspIoit @fs0c131y Bro who the cares about this? An attacker uses your code to verify he is 18? Wow much wow good job
English
1
0
0
23