abu bouli al boulali

771 posts

abu bouli al boulali banner
abu bouli al boulali

abu bouli al boulali

@searchspIoit

noob

가입일 Kasım 2009
208 팔로잉56 팔로워
peine de maure 🇨🇼!
peine de maure 🇨🇼!@kippacabana75·
Les frères si vous m’avez envoyé un message récemment et que g pas rep c paske g pas vu car mes dm sont auto delete tout les 3j a cause de elon de merde
Français
4
0
4
509
Jehmy
Jehmy@darkskinjh44534·
@justbyte_ Use telegram instead, I love my privacy
English
4
2
122
49K
Aryan
Aryan@justbyte_·
- create a new instagram account - go private - post all your files - unlimited free cloud storage That's it bro...
Aryan tweet media
English
326
1.1K
42.1K
3M
Princesse
Princesse@pouletcru5__·
On a croisé Bouli wshh
Princesse tweet media
Français
1
0
3
74
abu bouli al boulali
abu bouli al boulali@searchspIoit·
@gigdotzip @fs0c131y Le but final pour un attaquant dans la faille du PIN est de prendre le contrôle du token de l'user, jexplique juste que t'as pas besoin d'accès au téléphone et d'un accès root pour l'obtenir
Français
0
0
0
7
Dan 🪛
Dan 🪛@gigdotzip·
@searchspIoit @fs0c131y this has nothing to do with that i’m talking about or what is shown in the vid im replying to
English
1
0
0
10
Baptiste Robert
Baptiste Robert@fs0c131y·
Je confirme, Paul is right
Paul Moore - Security Consultant @Paul_Reviews

Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

Português
13
67
471
90.6K
Suresh
Suresh@Suresh_00S·
hey @grok which one is the best among these?
Suresh tweet media
English
651
178
14.9K
8.8M
ZeuPet
ZeuPet@ZeuPet·
c’est quoi ce grec qui suce l’état là comment ça -10% ratp condé mairie
ZeuPet tweet media
Français
63
578
9.9K
381.8K
abu bouli al boulali 리트윗함
xenu
xenu@xenumonero·
It's amazing that is the case, because none of Proton's X accounts even advertised this. I only became aware of it because I went to go check on what has been taking so long with the payment service. Monero is not even mentioned once on Proton's website as a payment option. We were told Proton would support Monero, but your solution was to close a support ticket and post a link to a third party reseller landing page on said support ticket (which literally sells services to your competitors), and then never mention Monero again. On your website you have numerous visual guides on how to send money for Proton using platforms that, from a privacy perspective, are atrocious. You guys couldnt spend an afternoon and spin up a payserver for Monero? There is no reason it should not be a payment option easily available on your payment method page like with Bitcoin.
David Peterson@davidgpeterson

@sebp888 People have been buying Proton VPN with Monero since September. We also added Proton Mail, Proton Unlimited, etc into the mix as well for good measure. x.com/davidgpeterson…

English
6
7
73
2.7K
Mae💆🏻‍♀️🇵🇸
@PupettaMassicot @SJ_TheWolvie Tu pense comme une privilégiée bien sûr que si, y’a des tonnes de gens en dépression qui sont pas diag, de femmes autistes pas diag, de gens bipolaires pas diag. Chercher des solutions ça passe aussi par l’auto diag des fois
Français
2
0
2
80
Iris‘
Iris‘@Iristarlpb·
@SJ_TheWolvie Comme tout le monde à la possibilité d’aller chez un psy et de se faire diag
Français
6
0
9
22K
Lee⋆ ˚。⋆୨♡୧⋆ ˚。⋆
MDRRR ok (j'ai arrêté au bout de 5 min quand le mec a dis qu'il fallait un diagnostic et un traitement et que les autodiag c'est de la merde, another day to hate la psychiatrie)
Lee⋆ ˚。⋆୨♡୧⋆ ˚。⋆ tweet media
Français
238
20
372
2.1M
abu bouli al boulali
abu bouli al boulali@searchspIoit·
Paul Moore - Security Consultant @Paul_Reviews

It's not easy to visualize the relay attack against the #EU #AgeVerification app from a user's perspective, so here it is. Even if the app works exactly as designed, the website & verification process is entirely decoupled & 'anonymous' The architecture assumes you'll send the request to your device, which contains your biometric data. But, it can go to any device, anywhere in the world... and because the phone has no way to know who initiated the process, the child still passes age verification. The assertion is the user is over 18. In reality, the app is responding to say the owner of this Android device is over 18. It doesn't know who the user is... how can it know their age? This is the current design, not a bug. They thought the ISO/IEC 18013-7 Annex C/DC API upgrade would protect against this, but CTAP only protects against external attackers, not the user wanting to bypass the system themselves - hence my description that we've replaced "I am over 18" with "someone is over 18" and it's supposedly better. If (more likely when) this is exploited, will company Directors/staff still face fines, legal action or imprisonment for not protecting children? Once you've signed in, websites are highly unlikely to ask for age verification again... so this attack, even if it could be mitigated in some way (I can't see how) only applies to new verifications. The EU #AgeVerification Relay Attack:

QME
0
0
0
47
abu bouli al boulali
abu bouli al boulali@searchspIoit·
@preppycx @fs0c131y le post de smelly parle d'un point de vue risque pour la victime, pas moi. Ca fonctionne comme ca, ce n'est pas une faille de securité. C'est juste de la merde et ca n'a aucun sens. Tu donnes ta CNI à une app qui fait la meme chose que tu faisais avant en cliquant sur 18+ ? : oui
Français
1
0
0
37