Sean Pesce

90 posts

Sean Pesce banner
Sean Pesce

Sean Pesce

@SeanPesce

IoT & Android Hacker | OSCP | https://t.co/363zDIbhfm

United States Katılım Ağustos 2016
194 Takip Edilen256 Takipçiler
Sean Pesce
Sean Pesce@SeanPesce·
@ozeniken @archiveis IIRC this is due to some archaic rules around classified data, and/or bringing data into classified spaces (e.g., SCIFs)
English
1
0
9
2.4K
Sean Pesce
Sean Pesce@SeanPesce·
@rebane2001 @NotionHQ I've long thought there should be an option to retain history on 0-second meta redirects TBH
English
0
0
1
108
Rebane
Rebane@rebane2001·
i think @NotionHQ is the first website i've come across that's (accidentally, i hope) hostile to noscript users it has a 0-second meta refresh to a js-disabled page, which means that even if you enable js, you're still stuck on this page and cannot even use the back button
Rebane tweet media
English
21
16
1K
62.9K
Sean Pesce
Sean Pesce@SeanPesce·
@Muntrive @FirewallFiasco @Hacker0x01 One-click ATO is absolutely a vulnerability, and often considered high-severity. Anyone saying otherwise is objectively incorrect. Consider also that many XSS and CSRF attacks require a click, and they don't always guarantee something as impactful as ATO.
English
1
0
1
191
Sean Pesce
Sean Pesce@SeanPesce·
@fr4vian Yeah it's basically impossible unless you have a generous triager - I've found several one-click RCEs and all were rated "high"
English
0
0
1
229
Franc Vian
Franc Vian@fr4vian·
Just curious 🤔Have any of you folks ever received a ‘critical’-rated report for a mobile issue? 👉MOBILE👈not web issue using mobile ... thats WEB
English
8
0
26
8K
Sean Pesce
Sean Pesce@SeanPesce·
@skcd42 @charliermarsh Yeah I believe this is just a general browser quirk, your highlighted selection is lost when the DOM is updated
English
1
0
2
416
skcd
skcd@skcd42·
the root cause for this is that when the streaming is going on, the markdown renderer re-renders the whole html node. The same problem occurs in vscode using the GitHub copilot cause of the markdown renderer vscode uses. I remember tackling this exact problem while working on the editor and it was very very non-trivial. Now given that this is the web interface and they are probably using the Monaco editor for this, the root cause might be the same.
English
4
1
86
9.6K
Charlie Marsh
Charlie Marsh@charliermarsh·
This can't just be me, right? Battling endlessly against this text-selection behavior?
English
298
65
3K
344.6K
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
anyone used SMT solvers to find bugs in real apps like chrome? any blogs?
English
1
0
6
1.2K
Sean Pesce
Sean Pesce@SeanPesce·
@Ch0pin Also, excessive use of the "not interested in this post" button
English
0
0
2
110
Dimitri Os
Dimitri Os@Ch0pin·
How to normalize you tweeter feed as a security researcher in the musk era: - Start scrolling - Click / Stop only on security related topics. Don't dare to blink / delay over something else ... No matter what !! - Do this for about an hour
English
2
2
9
911
Sean Pesce
Sean Pesce@SeanPesce·
@Ch0pin Nice! Definitely an under-researched topic
English
0
0
0
73
Dimitri Os
Dimitri Os@Ch0pin·
finally some light ....
Dimitri Os tweet media
English
1
0
11
1K
Sean Pesce
Sean Pesce@SeanPesce·
@vasyaqwee @tdinh_me VS Code: right-click -> "format document," and when you copy/paste from it, it retains your (theme-specific) syntax highlighting
English
0
0
1
96
Tony Dinh
Tony Dinh@tdinh_me·
Love Pieter but all developers should stop pasting their JSON payload on random website on the internet just to beautify it 😬
@levelsio@levelsio

✨ I made a new thing today: 📑 JSON.pub Whenever I need to quickly copy paste a raw JSON data dump from my app and view it I'd always use json . parser . online . fr but it seems unmaintained, keeps going down, doesn't have HTTPS, and other JSON viewers are full of spyware/malware/tracking scripts So I made this today with a lot of help from ChatGPT to solve it for me and everyone else: JSON.pub visualizes raw JSON data for you, and does it 100% on the client without sending any data to the server But it also secretly supports a lot of other data formats like XML, PHP serialized data, hexadecimal, base64 encoded data, and even binary! And it also works well on mobile! Another one of my little hack projects :D If you want me to add other data types, let me know and I'll add them

English
79
53
2.1K
313.2K
Sean Pesce
Sean Pesce@SeanPesce·
@MishaalRahman Actually, I've seen quite a few devices with security policies that let you install/sideload apps, but not enable developer options - this would still be a use-case for Termux
English
0
0
1
130
Mishaal Rahman
Mishaal Rahman@MishaalRahman·
Here's a first look at Android's upcoming all-in-one Terminal app, which downloads, configures, runs, and interfaces with an instance of Debian running a virtual machine! Currently, the Debian images are hosted on a Googler's GitHub, but Google plans to host these images themselves soon. For more info on this Terminal app, see the replies👇 (Thanks to an anonymous dev for sharing this!)
English
13
54
449
54.4K
Sean Pesce
Sean Pesce@SeanPesce·
This is just a small sample from that list
Sean Pesce tweet media
English
0
0
0
337
Sean Pesce
Sean Pesce@SeanPesce·
Arc browser (on Android, at least) seems to block ads and annoyances by injecting a <style> element on every page you visit - it applies this style by using a giant list of more than 12,000 CSS selectors for common nuisance DOM elements
Sean Pesce tweet media
English
1
0
0
546