Aray 🦋

2.8K posts

Aray 🦋 banner
Aray 🦋

Aray 🦋

@araylW

19 ʚɞ - 🏳️‍⚧️ - ⋆。˚ life hate account ˚。⋆ - #kcwin #cfowin

she/her Katılım Nisan 2023
617 Takip Edilen87 Takipçiler
Sabitlenmiş Tweet
Aray 🦋
Aray 🦋@araylW·
C'est pas fou mais j'aime bien
Français
2
1
14
2.2K
Aray 🦋
Aray 🦋@araylW·
Anxiété de merde
Français
0
0
5
48
Aray 🦋
Aray 🦋@araylW·
acheter une ledger sur un site chinois pas cher faut être un peu con quand même
International Cyber Digest@IntCyberDigest

🚨🇧🇷 A cybersecurity researcher from Brazil exposed a large scale scam operation by buying a "Ledger" hardware wallet off a Chinese marketplace — suspiciously cheap and the packaging looked original from a distance. Here's what he found after cracking the thing open: The "hardware wallet" Inside the shell was a completely different chip — the kind you'd find in a cheap IoT gadget, not a wallet designed to protect your crypto. The markings had been physically sanded off to hide what it actually was. The firmware pretended to be a real Ledger version that doesn't even exist (Ledger Nano S+ V2.1). And here's the kicker: every seed phrase and PIN you'd type into it was stored in plain text and sent straight to the attacker's server (kkkhhhnnn[.]com). Instantly... It was built to drain wallets across ~20 different blockchains. The fake app The seller kindly included a "Ledger Live" app to go with it. It was a modified copy — not even signed properly, the attackers didn't bother with the basics — and it silently siphoned off data the moment you used it. Just when you thought this was it, the same crew is also pushing malware for Windows, macOS, and even iOS — using TestFlight to sneak past Apple's App Store review entirely. The researcher has sent a full report to Ledger's security team. A deeper technical breakdown is expected once they've finished their analysis. This was shared on Reddit by u/Past_Computer2901

Français
1
2
77
3.4K
Aray 🦋 retweetledi
Aray 🦋 retweetledi
Seb
Seb@seblatombe·
🔴 L'application européenne de vérification d'âge hackée en 2 minutes : de simples modifications dans les fichiers locaux permettent de contourner le PIN, le biométrique et les limites de tentative, exposant potentiellement des données d’identité sensibles.
Paul Moore - Security Consultant @Paul_Reviews

Hacking the #EU #AgeVerification app in under 2 minutes. During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory. 1. It shouldn't be encrypted at all - that's a really poor design. 2. It's not cryptographically tied to the vault which contains the identity data. So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app. After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid. Other issues: 1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying. 2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step. Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.

Français
29
514
1.1K
82.3K
Aray 🦋
Aray 🦋@araylW·
@bc1ruby lets goo ça yaura quoi comme features ?
Français
1
0
1
12
尺ㄩ乃ㄚ 🌸
尺ㄩ乃ㄚ 🌸@bc1ruby·
je vais faire une extention pour ameliorer twitter ça commence a me casser les couilles
Français
2
0
7
193
Aray 🦋 retweetledi
Proton VPN
Proton VPN@ProtonVPN·
Things age verification achieves: • Violating adults' privacy online • Creating leak and hack-worthy databases with tons of personal sensitive information • Censoring the internet as a whole Things age verification does not achieve: • Protecting children online
English
59
972
3K
90.2K
Aray 🦋
Aray 🦋@araylW·
@Jzombigaming En ce moment je cherche plus une webapp, c'est plus pratique en split view avec un autre tab
Français
2
0
1
56
Jzombi 2.0
Jzombi 2.0@Jzombigaming·
@araylW C'était quoi le problème avec ces logiciels pour toi ? (Vraie question ça m'intéresse)
Français
2
0
1
61
Aray 🦋
Aray 🦋@araylW·
Je cherche une app / webapp pc de prise de note rapide, vous avez des suggestions ? J'ai testé obsidian, notion, QOwnNotes mais rien ne me va
Français
4
0
4
417
Aray 🦋
Aray 🦋@araylW·
@Jzombigaming Pour notion: trop lent à charger et je détèste l'ui Obsidian: les vaults sont chiant a gérer QOwnNotes: l'une des meilleures que j'ai testée dernièrement mais je suis pas fan de l'ui
Français
0
0
1
11
Aray 🦋
Aray 🦋@araylW·
ptdrr je suis en train d'aider une pote à faire un cookie grabber je chiale
Français
0
0
2
57
Aray 🦋 retweetledi
Céleste🌸
Céleste🌸@celestial04_·
fou rire quand tu sais que linux c’est limite impossible à manager en terme de cybersécurité
Français
4
1
50
4.8K
l'
l'@urlowola·
y'a pas un letterboxd version musique svp
Français
24
1
53
12.8K
Aray 🦋
Aray 🦋@araylW·
fou rire quand tu sais que linux c’est limite impossible à manager en terme de cybersécurité
Français
1
0
30
1.2K
Aray 🦋
Aray 🦋@araylW·
J'ai passé la nuit à tester @zen_browser c'est le meilleur navigateur que j'ai testé jcrois bien
Français
1
0
2
92
Aray 🦋 retweetledi
Oza
Oza@Ozarukuro·
Voir son PC vieillir...
GIF
Français
32
454
6.7K
122.1K