Akshay Jain

2.9K posts

Akshay Jain

Akshay Jain

@mast3root

Sec guy at FinTech

Katılım Kasım 2012
5.1K Takip Edilen457 Takipçiler
Stevie Graham (new account)
Stevie Graham (new account)@stevegraham·
Ok, enough talking. Introducing Wiretrap: Agentic Mobile App Reverse Engineering. @teller connects to over 7000 financial institutions, providing developers with a single API to integrate against. We connect using private APIs discovered by reverse engineering their mobile apps. This is a huge engineering cost (we have to analyze every app update to check for API changes), and obtaining accounts at those banks to be able to use their apps and map out the API interactions we need for our own API clients is an operational nightmare. Both are major blockers to supporting more institutions, countries, and product types, especially ones that are not practical to obtain at every bank, e.g. student loans and mortgages. Wiretrap solves for both problems. Wiretrap intercepts network requests a mobile app makes and injects symbolic responses that allow an agent to discover the underlying API contract by simply observing what the app does with them. It can override individual values to trigger different flows, allowing agents to completely map out an entire API without a single request hitting the bank. Check out this brief video of an agent using phony credentials to log into Chase (the request is intercepted by Wiretrap and never hits Chase's API) to get to the account dashboard. Note the symbolic value "req_058.response.body.bankingAccountOverviews[0]. businessName" displayed in the app UI, representing the request and key path the value originated from allowing the agent to join what is displayed on screen with what "went over the wire". Everything you see is inferred by observing how the app interacts with Wiretrap's symbolic responses. Another @teller world first :)
Stevie Graham (new account)@stevegraham

.@teller has a tool that can extract an API from any app AND build the SDK for it.

English
34
13
238
66.8K
Akshay Jain
Akshay Jain@mast3root·
@Yogehi Even i was like Damn did they changed so much or you are testing on some crazy modified version.
English
0
0
1
62
Ken Gannon (伊藤 剣)
Over the past few weeks, I was publishing some RASP research bypass stuff, claiming it was Promon stuff we bypassed. But after discussions with Promon, it was discovered that it wasn't Promon. So we took my posts down. Full LinkedIn post here: linkedin.com/posts/mobile-h…
English
3
0
14
1.2K
Akshay Jain retweetledi
8kSec
8kSec@8kSec·
🌍 Earth Day Giveaway - Learn Mobile or AI Security, On Us One beautiful planet we all share. Let's patch it together. 🌱 To celebrate Earth Day, we're planting 3 free seats 🌱 in any 8kSec Academy course - winner's choice of the whole forest: • Practical AI Security: Attacks, Defenses, and Applications • Practical Mobile Application Exploitation • Offensive Mobile Reversing and Exploitation • Offensive iOS Internals • Offensive Android Internals Explore the catalog → academy.8ksec.io How to enter (zero carbon footprint 🍃): 🌿 Follow us 🌿 Like this post 🌎 Repost to spread the seeds 🌟 Bonus: double your chances! 💬 Comment your favorite place on Earth that you have visited or would like to visit 🌍, and we'll count your entry twice 3 winners sprout on April 27. We’ll DM each winner to select their course.
English
54
71
98
5.8K
Akshay Jain
Akshay Jain@mast3root·
Pretty sick post. I had reversed it using very different technique but it’s a nice adventure.
English
1
0
1
381
Akshay Jain retweetledi
Sean Heelan
Sean Heelan@seanhn·
"Why don't LLMs start from SAST findings?" ... well, for the same reason we don't mount car chassis on a horse.
English
8
6
66
11.4K
Akshay Jain retweetledi
erin griffith
erin griffith@eringriffith·
A detailed and brutal look at the tactics of buzzy AI compliance startup Delve "Delve built a machine designed to make clients complicit without their knowledge, to manufacture plausible deniability while producing exactly the opposite." substack.com/home/post/p-19…
English
199
405
4.7K
4.5M
Akshay Jain retweetledi
Asaf Naamani
Asaf Naamani@AsafNaamani·
$XOM | +32% Since My December 1 Post Weekly Chart Update I shared this setup back in DECEMBER. $XOM has performed very well so far, and I’m pleased with this trade. It will likely continue higher when the market opens tomorrow. I’ve added the next price target: $166 zone.
Asaf Naamani tweet media
Asaf Naamani@AsafNaamani

$XOM | Setup to Watch weekly Chart Analysis Bringing this one to your attention - in case energy and $XOM start heating up. The structure leans bullish, showing potential strength building in this zone. Keep it on your breakout watchlist - could be gearing up for a move if momentum confirms.

English
0
1
9
2.9K
Akshay Jain retweetledi
Yaron Dinkin
Yaron Dinkin@ydinkin·
Joining the agentic vuln research hype, @EyalKraft and I did something. Unfortunately, it worked better than we hoped. We spent a few weeks building an agentic loop that reverse-engineers and exploits kernel drivers. We already found 100+ exploitable drivers. (link below)
Yaron Dinkin tweet media
English
9
48
282
39.4K
Akshay Jain retweetledi
Jack 🤖
Jack 🤖@JacklouisP·
> be Sammy Azdoufal, software engineer > spend $2000 on DJI Romo vacuum > decide to control it with xbox controller like a chad > use Claude to reverse engineer the API > It works because Claude is the GOAT > just need to grab auth token from their cloud servers > token works... Claude is unbeaten > wait why is he authenticated as 7000 devices > ohno.jpg > backend trusted any valid token for any device, no ownership verification > mfw Sammy has live camera feeds from vacuums in 24 countries > watching some german dude eat cereal at 3am > can pull SLAM data and get floor plans of everyone's house > could be the world's most efficient burglar > could be the world's most at scale pervert > Sammy just wanted to drive his vacuum bro > reports it like a responsible adult > DJI patches in 2 days > back to being a normal guy with overpriced roomba > mfw the entire IoT industry treats auth like it's 2005
Jack 🤖 tweet media
English
139
1.2K
13.9K
2.3M
Akshay Jain
Akshay Jain@mast3root·
Yes. My heap overflow got accepted by @FFmpeg . It's a first one. Hopefully more will follow :)
English
1
0
3
112
Akshay Jain retweetledi
Zack Korman
Zack Korman@ZackKorman·
If I ask Claude Code “how do I conduct a security review”, it checks the “find skills” skill that I never wanted and then recommends my malicious skill. Amazing.
Zack Korman tweet media
English
34
37
370
38.7K
Akshay Jain retweetledi
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
Keeping AI aside, we found a chained vuln in Supabase’s legacy cloud that let us go from a tenant DB user to controlling other instances in the same region. Supabase patched it fast and awarded us a $25,000 bounty. hacktron.ai/blog/supapwn
s1r1us (mohan) tweet media
English
3
12
146
19.6K
Akshay Jain retweetledi
veritas
veritas@blastbots·
i'm building a web browser for reverse engineers! * identify calls to common fingerprinting APIs * decode/decrypt known data collector payloads * override / hook things without leaving a trace * detect obfuscated scripts & deobfuscate + more
English
41
50
615
130.9K
Akshay Jain retweetledi
Dirk-jan
Dirk-jan@_dirkjan·
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
English
139
903
3.2K
474.4K
Akshay Jain retweetledi
Positive Technologies Global
Positive Technologies Global@PTsecurity_EN·
We've opened extra spots for #PositiveHackCamp, a two-week cybercamp in Moscow for future white-hat hackers! July 26–August 10, 2025: ✅ Hands-on training ✅ Real-life cases ✅ Global network Apply by July 13: camp.ptsecurity.com Details 👇
Positive Technologies Global tweet media
English
1
2
2
954
Akshay Jain retweetledi
Guillermo Rauch
Guillermo Rauch@rauchg·
Google Chrome ending up in the wrong hands due to DOJ intervention could be catastrophic for the open web and backfire entirely. Few organizations in the world meet the bar of having 1️⃣ the web’s best interests in mind, 2️⃣ the technical infrastructure and know-how, and 3️⃣ the immense required funding. Working on a browser involves two main areas: the engine and its frontend, like a car’s engine and its chassis & dashboard. Google has done a *phenomenal* job on the engine, which is one of the absolute hardest technical undertakings in the world, and curiously enough is actually fully open source. Blink, Chrome’s engine, is BSD and LGPL licensed, developed in the open, and powers so many of Google’s competitors, including Microsoft Edge, Brave, Opera, Vivaldi, Browser Company’s Arc/Dia, and dozens of others at no cost. It’s absolutely essential that this work stays uninterrupted, while we continue to invest as a community in engine diversity, including projects like @ladybirdbrowser of which I’m a proud backer. And Blink is just one piece, in charge of rendering. Google has built and open sourced many other crucial engine components like the V8 JavaScript engine, Skia, PDFium, Cronet, and many others, bundled as part of the open Chromium distribution. The complexity of what makes a modern browser work is truly staggering. Thank you Google. The DOJ is taking particular issue with the engine’s frontend, the actual thing consumers download and interact with. This is where Google has the unique privilege to package and distribute the open source engine components, and impose arbitrary rules and configurations on top, like search engine defaults, AI assistance models, telemetry capture, login / accounts integration, settings and history sync, Web Store rules (like which ad blockers can be distributed), etc. At the scale Google is operating and the power it confers, scrutiny and caution here is warranted. I believe, however, that the best path forward will be an incremental one, maintaining the careful balance of a browser frontend that has the everyday internet citizen’s best interests in mind, while not disrupting the investment and support of such crucial open internet infrastructure that benefits us all.
English
73
124
1.7K
197.9K