R4T | ねずみ | Nezumi
834 posts

R4T | ねずみ | Nezumi
@ratilovich
RedTeam Operator | OSEP | OSCP | eCPTXv2 | CRTE | CRTP | RTO2 | Cyber Warfare | https://t.co/hOaGzR8H4X | Opinions Are Mine



X cannot read your messages. We back up your private keys to our hardware security modules (HSMs) to make recovering your message history on new devices frictionless. These HSMs were initialized in our published key ceremony: x.com/XEng/status/19… Your keys can only be recovered from the HSMs by entering your PIN correctly. The limit on the number of guesses for the PIN is set to 20 by default (this can be verified through the key fetch response and cannot be disabled after registration), after which the keys self-destruct, meaning no one at X can reliably brute force your PIN to recover your keys. We're always improving X Chat and aim to boost security even further without hurting the user experience on X. The goal of X Chat is to be the communication system for Earth. Privacy and usability are core. We offer end-to-end encrypted messages, with no ad hooks and no dependency on AWS like other messaging services. Enhanced privacy features such as opt-in self custody and forward secrecy are on our roadmap.









Today, the kidnappers used his phone, took this picture and uploaded it on his Facebook page. Please you people should beg @officialABAT to call them, like he called them personally for the release of others. What kinda Godforsaken excuse of a country is this!!!

How lack of rate-limiting can lead to an account takeover of this mobile app: > Get the victim’s email from any source. > Click on “Forgot Password.” > Paste the email. > The victim receives a 4-digit OTP that expires in 3-5 minutes. > Enter a random 4-digit OTP with a new password and capture the request. > Send the request to Intruder or FFUF. > Set the minimum and maximum length to 4 digits, that’s 9,999 possible attempts to guess the correct combination. > Less than 60 seconds later: Password reset successful! > Use the victim’s email and new password to log in. > Congratulations! Account Takeover. Recommendation: - Implement proper rate limiting and throttling - Do not use 4 digits as a reset Pin, it should be >=6 with a mix of numbers and alphabets. - Ensure OTP expires on time. You’re welcome.
















