tkp

725 posts

tkp banner
tkp

tkp

@tkpsf

https://t.co/wbLisRKoBl / https://t.co/9EGN6OnFSE

San Francisco, CA Entrou em Temmuz 2017
1.1K Seguindo172 Seguidores
tkp
tkp@tkpsf·
@mikemo Caught about a 1/2 hour of it. The team concept is unique. How did the skaters feel about it? Using a spreadsheet with macros to update a locally running web application is something I've never seen before. Props on getting that to work.
English
1
0
11
251
Mike Mo
Mike Mo@mikemo·
All feedback is welcome after watching PSL. Any recommendations or thoughts?
English
61
2
126
18.5K
tkp
tkp@tkpsf·
Cross-site leaks are pretty neat.
English
0
0
0
72
tkp
tkp@tkpsf·
<script>alert('p0wd3r')</script>
tkp tweet mediatkp tweet media
English
0
0
0
71
tkp
tkp@tkpsf·
It's not perfect, or complete, but I built a site that archives some of California's public traffic camera photos and turns them into time lapses: roads.today There are some upcoming snow storms that will be fun to watch as they pass over the mountain passes.
English
0
0
0
77
tkp
tkp@tkpsf·
If my math is correct, that 29% increase converts to over 92 billion liquid US gallons (92,323,363,830) or 349 billion litres (349,481,948,380) of water added to the reservoir in 3 days.
English
0
0
0
47
tkp
tkp@tkpsf·
The Folsom, California reservoir capacity went from 34% capacity on December 29, 2022 to 63% capacity on January 1, 2023. Source: cdec.water.ca.gov/resapp/Rescond…
tkp tweet mediatkp tweet media
English
1
0
1
313
tkp
tkp@tkpsf·
@samwcyo Is it the victim's mobile that device that ends up sending an unlock signal to the car (such as over Bluetooth), therefore requiring the victim to be within a certain range? Or is the car actively listening for requests made to that API?
English
0
0
0
0
Sam Curry
Sam Curry@samwcyo·
After putting everything together, we reported the issue to Hyundai and worked with them to confirm the fix. Thanks for reading! This thread is a small part of a few months of web security research in the auto industry. We're hoping to disclose more related issues in the future.
English
8
8
351
0
Sam Curry
Sam Curry@samwcyo·
We recently found a vulnerability affecting Hyundai and Genesis vehicles where we could remotely control the locks, engine, horn, headlights, and trunk of vehicles made after 2012. To explain how it worked and how we found it, we have @_specters_ as our mock car thief:
Sam Curry tweet media
English
75
1.1K
4.7K
0
tkp
tkp@tkpsf·
Hello, it's been a while. I'm still digging into mobile and web apps for work, as well as exploring the world as much as possible.
tkp tweet mediatkp tweet mediatkp tweet media
English
1
0
4
0
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
@bhavukjain1 I was trying to bypass the ssl on Facebook apps. And I have tried all the public methods and didn't work. And yeah I gave up
English
2
0
2
0
Bhavuk Jain
Bhavuk Jain@bhavukjain1·
Too many fatal alerts to fix. Ssl unpinning is hard.
Bhavuk Jain tweet media
English
5
0
41
0
tkp
tkp@tkpsf·
@LeeAReynolds @JackRhysider Just started learning about Algo and the technology (and Turing Award winning cryptographer behind it @silviomicali ). Pretty neat stuff. Looking at developer options.
English
0
0
1
0
Jack Rhysider 🏴‍☠️
Jack Rhysider 🏴‍☠️@JackRhysider·
So the question is, what crypto currency uses 1% as much power as bitcoin?
English
80
8
234
0
tkp
tkp@tkpsf·
Using a mobile app that has a web app counterpart? Look at how a web app user can interact with a mobile app user, you just might find a vulnerability in the interaction.
English
0
0
2
0
tkp
tkp@tkpsf·
@doronz88 @campuscodi Nice, I was attempting with 13.2.3 on iPhone6 and 14.1 (jb iPhone 8 w/checkra1n, so no passcode which might be causing issues with iTunes trust). I'll have to experiment with 14.0 and 14.2
English
1
0
0
0
DoronZ
DoronZ@doronz88·
@tkpsf @campuscodi I checked it with iOS 14.0 and 14.2, so I'm guessing at least every 14.x. I haven't checked for this feature in other firmwares, So if you have on some others maybe reply as an issue and I'll add a list of tested devices?
English
1
0
0
0
tkp
tkp@tkpsf·
@sambowne :( Without CCSF and your classes I wouldn't have found my way into the career I'm in.
English
1
0
0
0
Sam Bowne
Sam Bowne@sambowne·
CCSF just sent Accusation notices to many instructors, whether they are actually being laid off or not. It's like working for the USSR: the cruelty is the point.
Sam Bowne tweet media
English
4
1
6
0
tkp
tkp@tkpsf·
I recently asked the question "Do you cover your cell phone cameras when not in use?" on my Instagram account. 6 people voted yes, 81 voted no.
English
0
0
0
0
tkp
tkp@tkpsf·
@sambowne wow, that is quite the adventure
English
0
0
0
0