Favour Idowu | cracker 🎭

1.8K posts

Favour Idowu | cracker 🎭 banner
Favour Idowu | cracker 🎭

Favour Idowu | cracker 🎭

@favour_eng

A Creative Software Engineer 😵‍💫| Penetration tester | Dreaming Big - Taking actions | Building https://t.co/Ryxqohniau

@Space شامل ہوئے Haziran 2023
1.1K فالونگ312 فالوورز
پن کیا گیا ٹویٹ
Favour Idowu | cracker 🎭
Favour Idowu | cracker 🎭@favour_eng·
I build Scalable web based Applications for founders and businesses What do you do?
Favour Idowu | cracker 🎭 tweet media
English
0
0
3
312
Kath Korevec
Kath Korevec@simpsoka·
Gm. It’s my birthday today. Taking the day to enjoy this. Hope y’all have a good day!!
Kath Korevec tweet media
English
83
0
358
14.9K
Framer
Framer@framer·
Who needs some followers? Drop your @framer community profile below so everyone knows who you are!
English
406
12
252
18.5K
Favour Idowu | cracker 🎭 ری ٹویٹ کیا
Favour Idowu | cracker 🎭
Favour Idowu | cracker 🎭@favour_eng·
I'm tired of getting 3 likes man. I need brothers and sisters in tech, AI, startups, marketing, distribution, vibecoding to come to my rescue. Let's connect
English
1
1
1
43
Favour Idowu | cracker 🎭 ری ٹویٹ کیا
Favour Idowu | cracker 🎭
Bro, Confidence is almost everything, You might be smart but the person with confidence will win you always…
English
0
1
1
20
Favour Idowu | cracker 🎭 ری ٹویٹ کیا
Favour Idowu | cracker 🎭
If you are certain that, a day would come where millions would use your Solutions. Quote this with what you are building. #connect.
English
0
1
2
30
Favour Idowu | cracker 🎭
Now AI can build and ship features in few seconds, It’s really hard to keep things simple,
English
0
1
1
9
Katie Paxton-Fear
Katie Paxton-Fear@InsiderPhD·
You’ll never guess what my favourite display technology is
Katie Paxton-Fear tweet media
English
13
0
35
3K
Marques Brownlee
Marques Brownlee@MKBHD·
NEW VIDEO - Adding a touchscreen to the Macbook Pro to feel what it would be like when the rumored Ultra finally does come out: youtu.be/WOzcFkld6_g
YouTube video
YouTube
Marques Brownlee tweet media
English
52
73
2.6K
197.9K
Elon Musk
Elon Musk@elonmusk·
It is humbling to consider that if we harness just 1 millionth of the Sun’s power for AI, that will be much more than a million times the intelligence of all of humanity
English
15K
17.5K
205.7K
28M
Chisom Nwokwu🌟
Chisom Nwokwu🌟@tech_queen·
SpaceX is acquiring Cursor for $60B🤯
English
3
4
38
2.7K
Favour Idowu | cracker 🎭
Spent way longer than I’d like to admit debugging a CORS error on Pyramid School’s backend. Turns out it wasn’t Flask at all, it was how Vercel was proxying requests to Render. Fixed now. Onward 🚀
English
0
0
0
10
Favour Idowu | cracker 🎭 ری ٹویٹ کیا
Abdulkadir | Cybersecurity
Every developer has written something like this at least once. Here is why it should never reach production. 1. No authentication or token verification This is the most critical one. Anyone who knows or guesses a valid email address can reset that user’s password to anything they want. There is no reset token, no email verification step, no proof that the person making the request actually owns the account. You just send an email and a new password in a POST request and you own the account. That is not a password reset flow. That is an account takeover endpoint. 2. Password stored in plaintext The newPassword value goes directly into db.updatePassword with zero processing. No hashing. No salting. The password lands in the database exactly as the user typed it. If that database is ever breached, every single user’s password is immediately readable in plain text. 3. No input validation There is no check on what newPassword actually contains. Empty string, a single character, null, a 10,000 character payload. All of it goes straight to the database. No length requirements, no complexity checks, nothing. 4. No rate limiting This endpoint accepts unlimited requests with no throttling or lockout mechanism. Combine this with vulnerability one and you have an endpoint that can be automated to take over accounts at scale. 5. User enumeration The endpoint only responds when a user exists. Silence on a non-existent email tells an attacker exactly which addresses are registered accounts. That information has real value in targeted attacks. Five vulnerabilities. Twelve lines of code. This is what happens when security is an afterthought.
Exploit-Forge@ExploitforgeLTD

How many vulnerabilities can you spot in this code?

English
2
5
22
41.8K