Bypassing Certificate Pinning on Flutter-based Android Apps. A new guide.
One of the preliminary activities when analyzing mobile application, more usually than not, is to be able to sniff HTTP/S traffic via a MitM proxy. This is quite straightforward in the case of naive...
View ArticleSemgrep Rules for iOS Application Security (Swift)
Nowadays, millions of people rely on iOS mobile applications for almost everything. As a result iOS devices manage a significant amount of data including sensitive ones, such as: credentials, health...
View ArticleTesting the Security of Modbus Services
ICS and Building Management Systems (BMS) support several protocols such as Modbus, Bacnet, Fieldbus and so on. Those protocols were designed to provide read/write control over sensors and actuators...
View ArticleSemgrep Rules for Android Application Security
IntroductionThe number of Android applications has been growing rapidly in recent years. In 2022, there were over 3.55 millionAndroid apps available in the Google Play Store, and this number is...
View ArticleA Cool New Project: Semgrep Rules for Android Apps Security
In today's digital landscape, mobile application security has become an paramount concern. With the increasing number of threats targeting Android applications and the stored personal data, developers...
View Article20 years of Software Security: threats and defense strategies evolution
Software security has come a long way in the past two decades. With the advent of new technologies and a rapidly evolving threat landscape, defending against cyber attacks has become more challenging...
View ArticleOWASP Global AppSec Dublin 2023: WorldWide and Threat Modeling
The OWASP Global AppSec Dublin 2023 conference was a truly inspiring event for anyone involved in application security. As an attendee, I was able to catch up with OWASP colleagues and hear from...
View ArticleUN ECE 155 Threats in the real world: Wireless Networking Attacks and...
On March the 31st, I gave a quick talk on automotive security at VTM titled "UN ECE 155 Threats in the real world: Wireless Networking Attacks and Mitigations. A case study" (slides here).The idea was...
View ArticleThe Worst Log Injection. Ever. (Log4j [2.0.0-alpha,2.14.1] )
There has been such a hype about the Log4j issue and since IMQ Minded Security mission has always been about fixing, this informal post is about what's going on, how to check if someone's system is...
View ArticleA Journey Into the Beauty of DNSRebinding - Part 2
AbstractIn the first part, after a fast overview on the DNS Rebinding technique, we considered a practical example in which UPnP services has been exploited to perform NAT Injection attacks and,...
View ArticleMobile Screenshot Prevention Cheatsheet - Testing and Fixing
.post ul li { list-style: circle inside; margin-left: 20px; margin-bottom: 0px; font-size: 14px; } .post blockquote{ box-sizing border-box; color rgb(102, 102, 102); display inline; padding: 10px 10px...
View ArticleA Journey Into the Beauty of DNSRebinding - Part 1
AuthorsGiovanni GuidoAlessandro BraccioAbstractIn this first blog post about DNS rebindingtopic, we are going to show a practical example of DNS Rebinding attack against UPnP services exposed in a...
View ArticleDemystifying Web Cache Threats
AuthorsAlessandro BrucatoGiorgio RandoIntroduction Did you know the word “Cache” comes from French and means “Hidden”?If we transpose it to IT we can see why it has been named as such: It is because of...
View ArticleWAF Journey - Fixing Telerik UI Remote Code Execution via Arbitrary File Upload
IntroductionIt might occur that companies discover vulnerabilities on web application assets that were acquired by third party vendors. What happens if the asset is no longer supported/licensed and...
View ArticleMobile Screenshot prevention Cheat Sheet - Risks and Scenarios
Mobile Screenshot Prevention Cheat Sheet - Risks and ScenariosThe following article will try to analyze and explain risks and attack scenarios affecting mobile applications without any implemented...
View ArticleImplementing Secure Biometric Authentication on Mobile Applications
Nowadays, almost every mobile device has a biometric sensor that allows developers to implement local authentication and also store sensitive data securely through dedicated APIs. Biometric...
View ArticleBehave! A monitoring browser extension for pages acting as "bad boi".
Browsing: What Could Go Wrong?There's so much literature about client side attacks, but most of the focus is usually about classical malware attacks, exploiting software vulnerabilities.Malicious...
View ArticleRemote Working - Web Chats: Threats and countermeasures
IntroductionWith recent worldwide events, a sharply increasing number of companies are offering remote services to their customers. Even traditional businesses are implementing new features or pushing...
View ArticleOWASP SAMM v2: lessons learned after 9 years of assessment
OWASP SAMM v2 is out!OWASP SAMM (Software Assurance Maturity Model) is the OWASP framework to help organizations assess, formulate, and implement, through our self-assessment model, a strategy for...
View ArticleHow to Path Traversal with Burp Community Suite
IntroductionA well-known, never out of fashion and highly impact vulnerability is the Path Traversal. This technique is also known as dot-dot-slash attack (../) or as a directory traversal, and it...
View Article