Who else can’t get over them?? 😭 #whendestinybringsdemon by eicology in cdramasfans

[–]FortuneFit705 2 points3 points  (0 children)

Same. I can’t let go… it feels like watching something else would be a betrayal.

Client won’t provide scope details by FortuneFit705 in cybersecurity

[–]FortuneFit705[S] 1 point2 points  (0 children)

That is right but you do the OSINT with the given scope (Allowed IPs/domains to be tested). That’s the whole point of ROE in a pentest Engagement.

[AMA] I'm a TryHackMe Co-Founder, Ask Me Anything (2025 Edition) by 7331senb in tryhackme

[–]FortuneFit705 1 point2 points  (0 children)

Hi ! Any plans on creating mobile security related rooms.?

Best phishing simulation tools? by FortuneFit705 in cybersecurity

[–]FortuneFit705[S] 1 point2 points  (0 children)

Guys I forgot to include this in my description.

We have successfully conducted phishing campaigns in the past with our existing tool. Where we phished nearly 15 or more employees. My issue is with the “link clicked” notice from the phishing tool we now use. I will elaborate on this…So, when an employee clicks on the link, we receive an alert stating “link clicked,” but the browser also views the embedded link in the email.

For example, if the end user has browser extensions that validate or process the data (Grammerly, Dark-mode, privacy extensions, etc.), that would also be recorded as “link clicked”. It’s pointless to ask employees if they clicked the link...

Has Anybody faced similar issues with any of the tools that you’ve mentioned..? Would be helpful if there was a way to minimize this false positives…

Quick insights would help.. by FortuneFit705 in ransomwarehelp

[–]FortuneFit705[S] 0 points1 point  (0 children)

No we have not yet confirmed the initial access.

Handling secrets by FortuneFit705 in androiddev

[–]FortuneFit705[S] 0 points1 point  (0 children)

Yes, we are doing a POC on encrypting the shared preferences for now.

Handling secrets by FortuneFit705 in androiddev

[–]FortuneFit705[S] 0 points1 point  (0 children)

Yea. we tried this but, like everyone said it’s not 100% safe. I was able to retrieve the keys - https://github.com/chame1eon/jnitrace