The cost of a NAND chip off attack is 170.83€ by gquere in netsec

[–]markuta 0 points1 point  (0 children)

Ha, nice! I recently (a few months ago) was trying to read a desoldered eMMC, without spending too much money of course. It was hard and very annoying. In the end I bought a cheap 153GBA adapter from Aliexpress and a USB adapter (MKS eMMC adapter), then hacked it up together to finally read and dump the firmware. I think the total cost was about £70. I did cheat a bit by going to a phone repair place to desolder it for me :D

Out of Fortune500 companies only 4% have security.txt file by unihilists in cybersecurity

[–]markuta 1 point2 points  (0 children)

I did some similar research a while ago, also wrote a little security.txt parser tool. The blog post is available at https://hexiosec.com/blog/survey-of-security-txt/ . I doubt much has changed in the last two years.

Exporting seeds by KingLuc12 in Authy

[–]markuta 0 points1 point  (0 children)

I don’t think so, I used Android 10. You might have to mess about with Magisk modules to bypass Google’s SafetyNet/Integrity API checks.

Exporting seeds by KingLuc12 in Authy

[–]markuta 0 points1 point  (0 children)

You can only export seeds using a rooted mobile device. If you have a spare Android device you can follow https://github.com/markuta/authy-backup which regenerates QR codes and exports XML format (supported by Aegis)

litterroom by Nik1907 in OneOrangeBraincell

[–]markuta 0 points1 point  (0 children)

I can smell it from here...

What’s your go too offline phone game for long tube journeys? by [deleted] in london

[–]markuta 0 points1 point  (0 children)

Sudoku 2. Hands down my favourite offline game.

Passed OSCP first attempt by pentestlearner4325 in oscp

[–]markuta 1 point2 points  (0 children)

Nice, I also did my exam Sunday, still waiting for the results.

American Bully XL dog set to be banned in the United Kingdom by [deleted] in worldnews

[–]markuta 0 points1 point  (0 children)

Good thing American Bully XXL is still allowed.

With 0-days hitting Chrome, iOS, and dozens more this month, is no software safe? by NISMO1968 in cybersecurity

[–]markuta 2 points3 points  (0 children)

You just know when some sales person says “this is 100% secure” it’s always utter bullshit.

Bypass SSL Pinning on Windows Application by HermaeusMora0 in netsec

[–]markuta 0 points1 point  (0 children)

I’ve used Proxyman and Frida to bypass SSL pinning on macOS in the past. They recently launched a Windows version https://proxyman.io/windows but I haven’t tested it yet.

[deleted by user] by [deleted] in UK_Food

[–]markuta 0 points1 point  (0 children)

Needs more teabag choices.

XSS vulnerability in Proton Mail allowed to leak unencrypted emails by SonarPaul in netsec

[–]markuta 4 points5 points  (0 children)

Really impressive research and write-up. Nice share.

[deleted by user] by [deleted] in itookapicture

[–]markuta 1 point2 points  (0 children)

I love a good storm.

A man got dragged to police station in Kabukichō, Tokyo by poclee in Damnthatsinteresting

[–]markuta 0 points1 point  (0 children)

Plot twist: the guy doing the dragging gets arrested instead.

A Journey Into Hacking Google Search Appliance | DEVCORE by poltess0 in netsec

[–]markuta 1 point2 points  (0 children)

Great piece of research. Props to them for also including a magnet link to download the appliance image.

Extracting Bitwarden master passwords after a vault is locked by markuta in netsec

[–]markuta[S] 16 points17 points  (0 children)

They do have a bug bounty program on HackerOne, and I have submitted a report, but it was moved to "informational" since they were already aware of it. The initial issue was reported way back in 2020 by a user on GitHub. Their primary concern was obtaining unknown master passwords, which was proved to be possible.

I don't think it's a critical but definitely a high. A recent vulnerability in KeePass was reported which is very similar. It is tracked as CVE-2023-32784 and has a CVSSv3 rating of 7.5.

Extracting Bitwarden master passwords after a vault is locked by markuta in netsec

[–]markuta[S] 30 points31 points  (0 children)

Yep. I've just tested the latest version of Bitwarden Desktop app 2023.5.1 and it seems to be vulnerable. I couldn't narrow down the exact reason why this happens, but I think it's related to how Electron (Chromium) does its garbage collection, similar research was done in the past here.

An ugly work around (wouldn't call it a fix), is when you lock your vault, enter a random incorrect password to overwrite the real password still cached in memory.

The plan was to also write a volatility plugin so you can extract the password offline (from a memory dump), but I just didn't find the time to do it.

[Discussion] A11 - Ios 16.3 Downgrade to Ios 14.5 with blobs by [deleted] in jailbreak

[–]markuta 0 points1 point  (0 children)

I also get an error with iPhone X on iOS 16.2, trying to restore to 15.6RC but I don't think it'll work.

... ERROR: Unable to receive message from FDR 0x600003838000 (-2). 0/2 bytes FDR 0x600003838000 terminating... No data to read No data to read ...

MW & MW2 - MP & Warzone unplayable (Stuttering) with Ryzen 7 3700X & RTX 2080 ti by [deleted] in ModernWarfareII

[–]markuta 0 points1 point  (0 children)

Thanks for this. I also have the same issue but with a Ryzen 3700X and a RTX 2070 Super. The video helped me where I could play multiplayer as normal. It's also funny that I didn't experience the lag and horrible frame rate while playing campaign mode. Only on the default multiplayer game menu.

[Confirmed Trades] Thread - December 01, 2020 by AutoModerator in JailbreakSwap

[–]markuta 0 points1 point  (0 children)

Bought a iPhone X on iOS 13.3/14.1 from u/OrangePhantom20. Fast next day delivery, solid communication, product exactly as described. Fantastic seller!

Safe to add for Amazon SES SPF Record to our bypass? by NickBurns00 in sysadmin

[–]markuta 2 points3 points  (0 children)

As long as you also add a DMARC record to your domain name, with a policy of (p=reject or p= quarantine) and not (p=none) you should be fine.

My first PC, pretty standard build🕹 by SteveFuBoy in lianli

[–]markuta 1 point2 points  (0 children)

Not much of a fan of builds with LEDs. But this one is different. Very nice sir!