How I Uncovered an LFI in 15 Seconds: The Tale of a Curious Hacker and an Unprepared Server
👋 Hi there! I’m Shyam — a security researcher with a knack for finding vulnerabilities faster than your coffee gets cold. Today, I’m…Continue reading on Medium »
Read more...
👋 Hi there! I’m Shyam — a security researcher with a knack for finding vulnerabilities faster than your coffee gets cold. Today, I’m…Continue reading on Medium »
Read more...
Medium
How I Uncovered an LFI in 15 Seconds: The Tale of a Curious Hacker and an Unprepared Server 🐞
👋 Hi there! I’m Shyam — a security researcher with a knack for finding vulnerabilities faster than your coffee gets cold. Today, I’m…
Anyone know how I can pull Rayban Meta firmware for static analysis?
https://www.reddit.com/r/Pentesting/comments/1hsfkpi/anyone_know_how_i_can_pull_rayban_meta_firmware/
https://www.reddit.com/r/Pentesting/comments/1hsfkpi/anyone_know_how_i_can_pull_rayban_meta_firmware/
<!-- SC_OFF -->Watched a few teardowns, I'm assuming the cases USBC is strictly power without data and everything is done completely over WiFi/BLE - unless you want to tear it down. (Although it has a large PCB for just charging, nothings touches on the PCB for the case) I plan to run WireShark and nRF Scanner to see what I can find but wondering if anyone has some solid tips or has seen any good articles on this? I can't even find posts of people talking about the firmware. It uses a Snapdragon AR1 CPU and 32gb of flash memory. Good to know specs: https://www.qualcomm.com/products/mobile/snapdragon/xr-vr-ar/snapdragon-ar1-gen-1-platform Snapdragon AR1 Gen 1 – Key Specs CPU & Process Advanced process node (Qualcomm hasn’t publicly disclosed exact nm). Designed for low-power “always-on” smart glasses applications. AI / NPU 3rd Gen Qualcomm® Hexagon™ NPU Handles on-device AI (visual search, translation, voice assistance). Camera / ISP Dual ISPs (supports up to 12MP photos and 6MP video capture per camera). Display Support Binocular or single-lens display Up to 1280×1280 @ 60 fps (3DoF) Connectivity Qualcomm® FastConnect™ with support for Wi-Fi 7 Bluetooth® 5.3 / 5.2 Audio Up to 8 microphones Qualcomm® Noise & Echo Cancellation, AI-based targeted capture Power & Thermals Optimized for lightweight eyewear Low-power design for “always-on” capabilities Ray-Ban Meta (Gen 2) – Key Specs SoC Uses a custom variant of Snapdragon AR1 Gen 1 (as widely reported). Cameras Dual 12MP cameras (up from 5MP in Gen 1). Supports 1080p video at 60 fps. Onboard Storage 32GB flash storage for photos, videos, and firmware. <!-- SC_ON --> submitted by /u/Austinitered (https://www.reddit.com/user/Austinitered)
[link] (https://www.reddit.com/gallery/1hsfkpi) [comments] (https://www.reddit.com/r/Pentesting/comments/1hsfkpi/anyone_know_how_i_can_pull_rayban_meta_firmware/)
[link] (https://www.reddit.com/gallery/1hsfkpi) [comments] (https://www.reddit.com/r/Pentesting/comments/1hsfkpi/anyone_know_how_i_can_pull_rayban_meta_firmware/)
P4 Bugs and POC | Part 1: Broken Link HijackingContinue reading on Medium » (https://medium.com/@kumawatabhijeet2002/p4-bugs-and-poc-part-1-0dab3517bbe9?source=rss------bug_bounty-5)
PDF.js Arbitrary JavaScript Code Execution (CVE-2024-4367)
Hello everyone, Today we’re going to look at CVE-2024–4367, a serious vulnerability in PDF.js that allows attackers to run arbitrary…Continue reading on InfoSec Write-ups »
Read more...
Hello everyone, Today we’re going to look at CVE-2024–4367, a serious vulnerability in PDF.js that allows attackers to run arbitrary…Continue reading on InfoSec Write-ups »
Read more...
Medium
PDF.js Arbitrary JavaScript Code Execution (CVE-2024-4367)
Hello everyone, Today we’re going to look at CVE-2024–4367, a serious vulnerability in PDF.js that allows attackers to run arbitrary…
PDF.js Arbitrary JavaScript Code Execution (CVE-2024-4367)
Hello everyone, Today we’re going to look at CVE-2024–4367, a serious vulnerability in PDF.js that allows attackers to run arbitrary…Continue reading on InfoSec Write-ups »
Read more...
Hello everyone, Today we’re going to look at CVE-2024–4367, a serious vulnerability in PDF.js that allows attackers to run arbitrary…Continue reading on InfoSec Write-ups »
Read more...
Medium
PDF.js Arbitrary JavaScript Code Execution (CVE-2024-4367)
Hello everyone, Today we’re going to look at CVE-2024–4367, a serious vulnerability in PDF.js that allows attackers to run arbitrary…
Here’s 24 web-application hacking tools:
Burp Suite — Framework.Continue reading on Medium »
Read more...
Burp Suite — Framework.Continue reading on Medium »
Read more...
Medium
Here’s 24 web-application hacking tools:
Burp Suite — Framework.
What is a Hacker?
What comes to mind when you hear the word “hacker”? A cybercriminal? A tech geek? Someone cool? A genius?Continue reading on Medium »
Read more...
What comes to mind when you hear the word “hacker”? A cybercriminal? A tech geek? Someone cool? A genius?Continue reading on Medium »
Read more...
Medium
What is a Hacker?
What comes to mind when you hear the word “hacker”? A cybercriminal? A tech geek? Someone cool? A genius?
PDF.js Arbitrary JavaScript Code Execution (CVE-2024-4367)
https://infosecwriteups.com/pdf-js-arbitrary-javascript-code-execution-cve-2024-4367-be4a64f877df?source=rss------bug_bounty-5
https://infosecwriteups.com/pdf-js-arbitrary-javascript-code-execution-cve-2024-4367-be4a64f877df?source=rss------bug_bounty-5
Hello everyone, Today we’re going to look at CVE-2024–4367, a serious vulnerability in PDF.js that allows attackers to run arbitrary…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/pdf-js-arbitrary-javascript-code-execution-cve-2024-4367-be4a64f877df?source=rss------bug_bounty-5)
My First RCE Vulnerability
https://medium.com/@RekoJR/my-first-rce-vulnerability-636cdc9f2dab?source=rss------bug_bounty-5
Who Am i ?Continue reading on Medium » (https://medium.com/@RekoJR/my-first-rce-vulnerability-636cdc9f2dab?source=rss------bug_bounty-5)
https://medium.com/@RekoJR/my-first-rce-vulnerability-636cdc9f2dab?source=rss------bug_bounty-5
Who Am i ?Continue reading on Medium » (https://medium.com/@RekoJR/my-first-rce-vulnerability-636cdc9f2dab?source=rss------bug_bounty-5)
Here’s 24 web-application hacking tools:
https://saconychukwu.medium.com/heres-24-web-application-hacking-tools-17369f7f5097?source=rss------bug_bounty-5
Burp Suite — Framework.Continue reading on Medium » (https://saconychukwu.medium.com/heres-24-web-application-hacking-tools-17369f7f5097?source=rss------bug_bounty-5)
https://saconychukwu.medium.com/heres-24-web-application-hacking-tools-17369f7f5097?source=rss------bug_bounty-5
Burp Suite — Framework.Continue reading on Medium » (https://saconychukwu.medium.com/heres-24-web-application-hacking-tools-17369f7f5097?source=rss------bug_bounty-5)
What comes to mind when you hear the word “hacker”? A cybercriminal? A tech geek? Someone cool? A genius?Continue reading on Medium » (https://hackers-guild-blog.medium.com/what-is-a-hacker-c957e390855b?source=rss------bug_bounty-5)
MFA Bypass Exposed: A C Flaw in Two-Factor Authentication
Hello fellow hackers! I hope this year brings everyone the success and opportunities they’ve been working towards. May it be a year filled…Continue reading on Medium »
Read more...
Hello fellow hackers! I hope this year brings everyone the success and opportunities they’ve been working towards. May it be a year filled…Continue reading on Medium »
Read more...
Medium
Step 1: Initial Exploration
Hello fellow hackers! I hope this year brings everyone the success and opportunities they’ve been working towards. May it be a year filled…
MFA Bypass Exposed: A C Flaw in Two-Factor Authentication
https://medium.com/@swaroopvenkat828/mfa-bypass-exposed-a-c-flaw-in-two-factor-authentication-6e126b1cfbd0?source=rss------bug_bounty-5
https://medium.com/@swaroopvenkat828/mfa-bypass-exposed-a-c-flaw-in-two-factor-authentication-6e126b1cfbd0?source=rss------bug_bounty-5