Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Apple, Google Both Track Mobile Telemetry Data, Despite Users Opting Out

https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Apple, Google Both Track Mobile Telemetry Data, Despite Users Opting OutPost Views: 42
style="display:block"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="8337846400"
data-ad-format="auto"
data-full-width-responsive="true">
Reading Time: 1 Minute
Mobile device-tracking by Apple and Google take center stage in a report revealing that, despite both allowing users to opt out of sharing telemetry data – they do anyway.
“Both iOS and Google Android transmit telemetry, despite the user explicitly opting out of this,” wrote researcher Douglas Leith from Trinity College in Ireland, in a recently published academic report.

The research, entitled Mobile Handset Privacy: Measuring The Data iOS and Android Send to Apple And Google (PDF), also found that Google collects up to 20 times more data from its Android Pixel users compared to the amount of data that Apple collects from iOS users.

“The phone IMEI, hardware serial number, SIM serial number and IMSI, handset phone number etc. are shared with Apple and Google,” according to the report. “When a SIM is inserted, both iOS and Google Android send details to Apple/Google. iOS sends the MAC addresses of nearby devices, e.g. other handsets and the home gateway, to Apple, together with their GPS location. Currently there are few, if any, realistic options for preventing this data sharing.” Data Collected & Shared with Apple, GoogleParameters of the testing did not include pre-installed apps baked into the manufacturers’ mobile operating system, or third-party apps. Rather, research focused on data collected by OS-level handset components and functions, such as Apple’s Bluetooth UniqueChipID, Secure Element ID and the transmission of the devices’ Wi-Fi MAC addresses.

“Google collects a notably larger volume of handset data than Apple,” Leith wrote. “During the first 10 minutes of startup, the Pixel handset sends around 1MB of data to Google, compared with the iPhone sending around 42KB of data to Apple. When the handsets are sitting idle, the Pixel sends roughly 1MB of data to Google every 12 hours, compared with the iPhone sending 52KB to Apple — i.e., Google collects around 20 times more handset data than Apple.”

He noted that the operating systems connect to their back-end servers on average every 4.5 minutes, whether they’re in use or not.

On an informal basis, Leith did examine a number of the pre-installed apps and services, specific to the phone manufacturers. He noted that they also make network connections, despite never having been opened or used.
See Also: Malicious Docker Cryptomining Images Rack Up 20M Downloads
“In particular, on iOS these include Siri, Safari and iCloud; and on Google Android these include the YouTube app, Chrome, Google Docs, Safetyhub, Google Messaging, the Clock and the Google SearchBar,” he said. Apple, Google Dispute ResearchWhen Leith reached out to both Apple and Google to comment on his research he received mixed results.

“To date, Apple have responded only with silence (we sent three emails to Apple’s director of user privacy, who declined even to acknowledge receipt of an email,” Leith wrote. Since then, Apple has made public statements critical of Leith’s research and insisting privacy and opt-out measures do exist.

“Google responded with a number of comments and clarifications,” he wrote. “They also say that they intend to publish public documentation on the telemetry data that they collect.”

In a statement to the numerous publi[...]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Can I make a server think I uploaded a file earlier than I actually did?

Is it possible to do what the title says?

The website I'm talking about uses jQuery and AJAX in the front-end and PHP in the back-end. When I upload a file through a simple HTML form it gets sent to the server and then the page refreshes displaying the time I uploaded the file.

Screenshots:
https://imgur.com/a/L47dOTW
https://imgur.com/a/TNJItKR

Is there any way I can make the server think the file was uploaded earlier?

Thanks.

submitted by /u/PaterTheofilos
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Yemek Sepeti ve Veri İhlali

https://cdn-images-1.medium.com/max/600/1*ClJ-_KEB_Qn4ReqmHIaJZQ.jpeg
Bu yazıda Kişisel Verileri Koruma Kurumunun veri ihlali hakkında verdiği bazı kararlarla Yemek Sepeti veri ihlali bildirimini…

Continue reading on Medium »
Intigriti — XSS Challenge 0321

XSS with CSRF Bypass
Read more...
Facebook Push Notification Linkshim Bypassed

I’m glad you’re here. Please have fun reading (@nmochea).
Read more...
hacking: security in practice
view blurred images?

I am curious if there is a technique I can use to view blurred images on for example this site.

You have to pay them to see certain images. I am very grateful for some insight!

This is what I get when I inspect it on chrome developer console:





<svg<use
Unlock My Album

5 Credits for 90 days




submitted by /u/_User2020
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Find Default Misconfigurations and Insecure Files With “Spaghetti”

https://cdn-images-1.medium.com/max/2600/1*OcXO5wPUhEVkfwiE5EEmxw.jpeg
Spaghetti is a web-app security scanner software. It is intended to discover different default and insecure documents, configurations, and…

Continue reading on Medium »