SecJS's profile picture. Security Researcher

SecJS

@SecJS

Security Researcher

SecJS repostou

Happy New Year 2025🎉🎉 Elevate your mobile security expertise with FatalSec! Our YouTube channel is your ultimate resource for hands-on experience in mobile security. Explore latest videos on the channel: youtube.com/@fatalsec #MobileSecurity #AndroidSecurity #iOSSecurity


SecJS repostou

🎁"Happy National #OSINT Day!" Here's a little gift for you. ❓Did you know that hidden inside public Snapchat profile pages are the exact dates and times when the accounts were created and last modified? 🛠We added our "Snapchat User ID Bookmarklet" to tools.myosint.training

myosinttrainer's tweet image. 🎁"Happy National #OSINT Day!" Here's a little gift for you.

❓Did you know that hidden inside public Snapchat profile pages are the exact dates and times when the accounts were created and last modified? 

🛠We added our "Snapchat User ID Bookmarklet" to tools.myosint.training

SecJS repostou

رائع 👏 : موقع رهيب للتدرب على ثغرة الـXSS بمستويات مختلفة 👌: xss.pwnfunction.com


SecJS repostou

Account Hijacking Featuring OAuth and JavaScript | IWCON-W22 Talk by Youssef Sammouda TBH a very good presentation about OAuth misconfigurations and its bypasses to get zero Click ATO youtube.com/watch?v=spxnd4…

MiniMjStar's tweet card. Account Hijacking Featuring OAuth and JavaScript | IWCON-W22 Talk by...

youtube.com

YouTube

Account Hijacking Featuring OAuth and JavaScript | IWCON-W22 Talk by...


SecJS repostou

Generic fixed postMessage XSS on OKX cryptocurrency exchange youtu.be/Se463wvub64

ndevtk's tweet card. Fixed postMessage XSS on okx.com

youtube.com

YouTube

Fixed postMessage XSS on okx.com


SecJS repostou

Bypassing Source Check on postMessage to Achieve XSS🔥 by:@elmehdimee elmahdi4.wordpress.com/2025/02/23/exp…


SecJS repostou

I almost can't believe it, but I am finally releasing my Gitbook about CTF and Hacking, which is a year in the making. It contains many tricks, explanations, and resources from my experience and research. I hope it becomes a valuable resource for everyone! book.jorianwoltjer.com//


SecJS repostou

Full Account takeover in Microsoft via Client-side Attack in Login Flow New detailed writeup + Full PoC video. I hope you enjoy reading! melotover.medium.com/escalating-imp… #BugBounty #bugbountytips #infosec

Melotover's tweet image. Full Account takeover in Microsoft via Client-side Attack in Login Flow 

New detailed writeup + Full PoC video. I hope you enjoy reading!
melotover.medium.com/escalating-imp…

#BugBounty #bugbountytips #infosec

SecJS repostou

New Tool : Youtube Comment History You can now search all comments a user has wrote on Youtube (See replies for video example) 20 Billions comments recorded so far (ranging from 2005-2025) from 1.4 Billion different users found. youtube-tools.lolarchiver.com This is my most ambitious…


SecJS repostou

New Blog Post: Disclosing "PermissionJacking," a Safari bug that lets websites trick you into giving camera, mic, gps... access. After a lengthy back-and-forth, Apple's decision is that this is not a security issue, I disagree. Includes new attack vector github.com/RenwaX23/X/blo…


SecJS repostou

I hope everyone is having an amazing day :) I see a lot of interest in our new platform wayhack.sh which is great! Can I please kindly request everyone who is interested in trying out the platform to DM us over at: ✍️x.com/wayhacksh


SecJS repostou

Sometimes, SQL injection is still possible, even when prepared statements are being used. Our researcher @hash_kitten has written up a blog post about a novel technique for SQL Injection in PDO’s prepared statements: slcyber.io/assetnote-secu…

slcyber.io

Novel SQL Injection Technique in PDO Prepared Statements

Searchlight Cyber's Security Research team details a Novel Technique for SQL Injection in PDO's Prepared Statements.


SecJS repostou

In security, people talk about complex hacks in theory, but where can you legally practice them? We got tired of the gap between theory and practice. So, we built the practice ground ourselves, the same way we learned. Our free, hands-on CTF labs for Android, iOS & ARM hacking…


SecJS repostou

Facebook page admin and email disclosure philippeharewood.com/page-admin-and…


SecJS repostou

Want to master client-side bugs? 😎 Check out this extensive GitHub repository with tens of different resources curated by @zomasec! 🔗 github.com/zomasec/client…

intigriti's tweet image. Want to master client-side bugs? 😎

Check out this extensive GitHub repository with tens of different resources curated by @zomasec!

🔗 github.com/zomasec/client…

SecJS repostou

This is really nice research! karmainsecurity.com/dont-call-that…


United States Tendências

Loading...

Something went wrong.


Something went wrong.