Federico Dotta (@apps3c) 's Twitter Profile
Federico Dotta

@apps3c

@[email protected]

ID: 407649896

linkhttps://www.apps3c.info/ calendar_today08-11-2011 10:35:50

231 Tweet

1,1K Followers

90 Following

HN Security (@hnsec) 's Twitter Profile Photo

We just published “Nothing new under the Sun – Discovering and exploiting a CDE bug chain”, a new article by our [email protected]. He chains a printer name injection bug in dtprintinfo and a stack bof in libXm to achieve LPE to root on a fully-patched Solaris 10. security.humanativaspa.it/nothing-new-un…

Federico Dotta (@apps3c) 's Twitter Profile Photo

Fourth article of the series "Extending Burp Suite for fun and profit - The Montoya way" is out! Topic: creating new tabs for processing HTTP requests and responses! security.humanativaspa.it/extending-burp…

Federico Dotta (@apps3c) 's Twitter Profile Photo

A quick overview and some tips on how to handle and exploit Java applets and serialized Java objects in the present day using Burp Suite. security.humanativaspa.it/java-applet-se…

bugcrowd (@bugcrowd) 's Twitter Profile Photo

Katie Paxton-Fear 4. Brida, Burp to Frida bridge Bridges Burp and Frida, enabling traffic manipulation across multiple platforms. Simplifies mobile testing with direct function usage for data encryption/decryption, offering custom plugins, tabs, menu options and more. portswigger.net/bappstore/2c0d…

Federico Dotta (@apps3c) 's Twitter Profile Photo

Fifth article of the series "Extending Burp Suite for fun and profit - The Montoya way" is out! Topic: adding new functionalities to the context menu! security.humanativaspa.it/extending-burp…

Federico Dotta (@apps3c) 's Twitter Profile Photo

Sixth article of the series "Extending Burp Suite for fun and profit - The Montoya way" is out! Topic: adding new checks to Burp Suite Active and Passive Scanner! security.humanativaspa.it/extending-burp…

James Kettle (@albinowax) 's Twitter Profile Photo

Display responses that came from a server-side cache (Varnish/Cloudfront) with this filter bambda: return requestResponse.response().headerValue("X-Cache").toLowerCase().contains("hit");

Federico Dotta (@apps3c) 's Twitter Profile Photo

Seventh article of the series "Extending Burp Suite for fun and profit - The Montoya way" is out! Topic: using the Collaborator in Burp Suite plugins! security.humanativaspa.it/extending-burp…

Federico Dotta (@apps3c) 's Twitter Profile Photo

Eighth article of the series "Extending Burp Suite for fun and profit - The Montoya way" is out! Topic: BChecks - A quick way to extend Burp Suite Active and Passive Scanner! security.humanativaspa.it/extending-burp…

HN Security (@hnsec) 's Twitter Profile Photo

The unattainable unicorn in fault injection! Our latest article reveals that single-bit faults are possible on ESP32. Discover how some bits are easier to flip and why lowest voltage isn't always best. Join inode in his #hardwarehacking quest. security.humanativaspa.it/fault-injectio…

Federico Dotta (@apps3c) 's Twitter Profile Photo

A few notes and examples on a topic I've been exploring recently: AI red teaming on LLM-based applications! security.humanativaspa.it/attacking-gena…