Taher Barodawala (@tahersb) 's Twitter Profile
Taher Barodawala

@tahersb

Security engineer and always a student | Geek | Product Security @ VMware | Mostly RTs
infosec(dot)exchange/@tahersb

ID: 85590189

linkhttps://awesomesec.com/ calendar_today27-10-2009 15:18:28

763 Tweet

96 Followers

920 Following

Anthony Randazzo (@amrandazz) 's Twitter Profile Photo

Mapped all of the Amazon GuardDuty Findings to ATT&CK. A bit more of an art than a science. Hopefully useful to some detection and response teams out there. See 🧵for more detail 👇

Mapped all of the Amazon GuardDuty Findings to <a href="/MITREattack/">ATT&CK</a>. A bit more of an art than a science. Hopefully useful to some detection and response teams out there. See 🧵for more detail 👇
Check Point Research (@_cpresearch_) 's Twitter Profile Photo

Gamers Beware We recently turned our eyes to a major networking library used by a sizeable chunk of online gaming - Valve’s "Steam Sockets". Here is our report on the library, and the vulnerabilities we found in it. research.checkpoint.com/2020/game-on-f…

Renzon (@r3nzsec) 's Twitter Profile Photo

Sharing this mindmap I personally created months ago when I was studying memory forensics. These are all publicly available on the volatility GitHub page but I find it very useful for mapping the plugins and their usage. #dfir #incidentresponse #memoryforensics #infosec

Sharing this mindmap I personally created months ago when I was studying memory forensics.  These are all publicly available on the volatility GitHub page but I find it very useful for mapping the plugins and their usage.

#dfir #incidentresponse #memoryforensics #infosec
Securitum (@securitum_com) 's Twitter Profile Photo

ICYMI @[email protected] explained a few DOMPurify bypasses yesterday (youtu.be/QBkLI35sxVs). Today we're publishing a first part of two-part series about how he helped secure DOMPurify: research.securitum.com/helping-secure…

James Forshaw (@tiraniddo) 's Twitter Profile Photo

Having discovered various issues with Windows mini-filter drivers lately I found public information about how to analyze such drivers for security issues somewhat lacking. Therefore today I've put out a blog post to try and fix that glitch :-) googleprojectzero.blogspot.com/2021/01/huntin…

Orange Tsai  🍊 (@orange_8361) 's Twitter Profile Photo

I know there are lots of people waiting for the recent Microsoft Exchange pre-auth RCE on our side. This is a short advisory and detailed timeline. proxylogon.com #proxylogon

Masato Kinugawa (@kinugawamasato) 's Twitter Profile Photo

Interesting. The print() dialog has no information about the origin, so "document.write(document.domain);print()" might be better. By doing so, you can see document.domain on the print preview portswigger.net/research/alert…

LiveOverflow 🔴 (@liveoverflow) 's Twitter Profile Photo

NEW VIDEO! Ever wondered what these "Browser Sandbox Escapes" are about? @freddyb wrote an article about how easy it is to look for vulnerabilities in the Firefox Sandbox and I turned it into a video. What is a Browser Security Sandbox?! youtube.com/watch?v=StQ_6j…

NEW VIDEO!
Ever wondered what these "Browser Sandbox Escapes" are about? @freddyb wrote an article about how easy it is to look for vulnerabilities in the Firefox Sandbox and I turned it into a video.

What is a Browser Security Sandbox?!
youtube.com/watch?v=StQ_6j…
Masato Kinugawa (@kinugawamasato) 's Twitter Profile Photo

Inspired by Gareth Heyes \u2028' CSP bypass in PayPal, for the first time in 4 years, I found again that JS resources added by CloudFlare could introduce a CSP bypass. l0.cm/cf_cspbypass.h…

Mike Mackintosh  (@mikemackintosh) 's Twitter Profile Photo

I’m looking to give away a voucher for the #OSCP PEN-200 w/ 30 day lab access ($999 value) for those in #InfoSec looking to grow their career! To enter for a chance to win, make sure to follow me AND retweet or like. The winner will be randomly selected on October 1st!

shubs (@infosec_au) 's Twitter Profile Photo

Amazing writeup on finding a vulnerability through .NET reversing, enjoyed reading about the breakpoints that were set and how they logically owned Citrix ShareFile through a third party dependency codewhitesec.blogspot.com/2021/09/citrix…

Anugrah SR 📌| #HackLearnDaily (@cyph3r_asr) 's Twitter Profile Photo

⚠️📱Android Pentest Resources 👇 👉 Android app pentesting Hacktricks by @carlospolopm book.hacktricks.xyz/mobile-apps-pe… 👉 android pentest mindmap xmind.net/m/DVAq9V/# 👉 Android pentest checklist by Harsh Bothra xmind.net/m/GkgaYH/#