souilos (@thesouilos) 's Twitter Profile
souilos

@thesouilos

Operational Security for Web3 Companies

ID: 2984415263

linkhttps://linktr.ee/souilos calendar_today18-01-2015 18:11:58

503 Tweet

373 Takipçi

1,1K Takip Edilen

souilos (@thesouilos) 's Twitter Profile Photo

I met nisedo 3y ago at EthCC Paris. He then reunited all the best Web3 Security talents from the French community inside Soliditors . « Practice, Practice, Practice… » Nico joined Trail of Bits

I met <a href="/nisedo_/">nisedo</a> 3y ago at EthCC Paris.

He then reunited all the best Web3 Security talents from the French community inside <a href="/soliditors/">Soliditors</a> . 

« Practice, Practice, Practice… » Nico joined <a href="/trailofbits/">Trail of Bits</a>
souilos (@thesouilos) 's Twitter Profile Photo

Bad news of the day. Another wallet drained because the seed was stored in a password manager. Password managers are for passwords only. How much money is stolen every day? How much do you think of the stolen money isn’t public? From HNWI, to small, medium and big companies.

souilos (@thesouilos) 's Twitter Profile Photo

Coming from Web2 security, I am happy to see this. Maybe we will see one day, Metasploit, crackmapexec and more for Web3 sec 😎

souilos (@thesouilos) 's Twitter Profile Photo

I’ll definitely spend more time here. While nowadays 80% of the articles are AI written, you must check them out. High quality and technical posts from Trail of Bits

I’ll definitely spend more time here.

While nowadays 80% of the articles are AI written, you must check them out. 

High quality and technical posts from <a href="/trailofbits/">Trail of Bits</a>
souilos (@thesouilos) 's Twitter Profile Photo

Did you know you could run LinPEAS on your macOS?? Highly recommended to discover secrets & escalations paths. I have used it many times on Linux & Windows machines (WinPEAS).

Did you know you could run LinPEAS on your macOS?? 

Highly recommended to discover secrets &amp; escalations paths.

I have used it many times on Linux &amp; Windows machines (WinPEAS).
SlowMist (@slowmist_team) 's Twitter Profile Photo

🚨SlowMist TI Alert🚨 A community member recently reached out after interviewing with a Web3 team claiming to be from Ukraine. In the first round, he was asked to clone a GitHub repo locally — he wisely refused.🧑‍💻 🔍Our analysis revealed the repo contains a backdoor:

🚨SlowMist TI Alert🚨

A community member recently reached out after interviewing with a Web3 team claiming to be from Ukraine. In the first round, he was asked to clone a GitHub repo locally — he wisely refused.🧑‍💻

🔍Our analysis revealed the repo contains a backdoor:
zak.eth (@0xzak) 's Twitter Profile Photo

I've been in crypto for over 10 years and I’ve Never been hacked. Perfect OpSec record. Yesterday, my wallet was drained by a malicious Cursor extension for the first time. If it can happen to me, it can happen to you. Here’s a full breakdown. 🧵👇

souilos (@thesouilos) 's Twitter Profile Photo

I had to factory reset my macOS a few days ago. Will be pushed on our GitHub to help you reset your device & install the os within 1hr.

I had to factory reset my macOS a few days ago.

Will be pushed on our GitHub to help you reset your device &amp; install the os within 1hr.
m4rio (@m4rio_eth) 's Twitter Profile Photo

🚨 NEW: VSDeer is live! 🦌 Time to protect your assets by avoiding malicious IDE extensions. VSDeer scans for malicious extensions before you install them. VSDeer runs a nice scam algorithm which detects scammy extensions. Also, you should sandbox all your extensions, so i

🚨 NEW: VSDeer is live! 🦌

Time to protect your assets by avoiding malicious IDE extensions. VSDeer scans for malicious extensions before you install them.

VSDeer runs a nice scam algorithm which detects scammy extensions.

Also, you should sandbox all your extensions, so i
souilos (@thesouilos) 's Twitter Profile Photo

Your AppleID must be protected at all cost iPhone tip: Add a Screen Time passcode Settings > Screen Time > Use Screen Time Passcode and lock changes in Privacy & Face ID settings This prevents anyone from: •Removing or editing your Apple ID •Changing Face ID/Passcode

Your AppleID must be protected at all cost

iPhone tip: Add a Screen Time passcode 

Settings &gt; Screen Time &gt; Use Screen Time Passcode and lock changes in Privacy &amp; Face ID settings

This prevents anyone from:
•Removing or editing your Apple ID
•Changing Face ID/Passcode
yo4nn (@0xyoann) 's Twitter Profile Photo

Using a hardware wallet is essential if you want your funds to be secure. If you struggle don't hesitate to reach out to trusted people in this space like opsek or Patrick Collins for wallet security courses.

souilos (@thesouilos) 's Twitter Profile Photo

OWASP Top 10 vulnerabilities in smart contracts. Same as Web2. No matter which framework or dev tools you use, access controls must be mapped manually one by one and the principle of least privilege must be applied. Block everything first, then allow only the minimum necessary.

OWASP Top 10 vulnerabilities in smart contracts.

Same as Web2.
No matter which framework or dev tools you use, access controls must be mapped manually one by one and the principle of least privilege must be applied.

Block everything first, then allow only the minimum necessary.