Hacker at Orange Cyberdefense’s SensePost Team
Posts
I’m reminded of the disconnect between typical vuln scan/pentest XSS findings and real world exploitation by this write up of Russian exploitation of webmail apps https://ctrlaltintel.com/threat%20research/FancyBear/
How do you demonstrate XSS impact beyond the classic alert dialog or cookie stealer?
Periodic reminder - there’s no easy way to clear tracking cookies and other cruft from iOS apps. But you can do it across all of them with one easy shortcut! It won’t log you out of the app just get rid of the cruft from the in-app browser.
prefs:root=SAFARI&path=CLEAR_HISTORY_AND_DATA
I was interviewed for a local TV about the legislation & enforcement of personal data protection in South Africa. It was triggered by the sentencing of the person convicted of the Experian breach. I made the point that credit bureaus remain the problematic loophole in our privacy legislation while they are allowed to collect data & sell it without our consent - beyond purposes of fraud prevention.
My bit was clipped but I’m happy we got Szymon’s new art project in.