Remediating unvalidated forwards and redirects is almost always achieved by using an allow list of absolute URLs. Although what do you do if the absolute URL is not known ahead of time? This post digs into validating URLs for redirects / forwards using a relative path.
A walk through of solving the Cyberlock CTF challenge from r2con2020 using the Radare2 framework. This post breaks down the process of reversing an unknown x86 binary and showcases some of the capabilities of the framework.
An introduction into how existing popular rooting frameworks can be customised to provide a more stealthy alternative. This post highlights the importance of setting up a streamlined Android environment for security testing. In addition, I walk through an open source tool I wrote for modifying one of these frameworks that makes it virtually undetectable using conventional methods.
A high level overview of debugging and dynamically instrumenting Swift mobile applications on iOS 13. This post goes into detail on some of the nuances of testing on iOS 13, some tips on working with Swift apps with the dynamic instrumentation framework Frida, and some general information for getting set up.
My journey of knowing almost nothing about AWS to achieving the SAA-C02 Associate Solutions Architect certification in three weeks. This post highlights why I decided to pursue this certification, what resources I used, and what I should have done differently.