Search titles only
By:
Home
Members
Moderators
Current visitors
Escrow
Deposit
Account Upgrades
ADS
Help
WMIX.TO
Komplexes Bot
Log in
Register
What's new
Search
Search titles only
By:
Menu
Log in
Register
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Depov's latest activity
Depov
posted the thread
iOS App Pentest: From Frida Installation to the Keybreak Curet
in
Programming
.
On the audit of the fintech application for iOS, we stumbled in a three-layer jailbreak detection - file checks, sandbox recording in...
Jun 5, 2026
Depov
posted the thread
Reverse-engineering of iOS applications: IPA-analysis, class-dump and Frida through the eyes of a protector
in
Programming
.
The place in the attack chain: why reverse an iOS application Reverse-engineering of iOS applications is not an end in itself. This is...
Jun 5, 2026
Depov
posted the thread
Malware development on Rust: stealth agent for red team, bypass EDR and comparison with C++
in
Programming
.
A functionally identical plaid loader weighs 71.7 KB on C and 151.5 KB on Rust - the binary doubled. At the same time, according to a...
Jun 4, 2026
Depov
posted the thread
Nginx reverse proxy: C2 security and detection-checking for SOC
in
Web
.
Business logic of attack: the place of Nginx-redirector in kill chain Nginx reverse proxy for the security of C2 works at the Command...
Jun 4, 2026
Depov
replied to the thread
🛡️ MixTum & BFD Crew - FREE RAFFLE 🎁 1 mBTC!
.
Slot # 2 BTC: bc1q5hz3uhfrepc272h55cqlv4g4ygkyha37vrsxrq
Jun 3, 2026
Depov
posted the thread
Feature engineering for network traffic: why the quality of the features solves more than the choice of an algorithm in IDS ML models
in
Web
.
Six months ago, we killed two weeks for the selection of LightGBM hyperparameters for a C2 backed detect in corporate traffic. F1 was...
Jun 3, 2026
Depov
posted the thread
Development of extensions of Burp Suite in Python and Java: automation of web application pentest
in
Programming
.
On the latest API pentest, fintech service every request requiredHMAC-signature in the title X-Signature - calculated from the...
Jun 3, 2026
Depov
posted the thread
Preaothy RCE and bypass mTSS: the analysis of Mongoose vulnerabilities on millions of devices
in
Programming
.
The comment in the product code "ignore secp386 for now" - and the P-384 mTS is turned into a decoration. Heap overflow in TLS-handshake...
Jun 2, 2026
Depov
posted the thread
Penttest IoT devices: from reconnaissance and disassembly to OWASP ITG
in
Programming
.
On the last three IoT security testing projects, I opened the device body, connected to UART – and in two cases out of three received a...
Jun 2, 2026
Depov
posted the thread
APT42 and Seedworm: credential harvesting through social engineering — how Iranian APT steals accounts without malware
in
Web
.
In 2024, APT42hacked into the Trump campaign, pulled out internal documents andtried to merge them to journalists. Without a single...
Jun 2, 2026
Depov
posted the thread
Disable NTLMv1 via GPO — and still see it in pcap: bypass LmCompatibilityLevel and audit of legacy traffic
in
Web
.
Internal pentest of the financial organization, late 2024. Domain on Windows Server 2019, GPO Network security: LAN Manager...
Jun 2, 2026
Depov
posted the thread
Consent phishing through OAuth: From Phishing Link to Microsoft 365
in
Web
.
The place of the consent phishing OAuth attacks in the attack chain Consent phishing is not a pointtechnique, but a full-fledged attack...
May 31, 2026
Depov
posted the thread
BIOS protection bypass: Secure Boot off on plug-in firmware
in
Programming
.
The place in the chain of attack: why break the firmware Compromise of UEFI-fishering is notan end in itself, but the solution of two...
May 31, 2026
Depov
posted the thread
ML IDS Detection of Unsignature Attacks: Blind Areas of Behavioral Detector
in
Web
.
Six months ago on the internal Red Team exercise Isolation Forest,trained on the monthly baseline from Zeek conn.log, missed a DNStunnel...
May 30, 2026
Depov
posted the thread
Identity-based APT 2026 attack: how groups go from endpoints to the cloud and mail – Red Team and Detection Guide
in
Programming
.
In November 2023, the APT29 (Midnight Blizzard) climbed into the corporate environment of Microsoft through the password spraying of the...
May 30, 2026
Top
Bottom