Open in app

Sign In

Write

Sign In

Everping
Everping

23 Followers

Home

About

Published in Security-aholic

·Feb 13, 2020

Deal with challenge exceptions in Linkedin API

Recently, I have to use Linkedin API to crawl companies in their ecosystem. The official API (v3)requires OAuth for authenticating and forces you to request to them before you can use the full version (public and private APIs). Luckily, I found that Linkedin offers Voyager API for searching and listing…

Linkedin Api

1 min read

Deal with challenge exceptions in Linkedin API
Deal with challenge exceptions in Linkedin API
Linkedin Api

1 min read


Published in Security-aholic

·Aug 12, 2019

Subdomain takeover — Chapter two: Azure Services

Read this article at my company’s blog As I described in the chapter one, we can control the content of a sub-domain d by controlling the content of domain d1 that d point to through its CNAME record. Azure, a popular cloud service offer many services that can create such…

Custom Domains

4 min read

Subdomain takeover — Chapter two: Azure Services
Subdomain takeover — Chapter two: Azure Services
Custom Domains

4 min read


Published in Security-aholic

·Aug 12, 2019

Subdomain takeover — Chapter one: Methodology

Read this article at my company’s blog Subdomain takeover is a high severity vulnerability that can be exploited to take control of a domain and pointing it to an address managed by attackers. Attacks on this vulnerability are often used for the purpose of creating phishing sites, spreading malwares. …

Medium

4 min read

Subdomain takeover — Chapter one: Methodology
Subdomain takeover — Chapter one: Methodology
Medium

4 min read


Published in Security-aholic

·Feb 9, 2018

A python script get Alexa top sites

If you want to get top visited websites, Alexa is a reliable source. But, sadly, they only free the first 50 websites, and if you want to get more, you have to pay a fee. One of the ways to obtain that list is to use AWS service with price $0.0025 per URL. Everything seems easy when you are willing to pay, however, their sample code is only available ruby, php, java that I do not like them. I have rewritten a small script in Python to do this, you can check it bellow.

AWS

1 min read

A python script get Alexa top sites
A python script get Alexa top sites
AWS

1 min read


Published in Security-aholic

·Mar 3, 2017

Using Remote Asset Bundle in Unity3D framework really safe?

Introdution If you are a mobile application developer, you may be interested in exposing sensitive information from your application because of decompilation a mobile app such as Android app is not too difficult. A friend of mine recently developed an Android application using Unity framework, it can hide code by downloading…

Android

4 min read

Using Remote Asset Bundle in Unity3D framework really safe?
Using Remote Asset Bundle in Unity3D framework really safe?
Android

4 min read


Published in Security-aholic

·Feb 18, 2017

Client Side Template Injection — Kipalog.com

Information Security

1 min read

Client Side Template Injection — Kipalog.com
Client Side Template Injection — Kipalog.com
Information Security

1 min read


Published in Security-aholic

·Oct 29, 2016

Dirty Cow — CVE-2016-5195

Về Dirty Cow Gần đây tôi có thấy nhiều thông tin về lỗ hổng này, được đánh giá là Serious, cho phép leo thang đặc quyền, ảnh hưởng đến nhiều distro Linux… Tôi cũng không hiểu sao một lỗ hổng sau khi được công bố thì có logo, website riêng, Twitter, Facebook Page…

Dirty Cow

8 min read

Dirty Cow — CVE-2016-5195
Dirty Cow — CVE-2016-5195
Dirty Cow

8 min read


Published in Security-aholic

·Oct 13, 2016

How does HTTPS actually work?

What is HTTPS? We’ve heard a lot about HTTPS, and we use it every day. If you access a website from your browser and you see a little green padlock and the letters “https” in your address bar then congratulations, you are accessing this safely via HTTPS. HTTPS is a combination of HTTP…

Security

6 min read

How does HTTPS actually work?
How does HTTPS actually work?
Security

6 min read

Everping

Everping

23 Followers
Following
  • Diddy Doodat

    Diddy Doodat

  • WhiteHub

    WhiteHub

  • slavco

    slavco

  • Inti De Ceukelaire

    Inti De Ceukelaire

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech