Lior Keshet Profile
Lior Keshet

@LiorKesh

Followers
243
Following
94
Media
0
Statuses
105

Security researcher by day. Bug hunter by night.

Joined May 2013
Don't wanna be here? Send us removal request.
@LiorKesh
Lior Keshet
1 month
We broke commercial root detection in Android apps 🔓📲. We targeted sensitive apps - finance, security, government - which use commercial protections. We got them running on rooted devices. That gave us full control to modify app behavior however we wanted. 👇.
2
8
20
@LiorKesh
Lior Keshet
1 month
Finally, we built a persistent module, and got the apps cleanly running on the rooted device across reboots, updates, reinstalls - no adb needed. Read the full writeup here -
Tweet card summary image
lucidbitlabs.com
We bypassed leading Android root-detection SDKs and show what that means for banking, government-ID and anti-fraud apps running on rooted devices.
0
6
11
@grok
Grok
6 days
What do you want to know?.
476
307
2K
@LiorKesh
Lior Keshet
1 month
We reverse-engineered the apps, bypassing anti research protections. We pinpointed critical 'decision points' in which the app determines whether its safe to run or not. By hooking these points, we got the apps running happily on rooted devices.
1
2
4
@LiorKesh
Lior Keshet
1 month
Security critical apps often rely on Runtime Application Self Protection (RASP) to block execution on rooted devices and prevent tampering. Otherwise, attackers can:.- Fake location and/or movement.- Bypass usage restrictions.- Run apps on malware-infected devices.
1
0
2
@LiorKesh
Lior Keshet
1 month
RT @it4sec: DJI drone security analysis: reverse engineering communication, firmware extraction, and fuzzing for vulnerabilities. 𖥂🎮 ၊၊||၊….
0
145
0
@LiorKesh
Lior Keshet
1 month
At @LucidBitLabs, we broke commercial root detection in apps with top-tier app protections in place (RASP). Full write up -
Tweet card summary image
lucidbitlabs.com
We bypassed leading Android root-detection SDKs and show what that means for banking, government-ID and anti-fraud apps running on rooted devices.
0
4
5
@LiorKesh
Lior Keshet
2 months
RT @it4sec: Hacker tries to restore lost internet connection: reverse engineers the modem and hacks into ISP network. ☎️ 🌐🔬🔨. More details….
0
18
0
@LiorKesh
Lior Keshet
3 months
RT @dfsec_com: Our new blog post is live:
blog.dfsec.com
Dataflow Security blog
0
84
0
@LiorKesh
Lior Keshet
3 months
RT @offensive_con: #OffensiveCon25 videos are now up!.
Tweet card summary image
youtube.com
OffensiveCon 2025 Talks
0
169
0
@LiorKesh
Lior Keshet
3 months
RT @Morpheus______: "DisARMing" code - an exploration into systems programming, #debugging & #reverseEngineering on #Linux/#Android/#Darwin….
0
55
0
@LiorKesh
Lior Keshet
3 years
RT @NovoShield_Pro: NAVY FEDERAL CREDIT UNION SITE PHISHED.#novoShield's @LiorKeshet detected & reported - today - a phishing site hosted o….
0
1
0
@LiorKesh
Lior Keshet
4 years
RT @orsafr: The code for the tool we presented at @deepsec. Now it’s open source!!!.
0
4
0
@LiorKesh
Lior Keshet
5 years
RT @orsafr: Finally, The blog is out, proving that when it comes to cloud security, MFA is not a silver bullet. Technical Deep Dive: Vulner….
Tweet card summary image
proofpoint.com
Discover how attackers bypass MFA in Office 365 by acting on behalf of an account holder. Learn about MFA bypass attacks and how to protect yourself against them.
0
1
0
@LiorKesh
Lior Keshet
6 years
RT @iCyberFighter: Sending a shoutout to the awesome reverse engineer who dissected #goznym when it emerged. His name is .@LiorKesh and I m….
0
1
0
@LiorKesh
Lior Keshet
7 years
RT @BlueHatIL: The wait is over! Registration & schedule for #BlueHatIL 2019 are now live. Places are limited, register today! https://t.co….
0
37
0
@LiorKesh
Lior Keshet
7 years
RT @POC_Crew: We have uploaded slides from POC2018:) Thank you everyone for your support and interests! . Be noticed that some slides are n….
0
33
0
@LiorKesh
Lior Keshet
7 years
RT @4x6hw: Our #defcon26 talk, "Turning Deception Outside-In: Tricking Attackers with OSINT", was just uploaded to youtube. check it out. @….
0
11
0
@LiorKesh
Lior Keshet
7 years
RT @GoogleVRP: We opensourced most of the Google CTF 2018 Finals challenges:
0
328
0