_bhamza Profile
_bhamza

@_bhamza

Followers
389
Following
1K
Media
15
Statuses
759

Joined July 2018
Don't wanna be here? Send us removal request.
@HttpToolkit
HTTP Toolkit
28 days
Big milestone: HTTP Toolkit just crossed one million downloads! ๐Ÿš€ Honestly I didn't think it'd ever get this far, I'm blown away. A huge thanks to all the users, contributors & supporters over the years โค๏ธ. Onwards!
5
2
18
@hkashfi
Hamid Kashfi
1 month
(Automated) Pentesting is already dead I found it interesting how many people misunderstood and ignored the context of my earlier post here, which was about (Tenzai) securing a $75M seed round, and more specifically AI powered automated penetration testing. Iโ€™ve been doing a
11
52
333
@zhero___
zhero;
1 month
release of our new paper (w/ @inzo____) which resulted in CVE-2025-64525: Astro framework and standards weaponization from path-based middleware protection bypass to potential SSRF & XSS + full bypass of CVE-2025-61925 on @astrodotbuild https://t.co/xTO55gNFu4
12
83
347
@trailofbits
Trail of Bits
5 months
TOOL RELEASE: Detect plagiarized code even when variable names change and comments disappear. Vendetect uses semantic fingerprinting to catch copied code that traditional tools miss.
Tweet card summary image
blog.trailofbits.com
Vendetect is our new open-source tool for detecting copied and vendored code between repositories. It uses semantic fingerprinting to identify similar code even when variable names change or comments...
0
25
80
@assetnote
Assetnote
5 months
Sometimes, SQL injection is still possible, even when prepared statements are being used. Our researcher @hash_kitten has written up a blog post about a novel technique for SQL Injection in PDOโ€™s prepared statements:
slcyber.io
Searchlight Cyber's Security Research team details a Novel Technique for SQL Injection in PDO's Prepared Statements.
1
79
291
@souf_dev
soufDev
6 months
Get your FREE RankSight Score! With actionable plan Unveil your site's future visibility & get your definitive blueprint for top ranking in AI Search. No more blind spots. #RankSight #AISEO #LLMViz #DigitalMarketing
1
2
3
@linuxscout
ุทู‡ ุฒุฑูˆู‚ูŠ
6 months
ุฅุทู„ุงู‚ ุงู„ู†ุณุฎุฉ ุงู„ุชุฌุฑูŠุจูŠุฉ ู…ู† ู…ู†ุตุฉ ุขุฌูุฑู‘ูˆู…ุŒ ู…ู†ุตุฉ ู„ุฅุนุฑุงุจ ุงู„ุฌู…ู„ ูˆุงู„ู†ุตูˆุต ุงู„ุนุฑุจูŠุฉ ุจุงู„ุฐูƒุงุก ุงู„ุงุตุทู†ุงุนูŠ ู…ุน ุงู„ุชุฏู‚ูŠู‚ ุงู„ู†ุญูˆูŠ. ุชุทูˆูŠุฑ ู‡ูŠุซู… ุจู† ุญู„ูŠู…ุฉ. https://t.co/rAVQI0W1A0
3
10
28
@microsvuln
MicrosVuln
8 months
If you're using chatgpt/AI for solving "every single" security research challenge, then you're not a security researcher anymore, you're a Chatgpt/AI operator. #skipchatgpt
0
1
2
@enovella_
Edu Novella
8 months
After 2 years from the last release, APKiD v3.0.0 is out !๐Ÿ”ฅ - "Black Hawk edition" ๐Ÿ“ƒ Changelog: https://t.co/gZsWgRyQtJ ๐Ÿ Pypi package: `$ pip install --upgrade apkid` Thanks to @AbhiTheModder for the stunning work ๐Ÿ™Œ
Tweet card summary image
github.com
The following SDK got improvements, rules and fixes: Ahnlab V3 Engine (packer/anti_root) Appdome (ELF Aarch64) AppGuard packer (ELF/APK) Arxan (DEX) AY literal obfuscation Beebyte (DLL) BlackObfus...
0
16
43
@JamesClear
James Clear
9 months
When choosing a new habit many people seem to ask themselves, โ€œWhat can I do on my best days?โ€ The trick is to ask, โ€œWhat can I stick to even on my worst days?โ€ Start small. Master the art of showing up. Scale up when you have the time, energy, and interest.
114
642
4K
@8kSec
8kSec
9 months
๐Ÿ–ฅ๏ธLearn about root detection techniques on Android and how to bypass them in our latest blog: https://t.co/9fKs26Xl3T โ˜‘๏ธFound this interesting? Our courses offer more in-depth insights. Check them out here: https://t.co/n5WRBcePIM #MobileSecurity #AndroidSecurity #Jailbreak
0
9
37
@hacktricks_live
HackTricks
9 months
๐Ÿš€ To celebrate the upcoming Azure Red Team Expert cert, we're launching the first Cloud PEASS: Azure PEASS! ๐Ÿ”Ž It gets Azure/Entra tokens, finds all your permissions, highlights sensitive ones HackTricksAI and tells you how to privesc! ๐Ÿ‘‰ https://t.co/2bfhcf4itb #hacktricks
Tweet card summary image
github.com
Contribute to carlospolop/CloudPEASS development by creating an account on GitHub.
2
139
456
@ApkUnpacker
Govind Sharma
9 months
Introducing https://t.co/NWz6mFk0w1, a small POC code that detects known root-related apps by attempting to launch their activities and monitoring security exceptions. Strengthen your appโ€™s security by identifying potential root access attempts. #AndroidSecurity #RootDetection
Tweet card summary image
github.com
Small POC code that detects known root-related apps by attempting to launch their activities and monitoring security exception. - apkunpacker/RootAppDetector
1
7
47
@0xvangrim_
0xvangrim
10 months
I've talked to enough web3 SRs to know that your auditing methodology is your bread and butter. This means that you are not only focusing on understanding new bugs. But also make sure that the bugs you've found once upon a time will be found every single time. On your worst
3
3
34
@assem_ch
Assem
1 year
First project in the line: A software cost estimator based on Figma design files: considering nb of screens and the complexity, other factors will be added by time
7
7
30
@taym95
Taym Haddadi
1 year
Made it to top 10 contributors to Servo this year, this is probably the thing I'm most proud of in my life so far as a developer, More to come in the future!
2
4
20
@_bhamza
_bhamza
1 year
Previously, I covered how to useย #unidbgย from scratch to emulate an #Android native lib. The PoC was basic & slow. In this new blog, I'll demonstrate where the bottleneck is, and how we can make it production-ready by using Spring boot https://t.co/lHVvkbKfCh #mobilesecurity
Tweet card summary image
bhamza.me
Introduction In the last blogpost, we covered how to use unidbg from scratch to emulate an Android native library. As some might have noticed, the Proof of Concept code is not production ready as it...
0
20
55