GainSec Profile Banner
Jon G Profile
Jon G

@GainSec

Followers
683
Following
18K
Media
42
Statuses
7K

Hacker by night. 50 CVEs. Husband. Father. Skateboarder. Posts are my own.

New York, USA
Joined May 2016
Don't wanna be here? Send us removal request.
@blackorbird
blackorbird
1 day
Someone has launched a project called Poison Fountain, which seeks to poison training data for AI models. They aim to disrupt the technology by adding poisoned data to websites, making AI models less effective. rnsaffn[.]com/poison3/
1
15
51
@GainSec
Jon G
16 hours
Am I doing SigINT right?
0
0
0
@rub003
003random
4 days
This bug was buried so deep. You had to use a mobile user agent to reach the code path. Then block the victim account. And then request one of their posts via the oEmbed endpoint. This would trigger a try catch condition where super user privileges were used to fetch the post.
@intigriti
Intigriti
4 days
1️⃣ How I Exposed Instagram's Private Posts by Blocking Users @rub003 won 3rd place at BountyCon 2022 by chaining Instagram oEmbed endpoint quirks with mobile user agent detection to access private posts (earning him $14,500 in bounties). https://t.co/xBlePPez87
3
6
112
@GainSec
Jon G
4 days
You may have heard Benn mention me in his last video about Flock Safety. If you were dying to know the juicy technical details of why and how some of their PTZ and LPR camera feeds ended up exposed unauthenticated to the entire internet
Tweet card summary image
gainsec.com
How I took a security researchers initial discovery and found another 63 instances of Flock Safety Camera Feeds and Debug Web Service exposed unauthenticated to the internet. Also learn how it ended...
0
0
0
@fuzzsociety_org
fuzzsociety
8 days
We built a full-system iOS fuzzer using QEMU+AFL, dup2() I/O channels, hypercalls, syscall enumeration & __syscall tricks on undocumented architecture. Bridged gap between fuzzing theory & closed-source systems. Instructions and code https://t.co/WGHzf7CEBw Course and book
1
61
336
@khanhduytran0
Duy Tran
13 days
Happy new year! Here is a 167gr iPhone driving macOS 15.6, with native M4 driver partially patched for A18
78
467
8K
@DonShift3
Don Shift (buy my books)
15 days
I'd like to announce my promotion to Inspector with the Ventura County Joint Radio Spectrum Protection and Monitoring Unit. We use specially equipped unmarked patrol vehicles to detect and triangulate unlicensed and inappropriate usages of the radio spectrum in cooperation with
478
63
1K
@GainSec
Jon G
15 days
Was recently invited into the Security Ledger Podcast. Enjoyed my time with @securityledger and ofc @bennjordan
0
0
0
@chongdashu
Chong-U
18 days
Not many know about this hidden command: claude --teleport It starts a desktop claude code session SYNC'd with your web / mobile session Great when you're working on your phone -- and then want to pick up from EXACTLY where you left off when back at your PC Demo below 👇
17
39
801
@tom_doerr
Tom Dörr
19 days
Sideloads apps on iOS using DNS and certificates https://t.co/Zs6C80Sj4y
15
93
2K
@tom_doerr
Tom Dörr
21 days
Runs iOS apps on Apple Silicon Macs https://t.co/3BOBFqU9HX
13
88
1K
@blackorbird
blackorbird
21 days
Snitch is a modern, user-friendly command-line tool for inspecting network connections on Linux and macOS. It serves as a more visually appealing and intuitive alternative to traditional tools like ss or netstat, offering both an interactive terminal user interface (TUI) and
9
105
1K
@0xor0ne
0xor0ne
21 days
“Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes” (slide deck) https://t.co/TMJlI2aryv Credits @XenoKovah #infosec
0
76
533
@IntelTechniques
IntelTechniques
27 days
Issue 010 of UNREDACTED Magazine is now available: https://t.co/aaOqcsjBY6 83 pages of raw info. No third-party ads. No outside sponsors. No conflicts of interest. No fluff. No filler. No agenda. Only detailed information.
0
40
149
@cyb_detective
Cyber Detective💙💛
1 month
OSINT LLM Free @huggingface space which contains an LLM trained on the @bellingcat investigation toolkit and which will help you choose methods and tools for different OSINT tasks. https://t.co/HvM8TG1MEw Creator @buriedsignals
9
93
471
@SahilBloom
Sahil Bloom
1 month
The single greatest challenge for any ambitious person is eliminating the guilt associated with free time and rest.
281
669
7K
@the_yellow_fall
Gray Hats
1 month
LazyHook is a new open-source framework using hardware breakpoints and SEH to intercept system calls and execute code stealthily, bypassing memory integrity and EDR checks. https://t.co/yh8TZvaQ8v
1
7
26
@phrack
Phrack Zine
1 month
The wait is over! Phrack 72 40th Anniversary Edition is available now. Order straight to your doorstep — the perfect gift for your fellow hacker, just in time for the holidays🎄 No need to go to rely on the warez scene with scans anymore😅 Order here: https://t.co/tx7UUPZcm1
3
25
88
@steipete
Peter Steinberger
1 month
Codexbar 0.7.1 is out - now with handy shortcut for switching accounts. https://t.co/aTZZs7voSQ
9
9
219