Jon G
@GainSec
Followers
683
Following
18K
Media
42
Statuses
7K
Hacker by night. 50 CVEs. Husband. Father. Skateboarder. Posts are my own.
New York, USA
Joined May 2016
Someone has launched a project called Poison Fountain, which seeks to poison training data for AI models. They aim to disrupt the technology by adding poisoned data to websites, making AI models less effective. rnsaffn[.]com/poison3/
1
15
51
This bug was buried so deep. You had to use a mobile user agent to reach the code path. Then block the victim account. And then request one of their posts via the oEmbed endpoint. This would trigger a try catch condition where super user privileges were used to fetch the post.
1️⃣ How I Exposed Instagram's Private Posts by Blocking Users @rub003 won 3rd place at BountyCon 2022 by chaining Instagram oEmbed endpoint quirks with mobile user agent detection to access private posts (earning him $14,500 in bounties). https://t.co/xBlePPez87
3
6
112
You may have heard Benn mention me in his last video about Flock Safety. If you were dying to know the juicy technical details of why and how some of their PTZ and LPR camera feeds ended up exposed unauthenticated to the entire internet
gainsec.com
How I took a security researchers initial discovery and found another 63 instances of Flock Safety Camera Feeds and Debug Web Service exposed unauthenticated to the internet. Also learn how it ended...
0
0
0
We built a full-system iOS fuzzer using QEMU+AFL, dup2() I/O channels, hypercalls, syscall enumeration & __syscall tricks on undocumented architecture. Bridged gap between fuzzing theory & closed-source systems. Instructions and code https://t.co/WGHzf7CEBw Course and book
1
61
336
Happy new year! Here is a 167gr iPhone driving macOS 15.6, with native M4 driver partially patched for A18
78
467
8K
I'd like to announce my promotion to Inspector with the Ventura County Joint Radio Spectrum Protection and Monitoring Unit. We use specially equipped unmarked patrol vehicles to detect and triangulate unlicensed and inappropriate usages of the radio spectrum in cooperation with
478
63
1K
Was recently invited into the Security Ledger Podcast. Enjoyed my time with @securityledger and ofc @bennjordan
0
0
0
Not many know about this hidden command: claude --teleport It starts a desktop claude code session SYNC'd with your web / mobile session Great when you're working on your phone -- and then want to pick up from EXACTLY where you left off when back at your PC Demo below 👇
17
39
801
Snitch is a modern, user-friendly command-line tool for inspecting network connections on Linux and macOS. It serves as a more visually appealing and intuitive alternative to traditional tools like ss or netstat, offering both an interactive terminal user interface (TUI) and
9
105
1K
“Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes” (slide deck) https://t.co/TMJlI2aryv Credits @XenoKovah
#infosec
0
76
533
Issue 010 of UNREDACTED Magazine is now available: https://t.co/aaOqcsjBY6 83 pages of raw info. No third-party ads. No outside sponsors. No conflicts of interest. No fluff. No filler. No agenda. Only detailed information.
0
40
149
OSINT LLM Free @huggingface space which contains an LLM trained on the @bellingcat investigation toolkit and which will help you choose methods and tools for different OSINT tasks. https://t.co/HvM8TG1MEw Creator @buriedsignals
9
93
471
The single greatest challenge for any ambitious person is eliminating the guilt associated with free time and rest.
281
669
7K
LazyHook is a new open-source framework using hardware breakpoints and SEH to intercept system calls and execute code stealthily, bypassing memory integrity and EDR checks. https://t.co/yh8TZvaQ8v
1
7
26
@pianzes GitHub - KrishKrosh/TrackWeight: Use your Mac trackpad as a weighing scale https://t.co/2qlX87RJTl
github.com
Use your Mac trackpad as a weighing scale. Contribute to KrishKrosh/TrackWeight development by creating an account on GitHub.
0
10
106
The wait is over! Phrack 72 40th Anniversary Edition is available now. Order straight to your doorstep — the perfect gift for your fellow hacker, just in time for the holidays🎄 No need to go to rely on the warez scene with scans anymore😅 Order here: https://t.co/tx7UUPZcm1
3
25
88
Codexbar 0.7.1 is out - now with handy shortcut for switching accounts. https://t.co/aTZZs7voSQ
9
9
219