Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
adamdoupe
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
adamdoupe
5y ago
If you want to learn offensive security skills, particularly binary analysis, I highly recommend https://pwn.college It's a hands-on class that takes you through interacting with programs, to reverse engineering and memory
2.
▲
by
adamdoupe
8y ago
I posted this on the blog but thought I post here too. Last year I set up a WorldWideWeb.app (version 0.15) running in the Previous emulator on Ubuntu for a CTF challenge for DEF CON 2018 Quals (they had to exploit a buffer overflow in HTTP
3.
▲
by
adamdoupe
9y ago
Context here means the context of the output page. Usually this means the HTML context. Different sanitization is needed depending on _where_ in the HTML document the input is used. For instance, if the input is used in between HTML tags (l
4.
▲
by
adamdoupe
11y ago
In our study we didn't differentiate (from a security perspective, if you are vulnerable because you use a WebView when showing ads, then you are still vulnerable), so I don't have data for that. It would be interesting data, alth
5.
▲
by
adamdoupe
11y ago
Sure! The short version is that I don't know. We were looking for instances of insecure WebView usage, so from a security perspective small piece vs. entire app doesn't matter too much (and is difficult to measure, especially when
6.
▲
by
adamdoupe
11y ago
We've studied this and found that ~85% of the free apps on the Google Play store use a WebView (I like the term "mobile web app"): http://adamdoupe.com/publications/large-scale-study-of-mobil...
7.
▲
by
adamdoupe
12y ago
Most professor salaries are on 9-month appointments, for the academic year. The three summer months usually come from grants, teaching summer sessions, or consulting. However, a professor can choose to spend the grant money on student suppo
8.
▲
by
adamdoupe
12y ago
No. Check out the example in the article, an attacker can make your browser submit a form with a POST request using JavaScript. It's slightly harder to exploit, as the attacker can't just send you a link to facebook.com, but they
9.
▲
by
adamdoupe
15y ago
As I remember, the analysis doesn't handle calls that can't be determined statically. So the analysis would fail to determine the method and class of a obfuscated string.
10.
▲
by
adamdoupe
15y ago
A postdoc in my lab published an academic paper that did exactly this: automated static analysis of iOS compiled binaries for privacy violations. As far as I know Apple was not interested. Here's the paper if you want to take a look: http:
11.
▲
by
adamdoupe
15y ago
Link to the full paper for those interested: http://people.csail.mit.edu/rinard/paper/ecoop11.pdf
12.
▲
by
adamdoupe
15y ago
I've found that it's not the actual code review that's helpful, but preparing for a code review. It forces you to describe the code clearly, which often makes the code clearer in the process. Plus you try to anticipate the comments your co-
13.
▲
by
adamdoupe
17y ago
Hey guys, this is some research that some guys in my lab have been doing. Pretty cool stuff, they "took over" the Torpig botnet. Lots of interesting stuff, the paper on the link gives a good overview of some of the things they discovered. L
14.
▲
Botnet uses Twitter for Drive-by-Download Attacks
(cs.ucsb.edu)
1 points
by
adamdoupe
17y ago
|
1 comments
15.
▲
by
adamdoupe
17y ago
> if you're looking for motivation, i highly suggest finding some sport that you enjoy doing. go looking for it, i'm sure one exists. This is exactly what I've done. Rock climbing at a local gym 3 times a week. I also run 3.5 miles 2 ti
16.
▲
by
adamdoupe
17y ago
This is the way I use dropbox. I even created a script to install all of my packages and create the proper symlinks. Makes setting up a new computer (frequent occurrence with VM's) super simple. Dropbox rocks!
17.
▲
by
adamdoupe
18y ago
The featured five on the homepage moves way too fast. It switched when I was still reading. Beyond that, interesting site. Good luck!
18.
▲
by
adamdoupe
18y ago
On Firefox 1.5 on Linux (It's what they make us use at school), the "points or pay" text extends beyond the tab. http://tinypic.com/view.php?pic=20k3o0z&s=4 But beyond that, I agree with the comments so far, excellent design and I wis
19.
▲
Microsoft To Counter Open Source With 'Basic' Software Line
(informationweek.com)
5 points
by
adamdoupe
18y ago
|
3 comments
20.
▲
by
adamdoupe
18y ago
Can anybody who still uses Digg comment on if this makes Digg worthwhile again (or at least not a waste of time)?
21.
▲
The Myth of Moderate Exercise
(time.com)
35 points
by
adamdoupe
18y ago
|
66 comments
22.
▲
by
adamdoupe
19y ago
By singing? Actually this was really cool and would be fun to play with.
23.
▲
by
adamdoupe
19y ago
Steve Yegge's post "Effective Emacs" has instructions for how to do this, plus some other emacs tips: http://steve.yegge.googlepages.com/effective-emacs
24.
▲
Motherboard Transforms Chip Heat into Fan Power
(engadget.com)
1 points
by
adamdoupe
19y ago
|
0 comments
25.
▲
by
adamdoupe
19y ago
I voted this up for two reasons: 1. The article was well written and presented a point of view that is not commonly presented. 2. When I was younger (teenage years I think), I had this crazy idea to start smoking in order to see if I had th
26.
▲
by
adamdoupe
19y ago
Hey, I dunno if anyone is interested, but a year or so ago I create a site to get woot updates via Email or Text message. Check it out at http://wootwatchers.com and let me know what you think.
27.
▲
by
adamdoupe
19y ago
Keep drinking the Kool-Aid, I just started and it tastes wonderful... For those interested, Steve Yegge has an old post on emacs productivity tips: http://steve.yegge.googlepages.com/effective-emacs
28.
▲
by
adamdoupe
19y ago
This is extremely cool, (check out the video at the bottom), but I'd hardly consider the guy more of an artist than an entrepreneur, especially with this quote: "an unauthorized, ongoing video-art performance collaboration with the New Yor
29.
▲
by
adamdoupe
19y ago
"The Wall" by Jean-Paul Sartre deals with these issues. I read it in some BS French Lit class, but "The Wall" was one that stuck with me. I'd recommend reading it (no long at all) as it gives a good depiction of what it's like facing death
30.
▲
by
adamdoupe
19y ago
You've got it, but you can only downvote comments. And you can't downvote replies to your comment.
More ›