Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
An Android Spy App Left 1.7M Passwords and Nude Photos Exposed to Hackers (forbes.com/sites/thomasbrewster)
9 points by rbanffy on Aug 13, 2018 | hide | past | favorite | 2 comments


How would you get involved in this sort of security research? It's been an interest of mine for awhile. I have experience in reverse engineering binary files and malware but not so much experience in the "live internet stuff".

Would you start with simple CTF tasks?

I assume they used some sort of application to view the http requests that the phone was making and where able to figure out the right endpoints from that?

Thanks in advance.


A simple GET request? How can a single developer be so grossly negligent as to not protect their API's?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: