Andrea Fortuna
AboutSearch
Tools
DFIR Toolkit OSINT Toolkit
  • Sep 6, 2019

    KolibriOS: a full operating system in 1.44 Megabytes

    KolibriOS is an open source operating system with a monolithic preemptive kernel, video drivers, for 32-bit x86 architecture computers. … read more »
  • Sep 5, 2019

    Million of Android devices are vulnerable to a new SMS phishing attack

    Researchers at CheckPoint said that over half of all Android handsets are vulnerable to a over-the-air (OTA) SMS phishing attack that could allow an attacker to route all internet traffic through a rogue proxy that can sniff traffic and steal… read more »
  • Sep 4, 2019

    The Secret Life of SIM Cards

    Are you a privacy obsessed? You can do everything in your power to avoid being tracked through your phone, such as change OS, avoid Google’s services, only use open-source apps from F-Droid, turn off WiFi and location services but…there is… read more »
  • Sep 3, 2019

    Cloud Security in AWS: 12 useful tips by Michał Brygidyn

    Michał Brygidyn is an AWS DevOps engineer with AWS Certified Security and a security researcher with CompTIA Security+ certification. … read more »
  • Aug 30, 2019

    Google researchers reveals iOS's exploit chains that changes everything we know about iPhone security

    Security researchers from Google’s Project Zero team say they have discovered a number of compromized websites which used previously undisclosed security flaws to attack any iPhone that visited them. … read more »
  • Aug 30, 2019

    "Another World" ported on 8bit Apple II

    Okay, [this](https://www.andreafortuna.org/2019/08/16/the-making-of-another-world/) is the third post dedicated to Another World (previous are this and this): I think now it’s clear how much I appreciate this game. … read more »
  • Aug 29, 2019

    Windows information gathering using Powershell: a brief cheatsheet

    During a penetration test, once you get a local access to a target, you should start a local assessment of the machine in order to plan a correct tactic for privileges escalation and lateral movement. … read more »
  • Aug 28, 2019

    Bluetana: detecting credit card skimmers with a smartphone app

    Credit card skimming is a type of credit card theft performed using a small device to steal credit card information during a legitimate credit card transaction. … read more »
  • Aug 27, 2019

    Cybersecurity Firm Imperva discloses Data Breach: some client info exposed

    Imperva disclosed today a security incident that led data exposure affecting a subset of customers using its Cloud Web Application Firewall (previously known as Incapsula). … read more »
  • Aug 27, 2019

    Warshipping: infiltrate corporate networks using postal service

    In the beginning it was the wardialing: the scan a block of numbers (dialed with specific software and a modem) often related to a company, in order to find out a fax or a modem response. … read more »
  • Aug 23, 2019

    Google, Mozilla and Apple blocks Kazakhstan root CA certificate to fight government's web surveillance

    Do you remember this post about Kazakhstan government attempts to deploy a root certificate in order to start a spying campaign of citizen’s HTTPS traffic? … read more »
  • Aug 22, 2019

    How to generate a Volatility profile for a Linux system

    When you start analyzing a Linux memory dump using volatility, the first problem you may need to face is choosing the correct memory profile. … read more »
  • Aug 21, 2019

    USBSamurai: how to make a remote controlled USB HID injecting cable for less than 10$

    An interesting article by Luca Bongiorni explains how to create a remote controlled HID injector cable using some simple hardware components easily purchased on online stores (with less then 10$) … read more »
  • Aug 20, 2019

    CVE-2019-9506: the Key Negotiation of Bluetooth (KNOB) Attack

    The vulnerability resides in the way devices choose an entropy value for encryption keys while establishing a connection: an attacker in close proximity to the victim’s device could intercept or manipulate encrypted Bluetooth traffic between two paired devices. … read more »
  • Aug 16, 2019

    The Making Of "Another World"

    Another World was one of the video games I most loved in my youth. … read more »
  • Aug 15, 2019

    OS X forensic acquisition: a basic workflow

    OS X is, in effect, a nix based system. Therefore the forensic image acquisition processes are very similar to those used on Linux systems. Today I’d like to share my personal acquisition workflow for Apple Mac systems, *suitable for OSX… read more »
  • Aug 14, 2019

    Microsoft CTF protocol can be exploited on all Windows versions

    Google Project Zero disclosed a vulnerability in CTF, a Microsoft protocol used by all Windows versions since Windows XP that can be exploited with ease. … read more »
  • Aug 13, 2019

    Yep, even your DSLR Camera can be infected with ransomware!

    Researchers have discovered that some DSLRs and mirrorless cameras are actually vulnerable to ransomware attacks. … read more »
  • Aug 12, 2019

    Why WhatsApp (and Telegram) messages are not really private?

    Do you think chatting in WhatsApp is completely private. No, sadly it's not! #privacy #whatsapp #telegram #signal #briar #riotim #metadata #e2e… read more »
  • Aug 8, 2019

    Reverse engineering and penetration testing on iOS apps: my own list of tools

    After a post focused on Android, another list of tools useful for penetration testing and reverse engineering of iOS applications. Also all this tools are OSS and freely available. … read more »
« Previous page Next page »

Andrea Fortuna

  • Andrea Fortuna
  • andrea@andreafortuna.org
  • andreafortuna
  • andreafortunaig
  • andrea-fortuna

Cybersecurity expert, software developer, experienced digital forensic analyst, musician