RSSAmplifier

Blog

Whiskey Tango Foxtrot

Let's explore security adventures and get some vitamins together.

avicoder.meRSS feed ↗10 posts

Latest posts

The Art of Building an AppSec Program That Developers Love

Creating a robust AppSec program is no easy feat. It requires a deep understanding of both the development process and security principles. But what does it take to build an AppSec program that not only secures applications but also wins the hearts of developers??? Let’s explore some strategies: Understanding the Developer’s Mindset Developers are often under immense pressure to deliver new…

Host a bug bounty program under $500!

Backstory Security for our customers is our top priority. As a startup, we must continually seek ways to be resourceful by investing wisely in our business while safeguarding the information of our users. By being resourceful, we can reinvest possible savings into other initiatives that would improve the experience of our users and fuel the growth of the business. It is clear that bug bounties can…

Learning and Breaking GraphQL

tldr; Apollo's Odyssey GraphQL Assessment had a security vulnerability that allowed anyone to view the correct answer before submitting the final report. Learning I developed a interest in learning more about GraphQL in the past couple of years, for the simple reason that it is still quite a new technology for some of the application developers, and due to its flexibility to adapt to customer…

Security of Google Groups

Here we go again! I’m back with another series of discussion topics. This time it’s Google Workspace. Alphabet has a variety of applications for organisations that help you work with your teams and clients, but one of the most powerful is Google Workspace. There are a ton of applications that allow you to access your emails, calendars and contacts from anywhere with an internet connection. It also…

YaY!! CISSP Certified

Following my CISSP certification, I have a few opinions to share. Newcomers - don’t wait, opt for it! In fact, it should be one of the first certificates pursued after a couple of years of experience. I regret not doing it earlier. I think it is not as complicated as it has been advertised to be, but it depends on the individual. I have only read a few books and I believe you will be ready to…

Security Roadmap, Strategies and Challenges

It’s hard to develop a cybersecurity roadmap since several elements need to be considered, such as compliance and risk posture, policy framework, detection and response capabilities, resilience and recovery after a breach. Hi Everyone 👋 , in this part-series I’m gonna to be sharing about developing a security roadmap, that usually comes after asking some relevant questions. Also, I’ll talk about…

Free Email Provider List

Using this API endpoint https://avicoder.me/api/mailproviders.json , a user can retrieve a list of free email providers. The information here is not exhaustive and is based on the gist people have provided. Daily updates are made to it. Thank you

Root AVD and Install Magisk

Mostly I have done the android app penetration testing on GenyMotion. The problem is that a few apps aren’t working properly lately because of architectural requirements and incompatibility. Android Virtual Devices (AVD) can be a good alternative, but the images do not support rooting. So let’s root the AVD to overcome this limitation. The following guide is what I used to setup env on Mac…

Dual TZ - Fitbit

Fist bump folks, I don’t have much here about to talk about this Fitbit clock-face. One of my friend wanted to have an elegant clock-face for her Fitbit sense with support of dual clock so I made one on weekends. It is compatible with Sense and Versa 3 and built on Fitbit SDK 5.0 You can try it on your Fitbit Sense by installing it from here It has these features and more will be added depending…

Hackerone inscope urls

This is the compilation of all the in scope urls found in the public bugbounty program on hackerone. Updated daily! ⤋ Download JSON file