AppSec Guy
Фотография
нажмите — покажем
нажмите — покажем
https://cocomelonc.github.io/malware/2026/03/05/malware-cryptography-44.html next one from my blog.
Today, we will move away from classical encryption and use pure #mathematics. We are going to use the Discrete Fourier Transform (DFT) to turn our #shellcode into #frequency noise.
You might wonder: is this just a “academic” trick, or does it have real-world applications in high-end cyber espionage?
While we don’t often see a pure DFT loop in every commodity #malware, the philosophy behind it is a hallmark of sophisticated #APT groups. Here is why this idea is more “real” than it looks.
twitter/X
#hacking #cybersecurity #programming #research #maldev #book #threatintel #purpleteam #ethicalhacking #math
384 · AppSec Guy
Ссылка
нажмите — покажем
нажмите — покажем
CTFs are not same anymore, there is no any easy, medium challenge, because AI solves it.
it is slowly killing competitive environment of CTFs, making it pay-to-win game where whoever pays most for resources and AI wins mostly.
One of our friends krauq (FMC, Project Sekai player) left CTFs. its so strange.
https://blog.krauq.com/post/ctf-is-dying-because-of-ai
3 · 388 · AppSec Guy
Фотография
нажмите — покажем
нажмите — покажем
🇺🇿 O‘zbekistonda ilk Bug Bounty platformasi — Oq Doppi
Prezidentimiz tomonidan belgilangan 2030-yilgacha kiberxavfsizlikni rivojlantirish strategiyasiga muvofiq, mamlakatimizda axborot tizimlari xavfsizligini ta’minlash va zaifliklarni oldindan aniqlash muhim vazifalardan biridir.
Shu yo‘nalishda TuranSecurity tomonidan O‘zbekistonda birinchi Bug Bounty platformasi — Oq Doppi ishga tushirildi.
🔎 Bug Bounty nima?
Bu kompaniyalarga o‘z tizimlaridagi xavfsizlik zaifliklarini mustaqil va professional ethical (white hat) mutaxassislar yordamida aniqlash imkonini beradigan zamonaviy yondashuvdir. Natijada muammolar erta bosqichda aniqlanadi va xavflar oldi olinadi.
🎩 Nega “Oq Doppi”?
“White hat hacker” — tizimlarni himoya qilish uchun ishlaydigan mutaxassislarni anglatadi.
“Oq Doppi” esa ushbu tushunchaning milliy talqini bo‘lib, ishonch, himoya va mas’uliyat ramzidir.
🤝 Siz uchun qanday foyda beradi?
• Tizimlaringizdagi zaifliklarni real mutaxassislar aniqlaydi
• Xavfsizlik darajasi sezilarli darajada oshadi
• Muammolarni oldindan bartaraf etish imkoniyati
• Qonuniy va nazorat ostidagi test muhiti
🚀 Platforma bugundan ishga tushdi
Birinchi scope doirasida 2 ta dastur ochildi:
• TuranSec — *.turansec.uz
• Oq Doppi — platformaning o‘zi
🛡 Agar siz kompaniya bo‘lsangiz — tizimlaringizni himoya qiling
🛡 Agar siz mutaxassis bo‘lsangiz — o‘z bilimingizni amalda sinab ko‘ring
Oq Doppi — ishonchli va zamonaviy kiberxavfsizlik yechimi.
Havola: https://oqdoppi.uz
#OqDoppi #CyberSecurity #BugBounty #Uzbekistan #TuranSecurity
5 · 218 · AppSec Guy
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
Team1337 got 11th place at AITU CTF 2026 Quals, 4th place at international division.
Team got qualified for Final which will be held at Astana, Kazakhstan on April 24–25.
1337 did really strong performance against other international teams, we were able to get multiple firstbloods.
Congrats to our friends FR13NDS TEAM, they organized event really smooth.
@AppSec_guy
557 · AppSec Guy
login to linkedin > newbie posts wrong post about cybersec > suffer > repeat everyday
but at least learnt to educate instead of hate, but some people have brain issues not knowledge issues.
1 · 565 · AppSec Guy
Фотография
нажмите — покажем
нажмите — покажем
Brothers from FMC/L3ak inviting to join them on onsite.
1 · 488 · AppSec Guy
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
Фотография
нажмите — покажем
нажмите — покажем
🔥 Team1337 JAMOAMIZ — AITU CTF 2026 XALQARO MUSOBAQA G'OLIBI!
Kompaniyamiz mutaxassislari kiberxavfsizlik yo‘nalishida yana bir yirik xalqaro musobaqada g‘alabani qo‘lga kiritdi.
🇰🇿 24–25-aprel kunlari Qozog‘istonning Astana shahrida o‘tkazilgan AITU CTF 2026 musobaqasining final bosqichida Team1337 jamoamiz Rossiya 🇷🇺, Qozog‘iston 🇰🇿, Janubiy Koreya 🇰🇷, Mo‘g‘iliston 🇲🇳, Yaponiya 🇯🇵 va boshqa davlatlardan kelgan TOP-20 jamoa orasidan faxrli 1-o‘rinni egallab, musobaqa chempioniga aylandi.
Jamoa a'zolari tadbir doirasida o'tkazilgan GeoGusser musobaqasida 2-o'rinni qo'lga kiritdi.
Mazkur musobaqa Astana IT University hamda FR13NDS TEAM tomonidan tashkil etildi. Tashkilotchilarga yuqori saviyada o‘tkazilgan tadbir va samimiy mehmondo‘stlik uchun alohida minnatdorchilik bildiramiz.
❗️ Eslatib o‘tamiz, Turan Security kompaniyasi atiga 2 yil avval 4 kishilik jamoa bilan faoliyatini boshlagan. Bugungi kunda esa 40 ga yaqin mutaxassislarni birlashtirgan holda, O‘zbekistonda kiberxavfsizlik sohasini rivojlantirish va uni xalqaro maydonda munosib namoyon etish yo‘lida to'xtovsiz harakat qilmoqda.
Nasib bo'lsa biz to‘xtamaymiz. Oldinda yanada katta yutuqlar bor.
@turansecurity | www.turansec.uz | [email protected]
1 · 921 · AppSec Guy
to_do_list.append()
Write custom single threaded kernel which does for each syscall:
char fu[64] = "Fu Stick dude!\n";
write(1, fu, strlen(fu));
767 · AppSec Guy
Фотография
нажмите — покажем
нажмите — покажем
How to absolutely fail (Microsoft edition):
> Fail to triage researcher's hard work
> Got 0 days published
> 0 day is LPE through Defender itself
> Fail to patch it
> Get another Defender 0 day bypassing patch
@appsec_guy
1 · 482 · AppSec Guy
Файл
GSF Press Release 2026.09.11 _ Tunisian Court Extends.pdf · 210 КБ · нажмите — покажем
GSF Press Release 2026.09.11 _ Tunisian Court Extends.pdf · 210 КБ · нажмите — покажем
FOR IMMEDIATE RELEASE
Ten Months Without Evidence
Tunisian Court Extends Pretrial Detention of the Sumud 4 By Four Months Amidst Escalating Government Repression of Palestine Solidarity
2 · 201 ·