作者
Alaeddine Mesbahi
Alaeddine Mesbahi is the co-founder and CEO of Ostorlab, where he leads the company's vision for automated security testing and vulnerability management. Before founding Ostorlab, he held roles at Google on the security automation team and at Cisco's Trust Office. Alaeddine started his career as a penetration tester, building deep hands-on expertise in offensive security and technical research. He has presented at leading industry conferences including Black Hat US, BruCon, and OWASP AppSec, and holds several professional certifications such as OSCP, OSCE, and GREM.
借助 Proxy 对象插桩增强 PostMessage XSS 检测
本文介绍一种利用 JavaScript Proxy 对象检测 PostMessage 跨站脚本(XSS)漏洞的新方法,用以增强传统的动态模糊测试技术。
2024年4月4日
2023 年回顾
2023 年已经结束,是时候回顾过去,并以乐观的心态迎接 2024 年了。
2024年1月10日
全新 OWASP Mobile Top 10
全新 OWASP Mobile Top 10 发布:改进、更新内容以及幕后故事。
2023年11月27日
Ostorlab 完成 SOC 2 Type II 审计,彰显对安全与数据保护的承诺
Ostorlab 已成功完成 SOC2 Type 2 审计,彰显了其对安全与数据保护的承诺。
2023年4月12日
Alaeddine Mesbahi 的更多文章
这些第三方 SDK 都把我的用户数据发到哪里去了?😨
Ostorlab 的新功能专注于帮助团队了解、跟踪和搜索其攻击面,看清攻击者正在看到和瞄准的内容,简而言之,就是可能导致组织被攻破的一切。
2023年2月2日
Ostorlab 的 2022 年
2022 年给全球带来了诸多挑战,包括战争、经济不确定性以及世界许多地区不断攀升的通货膨胀。尽管面临这些挑战,Ostorlab 仍然非常感恩能度过极为成功的一年。
2023年1月3日
移动应用中的 Text4Shell(CVE-2022-42889)……我需要担心吗?
CVE-2022-42889 是 Apache Commons Text 库中的一个漏洞,由字符串插值滥用功能强大的处理器所致,存在于 Amazon Shopping、Udemy 和 Grammarly 等热门应用中。本文探讨该漏洞对移动应用的适用性和风险。
2022年10月24日
Ostorlab vs. NowSecure vs. MobSF vs. Immuniweb vs. AppKnox vs. Quixxi vs. Oversecured
本文全面审视各类移动安全扫描解决方案,同时着重指出真正让它们彼此区别开来的地方。
2022年3月21日
SSL Pinning 通用绕过……从原理到基于 LLDB 的完整可用 PoC
本文讨论如何在无需真正绕过的情况下“绕过”SSL 证书锁定。听起来有些费解?我们将讲解其原理,用 Python 基于 LLDB 构建完整的 PoC,最后将其扩展到其他有趣的任务。
2021年5月18日