AppSecNotes
Blog
    Code Review Tips

    Code Review Tips

    How to Conduct Better Code Review

    Code Review Input Sanitization Secure Code Review 101
    Social Engineering - Phishing Emails: Part III

    Social Engineering - Phishing Emails: Part III

    How to Spot a Phishing Email?

    Social Engineering Phishing SOC VirusTotal
    Social Engineering - Phishing Emails: Part II

    Social Engineering - Phishing Emails: Part II

    Sending Emails

    Social Engineering Phishing MailerSend Gophish
    Social Engineering - Phishing Emails: Part I

    Social Engineering - Phishing Emails: Part I

    How to serve a Phishing Website

    Social Engineering Phishing Social-Engineer Toolkit
    Personal Site

    Personal Site

    Finally have a site!

    Astro TailwindCSS DaisyUI
© 2025 Carlos Ferreira
Developed by Carlos Ferreira using Astrofy.
Profile image
  • Home
  • CV
  • Blog
  • Web Application Security
    • Recon
      • Asset Discovery
      • Fingerprinting
      • Content Discovery
      • Exploration
    • Authentication
      • Methodology
      • Attack MFA
      • Attack OAuth
      • Brute-Force Authentication
      • Bypass Brute-Force Protection
      • Attack Tokens
      • Token Deserialization
    • NoSQL Injection
    • SQL Injection
    • Path Traversal for LFI
    • Remote File Inclusion
    • Excessive Data Exposure
    • IDOR
    • Mass Assignment
    • Race Conditions
    • 401 and 403 Bypass
    • CORS
    • CSRF
    • Open Redirect
    • XXE
    • Unrestricted File Upload
  • Mobile Application Security
    • ADB Shell from VM or Networked Device
    • Android Emulator Setup
    • Android Interception Process
    • Android Static Analysis
    • Enumerate Storage Buckets
    • Enumerate Firebase Databases
    • Android Dynamic Analysis
    • Android Reconnaissance
    • Reversing APKs
    • Android Patching Applications (for Breaking SSL Pinning)
    • APK with Metasploit Shell
    • Frida CodeShare
    • Objection with Frida Commands
    • Pulling APK From Device
    • Running Drozer
    • The Ghost Framework
    • Pulling IPA
    • iOS Static Analysis
  • DevSecOps
  • Hacking Gear
  • CVEs
  • Contact