Samsung_Vulnerabilities
Oversecured discloses a report of 176 vulnerabilities discovered in Samsung preinstalled apps between 2022 and 2025, with 140 detailed, all fixed in collaboration with Samsung.
采用三状态比较模型,结合响应体归一化、Canary 标记、WAF/限流防护机制,有效降低误报;原生支持 GraphQL 和多租户场景。
A Burp Suite extension for cross-identity / cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.
Authz-ExeC replays every request you make as a privileged user using each identity you configure (a low-privilege user, a second tenant, unauthenticated), compares each response against the privileged one, and shows a live colour matrix of where access control held, broke, or needs review. Think Autorize / AuthMatrix — rebuilt on the modern Montoya API, hardened against false positives, with first-class multi-tenant and GraphQL support.
⚡ Core
Cookie, Authorization (JWT), and arbitrary headers (X-Tenant-Id,
X-Api-Key, …), strip all auth (unauthenticated), or apply regex ID-rewrite rules for BOLA.alg:none / strip-signature helpers).🎯 Accuracy (low false-positive)
200 + "access denied"), empty
results (row-level filtering), and login redirects. Per-verdict confidence score.🧩 Coverage
204/header-based
responses; skips only rendered HTML pages.Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.
根据分类、Topic 和编程语言匹配的相似项目。
Oversecured discloses a report of 176 vulnerabilities discovered in Samsung preinstalled apps between 2022 and 2025, with 140 detailed, all fixed in collaboration with Samsung.

An LSPosed module that hooks MIUI SystemUI back gestures using modern Xposed API 102 for research and customization.
OneStep4.0 is a multi-window desktop container for Android that requires root or system-level privileges, enabling a main window with several side windows for efficient app multitasking.