Dimitri 0s
@Ch0pin
Senior Security Researcher @Microsoft. Developer of https://github.com/Ch0pin/medusa
Lots of interesting stuff coming this fall…I’ll be flying to Berlin and Luxembourg — talks, hacks and mobile related stuff See you at Nullcon in September and Hack.lu in October!

🚀 Medusa 3.1.0 is out! Now compatible with Frida ≥ 17 and packed with new modules & improvements. github.com/Ch0pin/medusa/… #Medusa #Frida #AppSec #AndroidPentesting
Excited to share that my latest research has been accepted at NULLCON Berlin! It’s a follow-up to my previous work presented at Black Hat Europe — this time, we’re diving even deeper. See you in September in Berlin! 🇩🇪

Here are some thought-provoking unanswered questions🤔: - Is free will an illusion? - Can morality be objectively defined without culture or religion ? ...and the greatest of all..... - Why do people willingly deobfuscate Java code?
Kudos to @Wixter_07 for solving ‘Four’ and ‘Secure Browser’! Friendly reminder :) Looks like ‘Insider’ is still holding strong with only 11 solves so far github.com/Ch0pin/uncrack…
Congrats to @r_srikesh for solving four — amazing job! github.com/Ch0pin/uncrack…
Getting started in mobile hacking? 😎 Check out Medusa by @Ch0pin! A framework to help you pentest Android & iOS mobile applications! 🔗 github.com/Ch0pin/medusa
Want to add your challenge to github.com/Ch0pin/uncrack… ? Go ahead and open a PR! Just make sure it showcases a real vulnerability — ideally a whole class. Current ones focus on interesting behaviors like bypasses. Would love to include yours! #AndroidSecurity
Great work @joo_elsaka on solving “four” from github.com/Ch0pin/uncrack… — nicely done, mate!
While vendors dismiss the risk of vulnerabilities that require a third-party app to exploit, considering such scenarios unlikely to occur in practice Google bans Google Bans 158,000 Malicious Android App Developer Accounts in 2024 thehackernews.com/2025/01/google…
Yet another brilliant solution to the Insider challenge — this time by @AlQa3Qa3M0x0101 👏 Exceptional work!
The Insider ( github.com/Ch0pin/uncrack…) is not for quitters — and @zep3hyr clearly isn’t one 😎. Well done on solving this challenge! 👏
The level of ignorance in mobile pentesting is reaching alarming levels.
x64 Linux Binary Exploitation by @Ch0pin Basic: valsamaras.medium.com/introduction-t… Return into lib: valsamaras.medium.com/introduction-t… RoP Chains: valsamaras.medium.com/introduction-t… Stack Canaries: valsamaras.medium.com/introduction-t… ASLR: valsamaras.medium.com/introduction-t… #exploit #cybersecurity
CVE-2025-29805: My latest contribution involved discovering a vulnerability in Outlook for Android that could have allowed attackers to read and write sensitive user data. msrc.microsoft.com/update-guide/e…
Excellent intro to x64 Linux Binary Exploitation by @Ch0pin Basic: valsamaras.medium.com/introduction-t… Return into lib: valsamaras.medium.com/introduction-t… RoP Chains: valsamaras.medium.com/introduction-t… Stack Canaries: valsamaras.medium.com/introduction-t… ASLR: valsamaras.medium.com/introduction-t… #exploit #infosec
Collection of links to cybersecurity related resources (write-ups, blog posts and papers) github.com/0xor0ne/awesom… #infosec #cybersecurity
Android Kernel Adventures: Insights into Compilation, Customization and Application Analysis #AndroidKernel #Compilation #Customization #ApplicationAnalysis #SecurityAnalysis revflash.medium.com/android-kernel…