<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Ahmad Abolhadid on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/ahmad-abolhadid/</link>
    <description>Recent content in Ahmad Abolhadid on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 03 Mar 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/ahmad-abolhadid/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>BlackBoxAI: AI Agent can get your computer fully compromised</title>
      <link>https://insinuator.net/2026/03/blackboxai-ai-agent-can-get-your-computer-fully-compromised/</link>
      <pubDate>Tue, 03 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/03/blackboxai-ai-agent-can-get-your-computer-fully-compromised/</guid>
      <description>&lt;p&gt;AI agents are here, there, and everywhere. Smarter, faster, and more skilled,&#xA;they gain greater autonomy and trust. We trust their capabilities to do many&#xA;tasks much faster and sometimes better than we can. We trust them as they&#xA;usually demonstrate their eagerness to please us and fulfill our commands. Isn’t&#xA;that too good to be true, and we might be dealing with a double-edged sword&#xA;here? Can attackers use the same capabilities of the AI agents to attack their&#xA;own users? Can they exploit their eagerness to please their users to fulfill the&#xA;attackers’ intentions? And most importantly: what’s the worst that could happen&#xA;if you fully trust some random AI Agent?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Is Google Play Protect a Reliable Malware Detector?</title>
      <link>https://insinuator.net/2024/05/is-google-play-protect-a-reliable-malware-detector/</link>
      <pubDate>Fri, 03 May 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/05/is-google-play-protect-a-reliable-malware-detector/</guid>
      <description>&lt;p&gt;Google Play Protect is a built-in Android solution that enhances devices’ security. Its main job is to detect and block malware on Android devices. Several malware families were known for bypassing Play Protect checks in recent years. This brings us to an important question: “Is Google Play Protect a Reliable Malware Detector?”. This blog post shows how Play Protect deals with various Android malware in different scenarios. I deal with Play Protect as a black box.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spymax: The android RAT and it works like that</title>
      <link>https://insinuator.net/2022/09/spymax-the-android-rat-and-it-works-like-that/</link>
      <pubDate>Wed, 07 Sep 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/09/spymax-the-android-rat-and-it-works-like-that/</guid>
      <description>&lt;p&gt;Spymax is a mobile Remote Administration Tool (RAT) that enables an attacker to&#xA;control victims’ devices through an Android malware. Once the malware is&#xA;installed on a phone, the attacker can execute many attacks that highly impact&#xA;the confidentiality and integrity of the victim’s data, as well as the victim’s&#xA;privacy. It is powerful, widely available, and does not require root privileges&#xA;on the victim’s device. In this blogpost, I show the capabilities of this RAT&#xA;and analyze how its Android malware works.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Having Fun with Google MDM Solution</title>
      <link>https://insinuator.net/2021/01/having-fun-with-google-mdm-solution/</link>
      <pubDate>Thu, 21 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/01/having-fun-with-google-mdm-solution/</guid>
      <description>&lt;p&gt;It’s Friday, you managed to escape for a couple of hours from a busy working day&#xA;to see a doctor. Now you have to wait in a boring waiting room at the clinic&#xA;until it’s your turn to see her majesty. What would you like to do in this time?&#xA;Answer pending business emails, get lost in social media, or choose a new theme&#xA;to make your iPhone look awesome?  What about: all of the above? It’s nice to&#xA;have everything on your iPhone: MDM enrollment to access business data, in&#xA;addition to jailbreak for device freedom. However, MDM solutions ban jailbroken&#xA;devices, because they are not secure enough to handle sensitive business data.&#xA;And so, cat and mouse games of jailbreak detection/bypass between MDM solutions&#xA;and some users develop.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 teaser: Hacking mobile apps</title>
      <link>https://insinuator.net/2019/11/troopers20-teaser-hacking-mobile-apps/</link>
      <pubDate>Thu, 28 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/troopers20-teaser-hacking-mobile-apps/</guid>
      <description>&lt;p&gt;“If it’s a thing, then there’s an app for it!”…We trust mobile apps to process our bank transactions, handle our private data and set us up on romantic dates. However, few of us care to wonder,”How (in)secure can these apps be?” Well… at Troopers 20, you can learn how to answer this question yourself!&lt;/p&gt;&#xA;&lt;p&gt;In our 2 day long “Hacking mobile apps” workshop, we teach how to find security vulnerabilities in mobile apps, exploit them and defend against them. We start from scratch, therefore no prior experience in hacking or developing mobile apps is required. Whether you want to learn how to pentest mobile apps, you are an app developer that fancies to secure his/her apps, or just curios, our workshop is a jumpstart to your goal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS19 Training Teaser: Hacking mobile applications</title>
      <link>https://insinuator.net/2019/01/troopers19-training-teaser-hacking-mobile-applications/</link>
      <pubDate>Wed, 16 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/troopers19-training-teaser-hacking-mobile-applications/</guid>
      <description>&lt;p&gt;“If it’s a thing, then there’s an app for it!”…We trust mobile apps to process our bank transactions, handle our private data and set us up on romantic dates. However, few of us care to wonder,”How (in)secure can these apps be?” Well… at Troopers 19, you can learn how to answer this question yourself!&lt;/p&gt;&#xA;&lt;p&gt;In our 2 day long “Hacking mobile applications” workshop, we teach how to find security vulnerabilities in mobile apps, exploit them and defend against them. We start from scratch, therefore no prior experience in hacking or developing mobile apps is required. Whether you want to learn how to pentest mobile apps, you are an app developer that fancies to secure his/her apps, or just curios, our workshop is a jumpstart to your goal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>AndroTickler: Tickling Vulnerabilities out of Android Apps</title>
      <link>https://insinuator.net/2018/02/androtickler-tickling-vulnerabilities-out-of-android-apps/</link>
      <pubDate>Sat, 10 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/androtickler-tickling-vulnerabilities-out-of-android-apps/</guid>
      <description>&lt;p&gt;If you attack someone, they will defend themselves, but if you tickle them, they will eventually crack open. This surprisingly applies to Android apps as well! Therefore, I created AndroTickler, not to test apps against certain attacks or examine them for specific vulnerabilities, which developers would learn to avoid. However, it helps pentesters to analyze and test apps in their own style, but in a faster, easier and more flexible way. AndroTickler is a Swiss-Army-Knife pentesting tool for Android apps. It provides information gathering, static and dynamic analysis features, and also automates actions that pentesters frequently do and highly need during their pentests. In addition, it makes use of the powerful Frida to hook to the app and manipulate it in real-time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exploitation of IMS in absence of confidentiality and integrity protection</title>
      <link>https://insinuator.net/2017/02/exploitation-of-ims-in-absence-of-confidentiality-and-integrity-protection/</link>
      <pubDate>Fri, 17 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/exploitation-of-ims-in-absence-of-confidentiality-and-integrity-protection/</guid>
      <description>&lt;p&gt;IP Multimedia Subsystem (IMS) offers many multimedia services to any IP-based access network, such as LTE or DSL. In addition to VoLTE, IMS adds service provider flexibility, better QoS and charging control to the 4th generation of mobile networks. IMS exchanges SIP messages with its users or other IMS and usually these communications are secured by TLS or IPSec. But if an attacker manages to break the confidentiality and the integrity with IMS, he would find it vulnerable to several attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SAMLReQuest Burpsuite Extention</title>
      <link>https://insinuator.net/2016/06/samlrequest-burpsuite-extention/</link>
      <pubDate>Mon, 06 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/samlrequest-burpsuite-extention/</guid>
      <description>&lt;p&gt;Security Assertion Markup Language (SAML) is an XML standard for exchanging authentication and authorization data between a Service Provider (SP) and an  Identification Provider (IdP). SAML is used in many Single Sign-On (SSO) implementations, when a user is authenticated once by IdP to access multiple related SPs. When a user requests to access a SP, it creates a SAML Authentication Request and redirects the user to IdP to be authenticated according to this authentication request. If the user is successfully authenticated, IdP creates a SAML authentication response and sends it back to SP through the user’s browser.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Imma Chargin Mah Lazer-How to protect against (D)DoS attacks</title>
      <link>https://insinuator.net/2016/04/imma-chargin-mah-lazer-how-to-protect-against-ddos-attacks/</link>
      <pubDate>Fri, 01 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/imma-chargin-mah-lazer-how-to-protect-against-ddos-attacks/</guid>
      <description>&lt;p&gt;Denial of Service (DoS) attacks aim to make services and systems unavailable to legitimate users . If these attacks are performed by multiple sources at the same time and for the same target, they are called Distributed Denial of Service (DDoS) attacks. This talk “Imma Chargin Mah Lazer” describes different types of (D)DoS attacks that are out in the wild and are seen on a daily basis by different corporations. Furthermore,  a multi-layered strategy to mitigate such kinds of attacks has been presented within the talk. The speaker is Dr. Oliver Matula, an IT security researcher at ERNW who holds a PHD degree in physics. He presented the topic in a simple way which eases the delivery of information to audience of different technical levels and backgrounds.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 16: Wireshark in IP version 6</title>
      <link>https://insinuator.net/2016/03/troopers-16-wireshark-in-ip-version-6/</link>
      <pubDate>Tue, 29 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/troopers-16-wireshark-in-ip-version-6/</guid>
      <description>&lt;p&gt;Wireshark in IP version 6 workshop was a part of IPv6 summit sessions of Troopers 16. It was held by Jeffery Carrell on the second day of IPv6 summit on Tuesday, the 15th of March.  The workshop was generally divided into two sections: a short introduction to IPv6 and analyzing some IPv6 packets on Wireshark.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Introduction to IPv6&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;IPv6 protocol was defined at the end of 1990’s, mainly to provide a huge address pool after realizing that the world would run out of IPv4 addresses quickly. The work on IPv6 started before the introduction of NAT and Private addressing to IPv4, which are considered temporary solutions of IPv4 address shortage problem. IPv6 address consists of 128 bits, divided into 8 groups called &lt;em&gt;nibbles&lt;/em&gt;, &lt;em&gt;quibbles&lt;/em&gt; or &lt;em&gt;hextets&lt;/em&gt; separated by colons. Each nibble consists of four hexadecimal digits. The 128 bits address length provides 340 trillion trillion trillion addresses. An IPv6 address is divided into two parts: the left part is the network identifier while the right one is the host identifier. The default prefix is /64 which divided the IP address into two halves. An IPv6 address looks as follows: 2001:0db8:1010:61ab:f005:ba11:00da:11a5/64&lt;/p&gt;</description>
    </item>
    <item>
      <title>Denial of Service attacks on VoLTE</title>
      <link>https://insinuator.net/2016/02/denial-of-service-attacks-on-volte/</link>
      <pubDate>Wed, 03 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/denial-of-service-attacks-on-volte/</guid>
      <description>&lt;p&gt;Some weeks ago Hendrik explained in his blogpost &lt;a href=&#34;https://www.insinuator.net/2016/01/security-analysis-of-volte-part-1/&#34;&gt;Security Analysis of VoLTE, Part 1&lt;/a&gt; some attack vectors for Voice over LTE (VoLTE). One attack vector introduced was Denial of Service (DoS), which I also discussed in my Masterthesis “Evaluation of IMS security and Developing penetration tests of IMS”.&lt;/p&gt;&#xA;&lt;p&gt;In general, DoS attacks aim to prevent a system or a network from efficiently providing its service to legitimate users . The impact of such attacks can vary from a big degradation of quality to total blockage. DoS can occur on users level, where a user or a group of users cannot use the service. But the common conception of DoS is on the service level, where the whole service is broken, unstable or totally down. This blog post is about targeting DoS of the whole VoLTE service by attacking IMS.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
