ADAditya Dixitinblog.dixitaditya.com·Apr 9 · 9 min readHijacking iOS Deep Links in a Health App Using Custom URL SchemesOverview During a recent pentest of an iOS health application (let's call it MedVault), I came across something interesting. The app was using custom URL schemes for deep linking but had no Universal 133LA
ADAditya Dixitinblog.dixitaditya.com·Jan 29, 2023 · 4 min readSelfie - Damn Vulnerable DeFi #06Objectives There's a pool as always, and it offers flash loans of DVT tokens. There's also a governance mechanism that controls the pool. The initial token supply is 2 million, and the pool has 1.5 million DVT. We have 0. Our goal is to drain the poo...00
ADAditya Dixitinblog.dixitaditya.com·Jan 29, 2023 · 4 min readThe Rewarder - Damn Vulnerable DeFi #05Objectives There’s a pool offering rewards in tokens every 5 days for those who deposit their DVT tokens into it. There are 4 other participants who have already deposited some tokens and claimed their rewards. We need to claim the most rewards for o...00
ADAditya Dixitinblog.dixitaditya.com·Jan 26, 2023 · 3 min readSide Entrance - Damn Vulnerable DeFi #04Objectives A lending pool allows users to deposit and withdraw ETH. It also offers flash loans for free. The pool has 1000 ETH in balance and we start with 1 ETH. Our objective is to drain the pool. Smart Contract Analysis SideEntranceLenderPool.sol ...00
ADAditya Dixitinblog.dixitaditya.com·Jan 22, 2023 · 3 min readTruster - Damn Vulnerable DeFi #03Objectives There's a lending pool with a million DVT tokens. This pool offers a flash loan for free. But as it is with all flash loans, the user must pay back the loan in the same transaction. Our objective is to drain all the funds from the lending ...00