0xc0ffee / Ilyass El Hadi (@0xc0ffee_) 's Twitter Profile
0xc0ffee / Ilyass El Hadi

@0xc0ffee_

Appsec stuff @Mandiant/GCloud, bug bounty hunter, occasional CTF player. Opinions ≠ employer’s.

ID: 381590375

calendar_today28-09-2011 15:59:11

325 Tweet

1,1K Followers

507 Following

James Kettle (@albinowax) 's Twitter Profile Photo

Turbo Intruder can now trigger a callback per socket read, so you can extract and use response data before the response is fully delivered! github.com/PortSwigger/tu…

Seunghun Han (@kkamagui1) 's Twitter Profile Photo

I just submitted my new tool, "BitLeaker" to the CFP system of #BlackHat USA 2019. BitLeaker can extract the Volume Master Key (VMK) of BitLocker from the TPM. I also prepared new and not-published feature for Black Hat USA. I hope I could present it! Stay tuned! Black Hat

I just submitted my new tool, "BitLeaker" to the CFP system of #BlackHat USA 2019. BitLeaker can extract the Volume Master Key (VMK) of BitLocker from the TPM. I also prepared new and not-published feature for Black Hat USA. I hope I could present it! Stay tuned! <a href="/BlackHatEvents/">Black Hat</a>
0xrudra (@0xrudrapratap) 's Twitter Profile Photo

“[CVE-2019–5418] Ruby on Rails Arbitrary File Content Disclosure Analysis| Victor Zhu” by Victor Zhu link.medium.com/kn17maXbNV

Ian Bouchard (@corb3nik) 's Twitter Profile Photo

Just posted my writeup for INS'Hack 2019's "Bypasses Everywhere" XSS challenge - Bypassing CSP and Chrome's XSS auditor with Iframes - corb3nik.github.io/blog/ins-hack-…

0xc0ffee / Ilyass El Hadi (@0xc0ffee_) 's Twitter Profile Photo

3 day BurpSuite Pro training given by Nicolas Grégoire at NorthSec was excellent! Workflow improved heaps, learned a lot of neat tricks and ready to use them to find more bugs! Recommended!

0xc0ffee / Ilyass El Hadi (@0xc0ffee_) 's Twitter Profile Photo

My writeup for the FacebookCTF "Secret Note Keeper" challenge. Thank you Facebook Security for this great event! #ctf #fbctf #facebookctf 0xc0ffee.io/blog/FacebookC…

Louis Dion-Marcil (@ldionmarcil) 's Twitter Profile Photo

Here are my slides for "Cache Me If You Can: Messing with Web Caching", presented OWASP AppSec California & NorthSec! 🎉 Material includes: - Web Caching 101 - Web Cache Deception - Edge Side Include Injection - Web Cache Poisoning ...with real bugs showcased! drive.google.com/open?id=19IedR…

Here are my slides for "Cache Me If You Can: Messing with Web Caching", presented <a href="/AppSecCali/">OWASP AppSec California</a> &amp; <a href="/NorthSec_io/">NorthSec</a>! 🎉

Material includes:
- Web Caching 101
- Web Cache Deception
- Edge Side Include Injection
- Web Cache Poisoning
 
...with real bugs showcased!

drive.google.com/open?id=19IedR…
Tom Gallagher (@secbughunter) 's Twitter Profile Photo

Jonathan Birch is sharing tips on new Unicode normalization bugs (HostSplit/HostBond) he discovered. So many vulns found. He is encouraging folks to look around for more and showing how.

Jonathan Birch is sharing tips on new  Unicode normalization bugs (HostSplit/HostBond) he discovered. So many vulns found. He is encouraging folks to look around for more and showing how.
Jess (@hogarth45_) 's Twitter Profile Photo

Had a fun week collabing with 0xc0ffee / Ilyass El Hadi that lead to some cool SSRFs in a PDF generator. Looking forward to working with him again! #BugBounty

Alex Birsan (@alxbrsn) 's Twitter Profile Photo

Hey :) If you want to know how you can get started in bug bounties, the first and most important step is learning how to use Google, because that'll be your main tool for your whole career.

shubs (@infosec_au) 's Twitter Profile Photo

Half of the success in source code auditing is just having the confidence and faith that you will find something. It doesn't matter what language it is or how many times it's been audited. This has proven true throughout my career. Just. Don't. Give. Up.

Louis Dion-Marcil (@ldionmarcil) 's Twitter Profile Photo

I wrote a thing with my colleague 0xc0ffee / Ilyass El Hadi & Charles Prevost, about how we've been leveraging offensive webapp testing during Red Teams. 4 use cases of external breaches using webapps inside, enjoy! #appsec cloud.google.com/blog/topics/th…

Armadin (@armadinsecurity) 's Twitter Profile Photo

Armadin launches today with the largest combined Seed + Series A in cybersecurity history. AI-driven hyperattacks are here and human-led defenses can't keep pace. Meet the ultimate attacker: a swarm of AI agents built to prove what's actually exploitable before it is.

Armadin launches today with the largest combined Seed + Series A in cybersecurity history. AI-driven hyperattacks are here and human-led defenses can't keep pace. Meet the ultimate attacker: a swarm of AI agents built to prove what's actually exploitable before it is.