22sh (@0x22sh) 's Twitter Profile
22sh

@0x22sh

lazy man with a busy life

ID: 727584637749465088

calendar_today03-05-2016 19:44:30

535 Tweet

992 Takipçi

1,1K Takip Edilen

Masato Kinugawa (@kinugawamasato) 's Twitter Profile Photo

舞台裏はシンプルだった。日本語環境と英語環境。 「添付"致"します」だと救われなかった模様

舞台裏はシンプルだった。日本語環境と英語環境。
「添付"致"します」だと救われなかった模様
terjanq (@terjanq) 's Twitter Profile Photo

For this year Google CTF I created yet another Postviewer challenge called Postviewer v5². The challenge featured a seemingly impossible race-condition. Client-side race-conditions are an under-researched problem and could yield amazing real world bugs! gist.github.com/terjanq/e66c28…

Kévin GERVOT (Mizu) (@kevin_mizu) 's Twitter Profile Photo

I'm happy to release a script gadgets wiki inspired by the work of Sebastian Lekies, koto, and Eduardo Vela in their Black Hat USA 2017 talk! 🔥 The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇 gmsgadget.com 1/4

I'm happy to release a script gadgets wiki inspired by the work of <a href="/slekies/">Sebastian Lekies</a>, <a href="/kkotowicz/">koto</a>, and <a href="/sirdarckcat/">Eduardo Vela</a> in their Black Hat USA 2017 talk! 🔥

The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇

gmsgadget.com

1/4
Dirk-jan (@_dirkjan) 's Twitter Profile Photo

It's been almost a year since my last blog... So, here is a new one: Extending AD CS attack surface to the cloud with Intune certificates. Also includes ESC1 over Intune (in some cases). dirkjanm.io/extending-ad-c… Oh, and a new tool for SCEP: github.com/dirkjanm/scepr…

‌Renwa (@renwax23) 's Twitter Profile Photo

New Blog Post: Disclosing "PermissionJacking," a Safari bug that lets websites trick you into giving camera, mic, gps... access. After a lengthy back-and-forth, Apple's decision is that this is not a security issue, I disagree. Includes new attack vector github.com/RenwaX23/X/blo…

celesian (@c3l3si4n) 's Twitter Profile Photo

My article "High-Performance Network Scanning with AF_XDP" has been released on the 72th issue of Phrack. phrack.org/issues/72/3_md…

My article "High-Performance Network Scanning with AF_XDP" has been released on the 72th issue of Phrack.
 phrack.org/issues/72/3_md…
terjanq (@terjanq) 's Twitter Profile Photo

We published a blogpost about SafeContentFrame - a library for rendering untrusted content inside an iframe. The library is a big party of what I've been up to in the few last years! Check out the blog and take a slice of my birthday cake 🎂! bughunters.google.com/blog/671552987…

We published a blogpost about SafeContentFrame - a library for rendering untrusted content inside an iframe. The library is a big party of what I've been up to in the few last years! Check out the blog and take a slice of my birthday cake 🎂!

bughunters.google.com/blog/671552987…
Faith 🇧🇩🇦🇺 (@farazsth98) 's Twitter Profile Photo

Ok managed to get a wild memory access now (it's accessing `addr + offset` where `offset` is a really large but controllable value. With the correct heap spray, this is basically an arbitrary write primitive. Will do a quick writeup on the vulnerability now before I continue!

Ok managed to get a wild memory access now (it's accessing `addr + offset` where `offset` is a really large but controllable value.

With the correct heap spray, this is basically an arbitrary write primitive.

Will do a quick writeup on the vulnerability now before I continue!
OtterSec (@osec_io) 's Twitter Profile Photo

NEW: OAuth misconfigurations show how common dev settings can lead to account takeovers. Our second deep dive breaks down real cases where overlooking differences between desktop and mobile environments left SDKs, exchanges, and wallets open to exploits. osec.io/blog/2025-10-1…

James Kettle (@albinowax) 's Twitter Profile Photo

HTTP is supposed to be stateless, but sometimes... it isn't! Some servers create invisible vulnerabilities by only validating the first request on each TCP/TLS connection. I've just published a Custom Action to help you detect & exploit this - here's a narrated demo:

Weilin (William) Li (@hklst4r) 's Twitter Profile Photo

I have made a thorough analysis of the Balancer attack: blog.weilinli.io/posts/balancer… --- Yesterday, on July 3, 2025, Balancer was hacked for over $100 million due to a precision-loss bug. While the official post-mortem hasn’t been released yet, most pools are already paused or

I have made a thorough analysis of the <a href="/Balancer/">Balancer</a> attack: blog.weilinli.io/posts/balancer…
---

Yesterday, on July 3, 2025, Balancer was hacked for over $100 million due to a precision-loss bug.
While the official post-mortem hasn’t been released yet, most pools are already paused or
Infobahn (@infobahn_ctf) 's Twitter Profile Photo

Infobahn CTF starts in 24 hours! Prizes worth over $3000! Challenges across Web, Reverse Engineering, Cryptography, Binary Exploitation, Jail, and more. Sponsored by Google Cloud, OffSec, OtterSec, RET2 Systems, Cybersharing, and Rapid Risk Radar. 2025.infobahnc.tf

Infobahn (@infobahn_ctf) 's Twitter Profile Photo

Final 24 Hours! Wave 3 is live! We've added 2 brand-new web challenges. 8 challenges are still unsolved (5 web, 1 pwn, 1 rev, 1 jail). 10 flags are waiting. Go get them! 2025.infobahnc.tf

Infobahn (@infobahn_ctf) 's Twitter Profile Photo

Infobahn CTF 2025 is officially over! Congratulations to all the players and a special shout-out to our winning teams! 1. MNGA (Nu1L) 2. no rev/pwn no life (r3kapig) 3. KCSC We hope you all enjoyed the challenges!

Infobahn CTF 2025 is officially over!  Congratulations to all the players and a special shout-out to our winning teams!

1. MNGA (<a href="/Nu1L_Team/">Nu1L</a>)
2. no rev/pwn no life (<a href="/r3kapig/">r3kapig</a>)
3. KCSC

We hope you all enjoyed the challenges!
xvonfers (@xvonfers) 's Twitter Profile Photo

woah... [446113731, 446113732, 446122633, 446124892, 446124893][wasm-custom-desc] Fix subtyping chromium-review.googlesource.com/c/v8/v8/+/6973… Exploited in v8ctf as 0-days & chained with issue 446113730(v8sbx bypass)

woah...
[446113731, 446113732, 446122633, 446124892, 446124893][wasm-custom-desc] Fix subtyping
chromium-review.googlesource.com/c/v8/v8/+/6973…

Exploited in v8ctf as 0-days &amp; chained with issue 446113730(v8sbx bypass)
Sylvie (@_sy1vi3) 's Twitter Profile Photo

react2shell:11/29/25:lachlan2k:sy1vi3 sha256:18571097aedaec16f729c4227e1e508fe161d5d6b4256eec7d0525535ebb3fa0 cve.org/CVERecord?id=C…