Szymon Drosdzol (@tell1c0) 's Twitter Profile
Szymon Drosdzol

@tell1c0

Senior Security Engineer @Doyensec

ID: 1636366410606845952

calendar_today16-03-2023 13:59:03

9 Tweet

31 Followers

117 Following

Doyensec (@doyensec) 's Twitter Profile Photo

Our newest #oss project, from Maxence SCHMITT -CSPTPlayground (github.com/doyensec/CSPTP…) helps you learn how to find and exploit various client-side path traversal vulnerabilities. Level up and check it out today! #doyensec #appsec #CSPT #security

Doyensec (@doyensec) 's Twitter Profile Photo

Calling all security-minded #opensource coders! We're offering rewards 🎁 for meaningful contributions to #inql our #Burpsuite extension for #graphql security! DM us for details and let us know your background/interest level. #doyensec #oss #security github.com/doyensec/inql

Calling all security-minded #opensource coders! We're offering rewards 🎁 for meaningful contributions to #inql our #Burpsuite extension for #graphql security! DM us for details and let us know your background/interest level.

#doyensec #oss #security

github.com/doyensec/inql
Doyensec (@doyensec) 's Twitter Profile Photo

📢Attention #appsec people! Our latest #burpsuite extension, Prototype Pollution Gadgets Finder (by RoloMijan) is available in the BApp Store. Install today to find & exploit server-side prototype pollution vulns! #doyensec #bugbountytips #ctf #security portswigger.net/bappstore/fcbc…

Doyensec (@doyensec) 's Twitter Profile Photo

In the latest Doyensec research, our Norbert Szetei (73696e65) takes a closer look at the SMB3 Kernel Server (ksmbd) component of the Linux kernel. Check it out today & learn what he found, which led to multiple CVEs! #Doyensec #Appsec #Security #Linux blog.doyensec.com/2025/01/07/ksm…

In the latest Doyensec research, our Norbert Szetei (<a href="/73696e65/">73696e65</a>) takes a closer look at the SMB3 Kernel Server (ksmbd) component of the Linux kernel. Check it out today &amp; learn what he found, which led to multiple CVEs! 
#Doyensec #Appsec #Security #Linux

blog.doyensec.com/2025/01/07/ksm…
Informatyk Zakładowy (@infzakladowy) 's Twitter Profile Photo

Krzysztof K. 🇺🇦 Widziałem podgląd wyników z cache. Google Dorks wystawiające PHPMyAdminy bez uwierzytelniania. Statki szturmowe w ogniu sunące nieopodal Pasu Oriona. Wszystkie te chwile przeminą w czasie jak łzy w deszczu.

Szymon Drosdzol (@tell1c0) 's Twitter Profile Photo

OAuth vulnerabilities are everywhere—some attacks even resurface every few years due to its complexity. To help, eljoselillo7 and I created a guide on OAuth flows & attacks + a cheat sheet to verify your implementation. Check it out! #OAuth #CyberSecurity #AppSec

Szymon Drosdzol (@tell1c0) 's Twitter Profile Photo

After many late nights and busted apps as security consultant at Doyensec , I trained my spidey senses 🕷️ to detect when an API code is practically begging for an auth vulns. Join me at #CONFidence2025 for common pitfalls, and tips for writing secure authz from the start.

After many late nights and busted apps as security consultant at <a href="/Doyensec/">Doyensec</a> , I trained my spidey senses 🕷️ to detect when  an API code is practically begging for an auth vulns.

Join me at #CONFidence2025 for common pitfalls, and tips for writing secure authz from the start.
Doyensec (@doyensec) 's Twitter Profile Photo

🚨Just posted🚨: Learn about real-world API authorization vulnerabilities we frequently see with the slides from Szymon Drosdzol's recent presentation at confidenceconf in Krakow. doyensec.com/resources/CONF… #doyensec #appsec #security

🚨Just posted🚨: Learn about real-world API authorization vulnerabilities we frequently see with the slides from <a href="/tell1c0/">Szymon Drosdzol</a>'s recent presentation at <a href="/CONFidenceConf/">confidenceconf</a> in Krakow.

doyensec.com/resources/CONF…

#doyensec #appsec #security
Doyensec (@doyensec) 's Twitter Profile Photo

🚨Security Advisories🚨: multiple vulnerabilities in Retool (Retool), including host header injection and CSRF - discovered by Doyensec and the Robinhood (Robinhood) Red team! docs.retool.com/disclosures/cv… docs.retool.com/disclosures/cv… #doyensec #appsec #security #retool #robinhood

🚨Security Advisories🚨: multiple vulnerabilities in Retool (<a href="/retool/">Retool</a>), including host header injection and CSRF - discovered by Doyensec and the Robinhood (<a href="/RobinhoodApp/">Robinhood</a>) Red team! 

docs.retool.com/disclosures/cv… docs.retool.com/disclosures/cv…
#doyensec #appsec #security #retool #robinhood
Doyensec (@doyensec) 's Twitter Profile Photo

🚨Security Advisory🚨 Systemic SQL Injection vulnerability in pREST! Initial report details published: github.com/prest/prest/se… #Doyensec #AppSec #Security #PostgreSQL #SQLInjection

Doyensec (@doyensec) 's Twitter Profile Photo

🧞Your wish has been granted - the latest PagedOut edition is out! In it, our Szymon Drosdzol takes a quick look at #vibecoding, walking through the creation of an AI agent🤖. Check it out today! #doyensec #appsec #ai #Security pagedout.institute