William Bowling @vakzz@infosec.exchange (@wcbowling) 's Twitter Profile
William Bowling @[email protected]

@wcbowling

Security Engineer at @zellic_io, a.k.a vakzz when doing bug bounties and CTFs with @pb_ctf - devcraft.io

ID: 1586550266

linkhttps://wbowling.info/ calendar_today11-07-2013 18:51:33

213 Tweet

6,6K Followers

412 Following

s1r1us (@s1r1u5_) 's Twitter Profile Photo

My colleagues Aaditya Purani and Pew will present our research "Electrovolt" at South Pacific F (Level 0), BlackHat in exactly one hour. Attend the presentation if you are at BlackHat๐Ÿ”ฅ.

โ€ŒRenwa (@renwax23) 's Twitter Profile Photo

Asana Electron desktop app open redirect to local file read Did you knew local files in Electron have file:// origin not null, with another Mac trick we load our malicious file and steal any file on the pc bugcrowd.com/disclosures/f7โ€ฆ

Zellic (@zellic_io) 's Twitter Profile Photo

This weekend, we played 0xmonaco MatchboxDAO, a web3 gaming competition. We developed a highly profitable racing strategy by leveraging clever math and bugs. We got DQ-ed๐Ÿ˜… In this thread, we'll break down: ๐ŸŽฏ our car's unique strategy ๐ŸŽฏ the vulnerabilities our car exploited

This weekend, we played 0xmonaco <a href="/matchbox_dao/">MatchboxDAO</a>, a web3 gaming competition. We developed a highly profitable racing strategy by leveraging clever math and bugs. We got DQ-ed๐Ÿ˜…

In this thread, we'll break down:
๐ŸŽฏ our car's unique strategy
๐ŸŽฏ the vulnerabilities our car exploited
perfect blue (@pb_ctf) 's Twitter Profile Photo

It's finally happening! pbctf 2023 is here ๐Ÿ—“๏ธ Feb 18th, 14:00 UTC to Feb 20th 02:00 UTC (36 hours) ๐ŸŽ A $10,000 prize pool Proudly sponsored by @Zellic_io ctftime.org/event/1763

It's finally happening! pbctf 2023 is here

๐Ÿ—“๏ธ Feb 18th, 14:00 UTC to Feb 20th 02:00 UTC (36 hours)

๐ŸŽ A $10,000 prize pool

Proudly sponsored by @Zellic_io 

ctftime.org/event/1763
Zellic (@zellic_io) 's Twitter Profile Photo

Earlier this morning, SafeMoon's Liquidity Pool was compromised and USD 8.9M worth of tokens were withdrawn. After looking at the transaction trace and the recent contract changes, we can tell you what happened:

Zellic (@zellic_io) 's Twitter Profile Photo

Meet Cairo, the native language of Starknet. In this thread we'll: โœ… Introduce Cairo & Starknet โœ… Explore the security features of Cairo โœ… Examine potential pitfalls when writing contracts in Cairo โœ… Give you things to consider when writing secure code Let's dig in๐Ÿ‘‡๐Ÿงต:

Meet Cairo, the native language of Starknet.

In this thread we'll:

โœ… Introduce Cairo &amp; Starknet
โœ… Explore the security features of Cairo
โœ… Examine potential pitfalls when writing contracts in Cairo
โœ… Give you things to consider when writing secure code

Let's dig in๐Ÿ‘‡๐Ÿงต:
Zellic (@zellic_io) 's Twitter Profile Photo

The dangers of integer truncation: How the Zellic team found a critical vulnerability in the Astar Network. This bug allowed an attacker to drain certain LP contracts on the Astar-EVM, with no bugs required in the contracts. Read more: ๐Ÿงต๐Ÿ‘‡

The dangers of integer truncation:

How the Zellic team found a critical vulnerability in the <a href="/AstarNetwork/">Astar Network</a>.

This bug allowed an attacker to drain certain LP contracts on the Astar-EVM, with no bugs required in the contracts.

Read more: ๐Ÿงต๐Ÿ‘‡
perfect blue (@pb_ctf) 's Twitter Profile Photo

2023 was another great year for the team! ๐ŸŽ‰ Blue Water, a collab between perfect blue and Water Paddler, placed 1st in CTFtime globally!๐Ÿ† ๐Ÿฅ‡1st place in 6 CTFs ๐Ÿ’ปHosted a successful pbctf 2023 In the past, we also placed first in 2020 and 2021.โœŒ Looking forward to 2024!๐ŸŽ†

2023 was another great year for the team! ๐ŸŽ‰

Blue Water, a collab between perfect blue and <a href="/Water_Paddler/">Water Paddler</a>, placed 1st in CTFtime globally!๐Ÿ†

๐Ÿฅ‡1st place in 6 CTFs
๐Ÿ’ปHosted a successful pbctf 2023

In the past, we also placed first in 2020 and 2021.โœŒ

Looking forward to 2024!๐ŸŽ†
Zellic (@zellic_io) 's Twitter Profile Photo

Zellic has moved forward to the final voting phase for Arbitrum's Security Council! We ask delegates to vote for Zellic as the Security Council furthers our mission to maximize TVL and extends our commitment to Arbitrum and its ecosystem. Vote here: tally.xyz/gov/arbitrum/cโ€ฆ

Zellic (@zellic_io) 's Twitter Profile Photo

Version 0.11.0 of gnark was just released, which fixes two vulnerabilities in the Groth16 backend reported by Zellic (CVE-2024-45039, CVE-2024-45040). These affect the soundness and ZK property of generated proofs. Read on for more details and how to check if you're vulnerable.

Version 0.11.0 of gnark was just released, which fixes two vulnerabilities in the Groth16 backend reported by Zellic (CVE-2024-45039, CVE-2024-45040).

These affect the soundness and ZK property of generated proofs.

Read on for more details and how to check if you're vulnerable.
Solidity (@solidity_lang) 's Twitter Profile Photo

โœจ Our judges also decided to give a special mention to William Bowling @[email protected] for his submission in which the bug allows a `multisig` storage variable to be overwritten, allowing the `emergencyWithdraw` function to be called by an attacker. Read Patrick Collinsโ€™s thoughts on this

Zellic (@zellic_io) 's Twitter Profile Photo

What happens when Random() isnโ€™t random? Hereโ€™s how popular projects, including Proton Wallet and the Dart SDK were all affected by the same underlying weakness we uncovered in the Dart/Flutter ecosystem. All issues found were responsibly disclosed with the vendors. Letโ€™s go

kamensec (@kamensec) 's Twitter Profile Photo

Just completed my 10th audit as a contractor Zellic and these are my top favourite things about this place: 1. They have a diverse and deep talent pool. World top Web security, Cosmos, Rust, Golang, MOVE. They have experts in every direction I want to move into (pun

Zellic (@zellic_io) 's Twitter Profile Photo

With the rise of AI agents, we expect new bugs, but weโ€™ve instead found old bugs in disguise. Letโ€™s look at two old-school bugs we found while looking at elizaOS: โ€ข An SSRF allowing internal services to be accessed โ€ข An LFI allowing host files to be read Letโ€™s dive in ๐Ÿงต

With the rise of AI agents, we expect new bugs, but weโ€™ve instead found old bugs in disguise.

Letโ€™s look at two old-school bugs we found while looking at elizaOS:

โ€ข An SSRF allowing internal services to be accessed 
โ€ข An LFI allowing host files to be read

Letโ€™s dive in ๐Ÿงต
Zellic (@zellic_io) 's Twitter Profile Photo

How to spot misleading audit competition metrics Competitions are crowdsourced audits, where auditors compete to find bugs in a set timeframe. Last year, we acquired Code4rena which does these. We've also seen tons of misleading sales pitches. Here's what to watch out for: ๐Ÿงต

How to spot misleading audit competition metrics

Competitions are crowdsourced audits, where auditors compete to find bugs in a set timeframe. Last year, we acquired <a href="/code4rena/">Code4rena</a> which does these.

We've also seen tons of misleading sales pitches. Here's what to watch out for: ๐Ÿงต