pranav (@zerodaywo1f) 's Twitter Profile
pranav

@zerodaywo1f

offensive security • research

ID: 3072836234

linkhttps://zerodaywolf.sh calendar_today11-03-2015 10:07:36

596 Tweet

274 Followers

521 Following

sagitz (@sagitz_) 's Twitter Profile Photo

We found two 0-day vulnerabilities in @Ubuntu kernel and it all started by reading descriptions of old CVEs 📖 Thread about the discovery of #GameOverlay 🧵👇🏼

We found two 0-day vulnerabilities in @Ubuntu    kernel and it all started by reading descriptions of old CVEs 📖 
Thread about the discovery of #GameOverlay 🧵👇🏼
Anurag Mishra (@mishr_a_nurag) 's Twitter Profile Photo

Get Ready with Your AWS Accounts because Arif abhishekbv and me will be delivering training Seasides on 21 September. "Fundamentals of attacking and defending AWS" Attached is a clip of what you can expect at our training. seasides.net #cloudsecurity

Dimitar Tsvetanov (@cvetanovv0) 's Twitter Profile Photo

These resources are all you need to become at least an intermediate level Smart Contract Security Researcher🧐 When I started learning I wasn't lucky enough to have these resources. But now you have it and should take advantage. Let's take a look at them👇🏼

Nithin 🦹‍♂️ (@thebinarybot) 's Twitter Profile Photo

When bug bounty hunting, assume you are blocked by a WAF. What are the common ways you can evade WAF and continue hunting? Curious to know? Checkout this thread 👇🧵

Ruben V Piña (@ruben_v_pina) 's Twitter Profile Photo

Nithin 🦹‍♂️ Bypasses for the following WAFs: Amazon Web Services WAF Cisco Secure WAF Cloudflare Web Application Firewall Citrix Netscaler F5 BIG-IP Advanced WAF Fortinet's Fortiweb WAF Akamai Web Application Firewall Sophos Firewall Broadcom Radware nzt-48.org/bypasses-for-t…

GitHub Projects Community (@githubprojects) 's Twitter Profile Photo

| ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄| | Don't Push To Production On Friday | |_________________| \ (•◡•) / \ / —— | | |_ |_

Gergely Orosz (@gergelyorosz) 's Twitter Profile Photo

Ok Mullvad VPN is the example of security *by design*: The company does not store any form of data (no IPs, no logs.) They don’t even offer recurring subscriptions (!!) because doing so would force them to store data that can identify people. No affiliation: just awesome

pranav (@zerodaywo1f) 's Twitter Profile Photo

Spent two full days troubleshooting with ChatGPT but didn’t get anywhere. Took half a day to dig into the docs and troubleshoot it myself—just like the old days—and I’m happy to say my Pi-hole DNS on k8s is finally reachable on my Tailnet 😄

The Lunduke Journal (@lundukejournal) 's Twitter Profile Photo

Today, Linus Torvalds told a Google engineer that his code (updating RISC-V support in the Linux kernel) is “garbage” which “makes the world actively a worse place to live”. Adding that the Google engineer’s code needs to “get bent”. As you might have guessed, Torvalds has

Today, Linus Torvalds told a Google engineer that his code (updating RISC-V support in the Linux kernel) is “garbage” which “makes the world actively a worse place to live”.

Adding that the Google engineer’s code needs to “get bent”.

As you might have guessed, Torvalds has
pranav (@zerodaywo1f) 's Twitter Profile Photo

All the blogs I want to read are finally organized on my reader. Glad I stumbled upon kill-the-newsletter.com. This is a neat solution to not give out your email to newsletters. Plus I no more have to scroll through my email to look for any latest tech news I missed out on.

pranav (@zerodaywo1f) 's Twitter Profile Photo

I've been having a blast solving the Wiz Ultimate Cloud Security Championship challenges! I haven’t touched CTFs in quite a while, but jumping back in has been such a breath of fresh air. Thank you Wiz for the cool challenges! zerodaywolf.sh/writeups/

I've been having a blast solving the Wiz Ultimate  Cloud Security Championship challenges! I haven’t touched CTFs in quite  a while, but jumping back in has been such a breath of fresh air. Thank you <a href="/wiz_io/">Wiz</a> for the cool challenges!
 zerodaywolf.sh/writeups/
pranav (@zerodaywo1f) 's Twitter Profile Photo

Block ads & trackers on Android 11+ natively using Private DNS. I've been experimenting with public DNS providers which block annoying ads & trackers and I think the best one is dns.adguard-dns.com . Haven't seen any app crashes for a while. LMK if you know a better one.

pranav (@zerodaywo1f) 's Twitter Profile Photo

Recently ran an experiment and found out how alarmingly easy it was to compromise users via npm lifeycycle hooks. Read about it here - zerodaywolf.sh/blog/npm-lifec… #supplychain #security #opensource #npm #hacking

Prem Soni (@valuewithprem) 's Twitter Profile Photo

I admitted my son to a hospital today. I have a ₹1.2 crore Acko Platinum Health Plan the one with no room rent limit. ACKO Varun Dua Guess what? The hospital flat out denied me a suite room. 👇🏻