xanhacks (@xanhacks) 's Twitter Profile
xanhacks

@xanhacks

Web & Malware
- CTF with @Arn_Hack @HexagonCTF @GCC_ENSIBS
- Staff member of @HeroCTF @Flag4jobs

ID: 761269006863048704

linkhttps://www.xanhacks.xyz/ calendar_today04-08-2016 18:34:09

4,4K Tweet

1,1K Takipçi

618 Takip Edilen

Jorian (@j0r1an) 's Twitter Profile Photo

I almost can't believe it, but I am finally releasing my Gitbook about CTF and Hacking, which is a year in the making. It contains many tricks, explanations, and resources from my experience and research. I hope it becomes a valuable resource for everyone! book.jorianwoltjer.com//

slonser (@slonser_) 's Twitter Profile Photo

Small writeup on my 0day at Casdoor (not fixed yet) Abusing open redirect via pwa protocol handlers blog.slonser.info/posts/why-prot…

Kévin GERVOT (Mizu) (@kevin_mizu) 's Twitter Profile Photo

For this challenge, it was necessary to abuse a discrepancy between the DOM and the rendered page in Firefox's cache handling 💽 👉 bugzilla.mozilla.org/show_bug.cgi?i… This allows to shift iframe rendering from one to another leading to a sandbox bypass 🔥 👉 mizu.re/post/an-18-yea…

Eurosport France (@eurosport_fr) 's Twitter Profile Photo

WOW ! 😨 La chute incroyable de Charles Gamel-Seigneur 🇫🇷, qui parvient à se rattraper après être tombé sur la tête ! Suivez le meilleur du ski alpin sur Eurosport et Max

Worty (@_worty) 's Twitter Profile Photo

My writeup for the KalmarCTF challenge "no sqli" is out, covering the exploitation of CVE-2024-6382, an integer overflow in the Rust's MongoDB library. A very interesting challenge, enjoy! :) worty.fr/post/writeups/…

Benasin (@benasin3) 's Twitter Profile Photo

🚨HTTP Request Smuggling in lua-nginx-module!🚨 This affects major proxies like Kong GW, OpenResty, Apache APISIX and many more👀 Check it out: benasin.space/2025/03/18/Ope… Big thanks to James Kettle for his awesome research and for answering all my questions! #bugbounty #bugbountytips

bearstech (@bearstech) 's Twitter Profile Photo

Docs : une alternative Open Source à Notion ou Outline. (P) Ce projet est le fruit d'une collaboration entre les gouvernements français (la DINUM) et allemand (ZenDiS). 👉 Le projet : github.com/suitenumerique… 👉 En savoir plus : docs.numerique.gouv.fr/login/

Docs : une alternative Open Source à Notion ou Outline. (P)

Ce projet est le fruit d'une collaboration entre les gouvernements français (la DINUM) et allemand (ZenDiS).

👉 Le projet : github.com/suitenumerique…
👉 En savoir plus : docs.numerique.gouv.fr/login/
Worty (@_worty) 's Twitter Profile Photo

With Flat Network Society we took part in the Insomni'hack finals and we ended up in second place. The Insotransfer challenge was about an RCE on a FastAPI readonly docker instance, enjoy the read :) worty.fr/post/writeups/…

Agoratlas (@agoratlas) 's Twitter Profile Photo

Quelques semaines après la vaste campagne de manipulation autour de la rencontre Trump-Zelensky, nous revenons en détail sur nos découvertes et notre méthodologie d'enquête. À retrouver sur le blog Agoratlas : agoratlas.com/blog/rencontre…

adragos (@adragos_) 's Twitter Profile Photo

I'm releasing fontleak: a new CSS injection technique to quickly exfiltrate text nodes (and yes, that includes inline scripts). Works on Chrome/Firefox and Safari*. You can use it to escalate the impact of your HTML injection payloads and to solve CTF challenges.

0xReverse (@0xreversecom) 's Twitter Profile Photo

🔥 Understanding Alcatraz ~ Obfuscator Analysis by Utku Çorbacı - Analysis of Alcatraz Passes with IDA - OEP Finder with Qiling Framework - Scripting with IDAPython 0xreverse.com/understanding-…

Kévin GERVOT (Mizu) (@kevin_mizu) 's Twitter Profile Photo

The #FCSC2025 ended yesterday, and my write-ups are now available here 👇 mizu.re/post/fcsc-2025… Btw, like every year, all the challenges have also been added to hackropole.fr! 🚩 1/2

The #FCSC2025 ended yesterday, and my write-ups are now available here 👇

mizu.re/post/fcsc-2025…

Btw, like every year, all the challenges have also been added to hackropole.fr! 🚩

1/2
Kévin GERVOT (Mizu) (@kevin_mizu) 's Twitter Profile Photo

I've released my CTF bot template! :D It's not a big deal, but it comes with a heavily hardened Docker setup. The bot also sends a lot of debugging information over the TCP socket (console logs, navigation), which makes remote debugging much easier! 🔎 👉github.com/kevin-mizu/bot…

I've released my CTF bot template! :D

It's not a big deal, but it comes with a heavily hardened Docker setup. The bot also sends a lot of debugging information over the TCP socket (console logs, navigation), which makes remote debugging much easier! 🔎

👉github.com/kevin-mizu/bot…
0xdf (@0xdf_) 's Twitter Profile Photo

Checker from Hack The Box has some really complex exploitation steps. There's SQLI in Teampass, SSRF to file read in BookStack using a blind PHP filter oracle, and shared memory abuse. 0xdf.gitlab.io/2025/05/31/htb…

Sicarius (@els1carius) 's Twitter Profile Photo

There we go, after 3 years of work, endless nights of dev and a truckload of coffee. We are finally releasing the biggest project we've done in our entire life. I hope you will like it !

Worty (@_worty) 's Twitter Profile Photo

The part about the 0day I used on the TrackDb web challenge for the FCSC2025 has just been disclosed in the writeup, you can read it here: worty.fr/post/writeups/… Please note that this vulnerability is not patched (see the end of the writeup for explanations).