juwilie (@juwilie1337) 's Twitter Profile
juwilie

@juwilie1337

ID: 808223253495947264

linkhttp://juwilie.me calendar_today12-12-2016 08:13:34

91 Tweet

116 Followers

156 Following

МимоКрокодил (@m1mo_croc) 's Twitter Profile Photo

Вышел выпуск подкаста №4. Наконец cобрались обсудить давно интересующу нас тему: менджмент и бизнес - особенности данных веток таланов для пентестера. Есть ли вобще другие? Уже разлит по площадкам soundcloud.com/m1mo-croc music.yandex.ru/album/10321679 podcasts.apple.com/ru/podcast/id1…

juwilie (@juwilie1337) 's Twitter Profile Photo

Ruby on Rails 5 cookie tool (decrypt, encrypt and sign RoR cookies from Python) gist.github.com/juwilie/db1d3e… #pentest #bugbounty

shubs (@infosec_au) 's Twitter Profile Photo

I've just added an API routes wordlist containing 953011 possible API paths from the HTTPArchive dataset. Download it at wordlists.assetnote.io - all paths which start with "/api/", "/v1/", "/v2", or "/rest/". Good luck hacking! Thanks for requesting this, hope it helps.

Ian Beer (@i41nbeer) 's Twitter Profile Photo

Excited to finally publish my lockdown project from earlier this year: an iOS zero-click radio proximity exploit odyssey. googleprojectzero.blogspot.com/2020/12/an-ios…

Hack3rScr0lls (@hackerscrolls) 's Twitter Profile Photo

We have combined all the tricks we know about SSRF into a single mindmap. If we missed something, write about it in the comments! High resolution: raw.githubusercontent.com/hackerscrolls/… XMind source: github.com/hackerscrolls/… #CyberSecurity #BugBountyTip #BugBounty

We have combined all the tricks we know about SSRF into a single mindmap.

If we missed something, write about it in the comments!

High resolution: raw.githubusercontent.com/hackerscrolls/…
XMind source: github.com/hackerscrolls/…

#CyberSecurity #BugBountyTip #BugBounty
ϻг_ϻε (@steventseeley) 's Twitter Profile Photo

With the introduction of PHP 8.0, phar:// deserialization will be turned off by default so techniques like leveraging an XXE to trigger deserialization and gain RCE will no longer be possible. srcincite.io/assets/out-of-…

МимоКрокодил (@m1mo_croc) 's Twitter Profile Photo

Выпуск #4 - Облачные истории Первый выпуск в новом году. Сегодня у нас в гостях Антон - lead application security engineer в компании Semrush. Общаемся про облака, доверие к ним и уйдем ли мы от старого доброго VPN. music.yandex.ru/album/10321679 podcasts.google.com/feed/aHR0cHM6L…

juwilie (@juwilie1337) 's Twitter Profile Photo

Burp Suite will SSE (Server Sent Events) proxy functionality be eventually added? It is really boring to toggle proxy every time application uses SSE.

ZeroNights (@zeronights) 's Twitter Profile Photo

📢 ZN 2021: new time and place Nothing can compare to the energy of live conversation. ZN 2021 will take place at Sevkabel Port, St Petersburg on June, 30. Early registration is available. Use promocode EARLYBIRD to get 20% off till the end of March zeronights.ru

📢 ZN 2021: new time and place

Nothing can compare to the energy of live conversation. ZN 2021 will take place at Sevkabel Port, St Petersburg on June, 30.

Early registration is available. Use promocode EARLYBIRD to get 20% off till the end of March
zeronights.ru
juwilie (@juwilie1337) 's Twitter Profile Photo

Published a writeup for a Web challenge form YauzaCTF 2021 link.medium.com/PH8WOejFajb TL;DR: JA3 ratelimit bypass + a little guessing + MongoDB query injection

Ian Beer (@i41nbeer) 's Twitter Profile Photo

Today we're publishing a detailed technical writeup of FORCEDENTRY, the zero-click iMessage exploit linked by Citizen Lab to the exploitation of journalists, activists and dissidents around the world. googleprojectzero.blogspot.com/2021/12/a-deep…

Steph (@w34kp455) 's Twitter Profile Photo

The main problem with passwords is you always need to remember one for password managers like 1Password or Dashlane. Forget it! You can easily pick your most used one, written on a hand-made cracker! WOW! opensea.io/collection/pas…

juwilie (@juwilie1337) 's Twitter Profile Photo

Say NO to password managers in 2022! Use the most secure NFT password storage based on blockchain powered by cutting edge cryptography

Steph (@w34kp455) 's Twitter Profile Photo

I collected near million of subdomains from all #bugbounty scopes to make some #wordlists for enumeration. Hope it will help in searching new targets. You can check it here - "Yet another enumeration of subdomains with statistics" link.medium.com/nE3qmB2fHnb

Eldar Zaitov (@kyprizel) 's Twitter Profile Photo

All this CA stuff was cursed, but now, when CAs revoke certificates on a geographical basis, it is especially clearly visible.

Andrei Abakumov (@andrewaeva) 's Twitter Profile Photo

История о том, как мы придумали с нуля отдельную инфру для Банка в Облаке, которая сейчас летит в проде. Сложно поверить, что эта история началась со схемы на доске в комнате безопасности. О том, с какими трудностями мы столкнулись и какие выводы сделали youtube.com/live/HJDOSkW-y…

Андрей Гейн (@andrewgein) 's Twitter Profile Photo

What's happening? — Twitter asks. Almost nothing. Just Google laid off me before the start date of my employment: andgein.ru/blog/all/20-i-…