zoro (@sudozoro) 's Twitter Profile
zoro

@sudozoro

شاید روزی یک محقق امنیتی در دنیای چیزای نرم

ID: 1482006439531102211

calendar_today14-01-2022 15:07:32

1,1K Tweet

857 Followers

832 Following

zoro (@sudozoro) 's Twitter Profile Photo

دارم به این فکر میکنم یه نفر چطور میتونه از این مملکت خراب شده برسه به Pwn2Own !؟

zoro (@sudozoro) 's Twitter Profile Photo

su18.org/post/jdbc-conn… این مقاله در ارتباط با نحوه RCE گرفتن با استفاده از JDBC هست به نظرم خیلی چیز قشنگی اومد لازمه ذکر کنم که RCE ای که چند ماه قبل یک Security Researcher از metabase پیدا کرد از همین تکنیک استفاده کرده بود ، این یعنی مطالعه زیاد :)‌)

Matin Arjo (@skycer_00) 's Twitter Profile Photo

I’ve just shared a new write-up! A small curiosity turned into a full-blown SSRF — internal access, exposed data, and deep exploration. Read it here: medium.com/@skycer_00/ful… #BugBounty

Brut 🇮🇳 (@wtf_brut) 's Twitter Profile Photo

⚡MapperPlus facilitates the extraction of source code from a collection of targets that have publicly exposed .js.map files. ✅github.com/midoxnet/mappe… ✅Join Telegram - t.me/brutsecurity #bugbounty #bugbountytips

⚡MapperPlus facilitates the extraction of source code from a collection of targets that have publicly exposed .js.map files.

✅github.com/midoxnet/mappe…
✅Join Telegram - t.me/brutsecurity

#bugbounty #bugbountytips
d3fp4r4m (@defparam) 's Twitter Profile Photo

The man produces cutting edge research for blackhat 10 years in a row conducting proper disclosure each step of the way including 3 other desync related talks resulting in highly impactful data/tools for all of infosec and people still lose their minds over logos and websites 🤷‍♂️

James Kettle (@albinowax) 's Twitter Profile Photo

Not at Black Hat / DEF CON? You can still join the mission to kill HTTP/1.1: - Watch the livestream from #DEFCON at 16:30 on 8th - Read the whitepaper on our website - Grab the HTTP Request Smuggler update & Web Security Academy lab Follow for updates & links. It's nearly time!

James Kettle (@albinowax) 's Twitter Profile Photo

HTTP Request Smuggler v3.0.1 is now live! This fixes a false positive in the CL.0 scan caused by pipelining - thanks to sw33tLie for the report. Note that the new parser discrepancy scan still has superior accuracy. For more info on pipelining check out portswigger.net/research/how-t…

James Kettle (@albinowax) 's Twitter Profile Photo

I'm flying out to #romhack2025 tomorrow, for the final edition of HTTP/1.1 Must Die! Feel free to say hi if you'd like to chat.

Ben Sadeghipour (@nahamsec) 's Twitter Profile Photo

Really disappointed to see HackerOne do this. I also had a similar interaction with h1 about a month ago where they questioned my nationality and place of residence after 10+ on the platform.