Aethlios's Avatar

Aethlios

@aethlios.bsky.social

Lead developer | Bug hunter (approximately every 3 months) > https://aeth.cc

698 Followers  |  145 Following  |  7 Posts  |  Joined: 30.10.2023  |  1.7601

Latest posts by aethlios.bsky.social on Bluesky

Post image

I'm excited to share that I recently found a XSS in Quasar Framework. The CVE-2025-43954 has just been published to document this security issue.

You can learn more about it here:
- github.com/advisories/G...

24.04.2025 12:15 โ€” ๐Ÿ‘ 6    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
SAML roulette: the hacker always wins Introduction In this post, weโ€™ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library

You might have noticed that the recent SAML writeups omit some crucial details. In "SAML roulette: the hacker always wins", we share everything you need to know for a complete unauthenticated exploit on ruby-saml, using GitLab as a case-study.

portswigger.net/research/sam...

18.03.2025 14:57 โ€” ๐Ÿ‘ 52    ๐Ÿ” 23    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 4
Preview
The State of Secrets Sprawl Report | GitGuardian

Great resource on secret leakage, I invite you to read it.

12.03.2025 11:42 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Iโ€™ve updated the bug bounty & content creators starter pack with classic research group @hackerschoice.bsky.social! Let me know if youโ€™re not on this list and would like to be added.
go.bsky.app/GD7hKPX

03.02.2025 18:36 โ€” ๐Ÿ‘ 44    ๐Ÿ” 12    ๐Ÿ’ฌ 7    ๐Ÿ“Œ 2

Thanks for your all your votes! The public vote is now closed, and we're kicking off the panel vote with fifteen quality nominations. In the meantime we just published a new technique ourselves - check it out here:

22.01.2025 16:08 โ€” ๐Ÿ‘ 14    ๐Ÿ” 5    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Top 10 web hacking techniques of 2024 Welcome to the community vote for the Top 10 Web Hacking Techniques of 2024.

24 hours remaining until voting closes on the Top 10 (new) Web Hacking Techniques of 2024! If you haven't already voted now's the time to do it.
portswigger.net/polls/top-10...

21.01.2025 08:08 โ€” ๐Ÿ‘ 12    ๐Ÿ” 6    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Top 10 web hacking techniques of 2024 Welcome to the community vote for the Top 10 Web Hacking Techniques of 2024.

Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: portswigger.net/polls/top-10...

15.01.2025 15:24 โ€” ๐Ÿ‘ 24    ๐Ÿ” 8    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 7
Dom-Explorer

I've pushed some updates to Dom-Explorer:
- Allow multiple pipeline embed
- Short links for sharing/sync
- Support for DomPurify triggers
- User settings

Give it a try and share your findings!

yeswehack.github.io/Dom-Explorer

20.12.2024 13:54 โ€” ๐Ÿ‘ 20    ๐Ÿ” 6    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
EP 173 | Le rรฉcap : Kamal, Dokploy, Dokku, Portainer Ft. @AethliosIK & @penthium2
YouTube video by Laluka EP 173 | Le rรฉcap : Kamal, Dokploy, Dokku, Portainer Ft. @AethliosIK & @penthium2

Last part/EP with @aethlios.bsky.social & @penthium2.bsky.social ๐Ÿ˜˜

www.youtube.com/watch?v=UeOS...

16.12.2024 15:32 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
EP 172 | Portainer, and UID remap! Ft. @penthium2 & @AethliosIK
YouTube video by Laluka EP 172 | Portainer, and UID remap! Ft. @penthium2 & @AethliosIK

youtu.be/67DIr_OmXVk
cc @penthium2.bsky.social @aethlios.bsky.social ๐ŸŒน

15.12.2024 15:31 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
Why Can't You Fix This Bug Faster? Fixing security vulnerabilities in a timely manner is more complicated than you realize.

A younger me, as a pentester and bug hunter, had exactly the bias described in this article ๐Ÿคซ

Luckily, I later worked with and for "the other side" and it changed my mind ๐Ÿคฏ

I hope young people reading it will avoid taking years to understand the complexities of fixing bugs in a timely manner ๐Ÿคž

14.12.2024 23:02 โ€” ๐Ÿ‘ 60    ๐Ÿ” 16    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 5
EP 171 | Reset-tolkien Ft. @AethliosIK & @penthium2
YouTube video by Laluka EP 171 | Reset-tolkien Ft. @AethliosIK & @penthium2

www.youtube.com/watch?v=adf3...
with @aethlios.bsky.social & @penthium2.bsky.social ๐Ÿ’

13.12.2024 14:31 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Preview
Twitch Twitch is the world

Yo ! ๐Ÿง™โ€โ™‚๏ธ

Prochain stream demain -mardi 10 Dec- ร  21h !

Au programme ? We Deep Dive ! ๐Ÿง

- Reset-tolkien par @AethliosIK (X) ๐Ÿ—๏ธ
- Portainer & UID remap par @penthium2 (X) ๐Ÿณ

www.twitch.tv/thelaluka

09.12.2024 16:17 โ€” ๐Ÿ‘ 6    ๐Ÿ” 3    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

I feel like this post has wasted my time, but at least now I think my boiled eggs will be cooked to the second (I hope ๐Ÿซ ).

29.11.2024 16:55 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Bonjour,
Bienvenue dans ce live-skeet du procรจs de Florent Curtet, ce trentenaire poursuivi pour des extorsions numรฉriques, jugรฉ en cette fin de mois ร  Paris par le tribunal judiciaire.

25.11.2024 12:40 โ€” ๐Ÿ‘ 50    ๐Ÿ” 27    ๐Ÿ’ฌ 6    ๐Ÿ“Œ 5

A really comprehensive resource on CORS attacks. I'm going to rework my course slides based on this research, thank you for your contribution!

25.11.2024 14:01 โ€” ๐Ÿ‘ 9    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Custom lists are super cool! I enjoy reading social posts, but want to make sure I never miss a quality writeup or technique. To achieve this, I'm building a 'high signal web security' list of topic-focused accounts, which you can pin next to 'Following' if you want :)
bsky.app/profile/jame...

25.11.2024 13:09 โ€” ๐Ÿ‘ 57    ๐Ÿ” 16    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Preview
GitHub - AethliosIK/reset-tolkien: Unsecure time-based secret exploitation and Sandwich attack implementation Resources Unsecure time-based secret exploitation and Sandwich attack implementation Resources - GitHub - AethliosIK/reset-tolkien: Unsecure time-based secret exploitation and Sandwich attack implementatio...

I'm glad to see so many people switching over to Bluesky and following me!

Take the time to discover my open source tool on sandwich attacks :
๐Ÿ‘‰ github.com/AethliosIK/r...

25.11.2024 11:28 โ€” ๐Ÿ‘ 7    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

In case you're a professional Burp Suite user, there's a few seats left for the Q1 2025 training sessions

hackademy.agarri.fr/2025

17.11.2024 16:55 โ€” ๐Ÿ‘ 15    ๐Ÿ” 8    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 1

Any bug bounty people around? I'm creating a starter pack of people to follow but it's pretty brief currently! Let me know if you'd like to be added: go.bsky.app/GD7hKPX

21.11.2024 15:23 โ€” ๐Ÿ‘ 96    ๐Ÿ” 30    ๐Ÿ’ฌ 45    ๐Ÿ“Œ 2
Post image

My second article on time-based secrets has just been published! ๐Ÿš€

I explore a new usecase of the sandwich attack to set up a scenario for real-time monitoring of web application invitations.

- English version: aeth.cc/public/Artic...
- French version: aeth.cc/public/Artic...

18.07.2024 09:33 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Reset Tolkien

Reset Tolkien

Following #bugbounty findings, I started focusing my research on time-based secrets. This research began for me a year ago, and enabled me to take the time to implement my open source tool: โ€œReset Tolkienโ€. ๐Ÿš€

I've written an article detailing my research :
- ๐Ÿ‡ฌ๐Ÿ‡ง EN : www.aeth.cc/public/Artic...

02.04.2024 09:57 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@aethlios is following 20 prominent accounts