I'm excited to share that I recently found a XSS in Quasar Framework. The CVE-2025-43954 has just been published to document this security issue.
You can learn more about it here:
- github.com/advisories/G...
@aethlios.bsky.social
Lead developer | Bug hunter (approximately every 3 months) > https://aeth.cc
I'm excited to share that I recently found a XSS in Quasar Framework. The CVE-2025-43954 has just been published to document this security issue.
You can learn more about it here:
- github.com/advisories/G...
You might have noticed that the recent SAML writeups omit some crucial details. In "SAML roulette: the hacker always wins", we share everything you need to know for a complete unauthenticated exploit on ruby-saml, using GitLab as a case-study.
portswigger.net/research/sam...
Great resource on secret leakage, I invite you to read it.
12.03.2025 11:42 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0Iโve updated the bug bounty & content creators starter pack with classic research group @hackerschoice.bsky.social! Let me know if youโre not on this list and would like to be added.
go.bsky.app/GD7hKPX
Thanks for your all your votes! The public vote is now closed, and we're kicking off the panel vote with fifteen quality nominations. In the meantime we just published a new technique ourselves - check it out here:
22.01.2025 16:08 โ ๐ 14 ๐ 5 ๐ฌ 0 ๐ 024 hours remaining until voting closes on the Top 10 (new) Web Hacking Techniques of 2024! If you haven't already voted now's the time to do it.
portswigger.net/polls/top-10...
Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: portswigger.net/polls/top-10...
15.01.2025 15:24 โ ๐ 24 ๐ 8 ๐ฌ 0 ๐ 7I've pushed some updates to Dom-Explorer:
- Allow multiple pipeline embed
- Short links for sharing/sync
- Support for DomPurify triggers
- User settings
Give it a try and share your findings!
yeswehack.github.io/Dom-Explorer
Last part/EP with @aethlios.bsky.social & @penthium2.bsky.social ๐
www.youtube.com/watch?v=UeOS...
youtu.be/67DIr_OmXVk
cc @penthium2.bsky.social @aethlios.bsky.social ๐น
A younger me, as a pentester and bug hunter, had exactly the bias described in this article ๐คซ
Luckily, I later worked with and for "the other side" and it changed my mind ๐คฏ
I hope young people reading it will avoid taking years to understand the complexities of fixing bugs in a timely manner ๐ค
www.youtube.com/watch?v=adf3...
with @aethlios.bsky.social & @penthium2.bsky.social ๐
Yo ! ๐งโโ๏ธ
Prochain stream demain -mardi 10 Dec- ร 21h !
Au programme ? We Deep Dive ! ๐ง
- Reset-tolkien par @AethliosIK (X) ๐๏ธ
- Portainer & UID remap par @penthium2 (X) ๐ณ
www.twitch.tv/thelaluka
I feel like this post has wasted my time, but at least now I think my boiled eggs will be cooked to the second (I hope ๐ซ ).
29.11.2024 16:55 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Bonjour,
Bienvenue dans ce live-skeet du procรจs de Florent Curtet, ce trentenaire poursuivi pour des extorsions numรฉriques, jugรฉ en cette fin de mois ร Paris par le tribunal judiciaire.
A really comprehensive resource on CORS attacks. I'm going to rework my course slides based on this research, thank you for your contribution!
25.11.2024 14:01 โ ๐ 9 ๐ 2 ๐ฌ 1 ๐ 0Custom lists are super cool! I enjoy reading social posts, but want to make sure I never miss a quality writeup or technique. To achieve this, I'm building a 'high signal web security' list of topic-focused accounts, which you can pin next to 'Following' if you want :)
bsky.app/profile/jame...
I'm glad to see so many people switching over to Bluesky and following me!
Take the time to discover my open source tool on sandwich attacks :
๐ github.com/AethliosIK/r...
In case you're a professional Burp Suite user, there's a few seats left for the Q1 2025 training sessions
hackademy.agarri.fr/2025
Any bug bounty people around? I'm creating a starter pack of people to follow but it's pretty brief currently! Let me know if you'd like to be added: go.bsky.app/GD7hKPX
21.11.2024 15:23 โ ๐ 96 ๐ 30 ๐ฌ 45 ๐ 2My second article on time-based secrets has just been published! ๐
I explore a new usecase of the sandwich attack to set up a scenario for real-time monitoring of web application invitations.
- English version: aeth.cc/public/Artic...
- French version: aeth.cc/public/Artic...
Reset Tolkien
Following #bugbounty findings, I started focusing my research on time-based secrets. This research began for me a year ago, and enabled me to take the time to implement my open source tool: โReset Tolkienโ. ๐
I've written an article detailing my research :
- ๐ฌ๐ง EN : www.aeth.cc/public/Artic...