Turkey Dancer's Avatar

Turkey Dancer

@shaunau.bsky.social

Sometimes CTF. Frequently Pentesting. Weight training 4/7.

136 Followers  |  194 Following  |  1,243 Posts  |  Joined: 07.09.2023  |  1.7716

Latest posts by shaunau.bsky.social on Bluesky

AppSec Ezine

AppSec Ezine - 610th edition ๐ŸŽƒ #AppSec #Security

pathonproject.com/zb/?fac2c832...

01.11.2025 11:29 โ€” ๐Ÿ‘ 0    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Much of this is important for when Claude sessions need to be restarted.

31.10.2025 23:35 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Lots of planning discussion about architecture, pre-code. Project structure, rules around development. And where documents like IDEAS etc are stored. Use of PROPOSAL files to capture ideas discussed in depth. Important context and information discussed during dev I copy into my own notes files

31.10.2025 23:34 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

On Claude code: flipping between top down planning and bottom up implementation seems to produce pretty decent results. Single agent, review using batcat. Minimal edits with cli emacs to help CC with little things like placeholders. Simple CC.md file, strong documentation.md rules file.

31.10.2025 23:29 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
31.10.2025 22:45 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I guess the plan is to create a crime wave to try and justify the military being deployed

31.10.2025 22:38 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Join us in wishing a very spooky halloween and welcome to Jasie, our newest team member! ๐ŸŽƒ๐Ÿ•

Her official job title is Supervisor. Favourite activities include:

- Threat Hunting (for bikes)
- Security Testing (biting ankles)
- Compliance Monitoring (sniff testing)

Welcome!

31.10.2025 01:31 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
HTB: Store HTB Store walkthrough: exploiting XOR encryption for arbitrary file read, SFTP tunneling to Node.js debugger, and Chrome webdriver RCE for root access.

Store from VulnLab released on HackTheBox yesterday. It's got a web decryption known plaintext attack, directory traversal, node inspect, and Chrome debug.

30.10.2025 10:00 โ€” ๐Ÿ‘ 2    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Never in the history of the US has any president openly and repeatedly called for the investigation, arrest & prosecution of his political opponents. While many continue to shrug these things off and normalize them, I will never stop pointing out that this is what autocrats do.

29.10.2025 22:50 โ€” ๐Ÿ‘ 26763    ๐Ÿ” 9373    ๐Ÿ’ฌ 1968    ๐Ÿ“Œ 597
Preview
Home | BsideSydney25 BSides is a renowned Information Security conference that serves as a gathering point for the InfoSec community, fostering connections among like-minded professionals. Started in 2019, BSides Sydney has hosted, dynamic one-day events since then, showcasing presentations encompassing both offensive a...

In this talk, they will share their journeys as women building deep technical capability in cyber security, covering different generations, industries, and lived experiences.

Don't miss this one!ย 

Find event details here๐Ÿ‘‡

30.10.2025 01:30 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Iโ€™ve spent 2 solid hours doing bug bounty and I still havenโ€™t made $200k.

Can someone tell me what Iโ€™m doing wrong?

#bugbountytips

20.04.2025 23:09 โ€” ๐Ÿ‘ 5    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Reach out to @pentesterlab.com

29.10.2025 10:14 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Found an interesting ruby bug, time to see if it impacts rails. Anyone want to collab?

29.10.2025 08:34 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

The dumbest president in the world!!!
*brrrrrrrrrr* Lights out!

29.10.2025 09:43 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

Republicans have no money for SNAP to feed Americans, but when this guy needs $40 billion to bail him out before his election, that becomes Trumpโ€™s #2 priority after his ballroom.

29.10.2025 01:10 โ€” ๐Ÿ‘ 3266    ๐Ÿ” 1111    ๐Ÿ’ฌ 407    ๐Ÿ“Œ 91
Video thumbnail

Tim Cook was at Trump's speech in Tokyo today nodding along as Trump spewed lies

28.10.2025 16:17 โ€” ๐Ÿ‘ 898    ๐Ÿ” 270    ๐Ÿ’ฌ 147    ๐Ÿ“Œ 41
Post image Post image

What a difference four months makes. Imagine selling your house, moving for work and then being laid off anyway.

28.10.2025 18:51 โ€” ๐Ÿ‘ 248    ๐Ÿ” 74    ๐Ÿ’ฌ 6    ๐Ÿ“Œ 15

Is this situation just an inevitable side effect of capitalism?

28.10.2025 12:49 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I just donโ€™t get how the fuck all of this has happened - itโ€™s mind boggling how corrupt these pricks are. Someone stop them, for fuck sake.

28.10.2025 12:46 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Fortress Trust is insolvent
Nevada's Financial Institutions Division has issued a cease and desist order against Fortress Trust, stating that the firm is "on the verge of insolvency". The company admits it "failed to safeguard assets under its custody and is unable to meet all customer withdrawals". The company has only around $1.3 million in actual assets in custody, while it owes customers around $12.3 million.
In 2023, Fortress experienced a $15 million theft. Though the company originally announced it would be acquired by Ripple, which had agreed to cover the shortfall, the deal eventually fell through. It's not clear how โ€” or if โ€” the funds were ever restored.
Fortress's insolvency has strong parallels to that of Prime Trust, another trust company that shares a founder in Scott Purcell. NFID issued a cease and desist to Prime Trust in June 2023 after finding the company was insolvent; in bankruptcy proceedings, that company later blamed much of the insolvency on losing access to a

Fortress Trust is insolvent Nevada's Financial Institutions Division has issued a cease and desist order against Fortress Trust, stating that the firm is "on the verge of insolvency". The company admits it "failed to safeguard assets under its custody and is unable to meet all customer withdrawals". The company has only around $1.3 million in actual assets in custody, while it owes customers around $12.3 million. In 2023, Fortress experienced a $15 million theft. Though the company originally announced it would be acquired by Ripple, which had agreed to cover the shortfall, the deal eventually fell through. It's not clear how โ€” or if โ€” the funds were ever restored. Fortress's insolvency has strong parallels to that of Prime Trust, another trust company that shares a founder in Scott Purcell. NFID issued a cease and desist to Prime Trust in June 2023 after finding the company was insolvent; in bankruptcy proceedings, that company later blamed much of the insolvency on losing access to a

Fortress Trust is insolvent

October 22, 2025
https://www.web3isgoinggreat.com/?id=fortress-trust-insolvency

27.10.2025 23:59 โ€” ๐Ÿ‘ 57    ๐Ÿ” 6    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 1
Preview
Zoom CEO Eric Yuan says AI will shorten our workweek | TechCrunch Zoom CEO Eric Yuan says that, in a few years, we should be working a 3-4 day workweek because of AI.

Perfect timing for this story to drop on the same day Amazon lays off 30,000 workers due to claims of AI efficiencies.

If companies have less work for people to do, they donโ€™t give you Fridays off, they lay off people until everyone has a full workweek.

28.10.2025 00:20 โ€” ๐Ÿ‘ 489    ๐Ÿ” 165    ๐Ÿ’ฌ 23    ๐Ÿ“Œ 25
Preview
PentesterLab: Learn with our Python Code Review Badge The Python Code Review Badge is our badge dedicated to code review in Python. It covers the discovery of weaknesses and vulnerabilities using source code review.

๐Ÿšจ New labs just dropped!

3 new Python Code Review labs are now live on PentesterLab ๐Ÿ
Learn to spot subtle bugs and insecure patterns by reading real Python code.

๐ŸŽฏ pentesterlab.com/badges/python-code-review

#Python #AppSec #CodeReview #PentesterLab

28.10.2025 03:37 โ€” ๐Ÿ‘ 3    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

So if a doctor rents an apartment I own, Iโ€™m a doctor?

26.10.2025 22:26 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

โ€œItโ€™s a warningโ€ cโ€™mon.. how many โ€œwarningsโ€ do you need?

26.10.2025 09:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Do we expect to see a โ€œsustainably sourced dataโ€ badge for each SOTA model anytime soon? ๐Ÿ˜‚

25.10.2025 23:47 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Itโ€™s like feeding pigs their own shit, or feeding humans food made by humans by (from a shit tonne of chemicals) and wondering why every little kid is now a fat fuck with ADHD.

Simply put: garbage in, garbage out

25.10.2025 23:44 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Preview
HTB: Artificial Artificial starts with an AI website where I can upload models that are run with TensorFlow. Iโ€™ll exploit a deserialization vulnerability in how TensorFlow handles h5 files to get RCE and a foothold. Iโ€™ll find hashes in the database and crack one to pivot to the next user. That user has access to an instance of Backrest running on localhost. Iโ€™ll find the config and crack the hash to get access, and then show three ways to get execution as root through the application.

Artificial from HackTheBox is starts with uploading a malicious TensorFlow model to get a foothold through deserialization. I'll abuse Backrest in three different ways for root.

25.10.2025 15:00 โ€” ๐Ÿ‘ 4    ๐Ÿ” 4    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Iโ€™m pretty fucking sick of newsletters attempting to convert me to a paying customer

25.10.2025 23:31 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

iOS 26 is truly terrible in every way.

25.10.2025 12:53 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@shaunau is following 20 prominent accounts