CryptoCat's Avatar

CryptoCat

@cryptocat.me.bsky.social

Security Researcher ๐Ÿ˜ˆ Hacking Content @ https://yt.cryptocat.me ๐Ÿ’œ

458 Followers  |  80 Following  |  92 Posts  |  Joined: 13.06.2023  |  1.999

Latest posts by cryptocat.me on Bluesky

Post image Post image Post image

Famous beef noodle soup (broth simmering continously for over 50 years!) in one of my all time favourite cities - Bangkok! ๐Ÿ‡น๐Ÿ‡ญ Any hackers here wanna hang out, hmu ๐Ÿค™

01.07.2025 07:48 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image Post image

Singapore ๐Ÿ‡ธ๐Ÿ‡ฌ

28.06.2025 09:35 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

I've done a lot of awesome hacker meetups but this one was next level! So nice to meet brutecat, dreyand and IDlSSEVERYTHING๐Ÿ”ฅ These guys have some crazy skills (and stories), hope to meet again in the future ๐Ÿ’œ

28.06.2025 09:34 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
CryptoCat x Singapore

CryptoCat x Singapore

I'll be in Singapore this weekend! I know there's lots of cool hackers there so hmu if you wanna get some coffee/food/drinks ๐Ÿฅฐ

26.06.2025 08:07 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image 13.06.2025 05:56 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image

Finally back in #KualaLumpur ๐Ÿ™ Meeting some of my favourite Malaysian hackers for food/drinks tomorrow night. If you wanna join, let me know! ๐Ÿฅฐ

12.06.2025 15:56 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image

๐Ÿ‰

09.06.2025 18:14 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Offensive Security Web Expert (OSWE) Review + Tips/Tricks [OffSec]
YouTube video by CryptoCat Offensive Security Web Expert (OSWE) Review + Tips/Tricks [OffSec]

My OSWE review, tips/tricks.. general ramblings ๐Ÿ‘€๐Ÿ˜…

youtu.be/IK4t-i5lDEs

03.06.2025 10:03 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
OSWE Exam Complete

OSWE Exam Complete

Just finished my OSWE exam ๐Ÿ‘€ Today I write up the report.. while watching #NahamCon ๐Ÿ˜Œ

23.05.2025 10:01 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Confetti: Solution to my Intigriti May 2025 XSS Challenge - Johan Carlsson

Here is the official writeup of my XSS challenge on Intigriti. I think it contains some fun browser trivia even for those who did not look at the chall

joaxcar.com/blog/2025/05...

20.05.2025 15:59 โ€” ๐Ÿ‘ 19    ๐Ÿ” 6    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Intigriti May XSS Challenge (0525) | Jorian Woltjer A challenge by @joaxcar with a small but complex XSS chain, hitting DOM Clobbering with a race condition and abusing a cool URL parsing quirk in JavaScript.

The legendary @joaxcar.bsky.social made a really interesting XSS challenge this month for Intigriti. My solution involved winning a race condition with 100 <iframe>s to utilize a DOM Clobbering gadget after bypassing a RegEx.
Check out the writeup below:
jorianwoltjer.com/blog/p/hacki...

17.05.2025 09:03 โ€” ๐Ÿ‘ 12    ๐Ÿ” 7    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
CryptoCat x Asia

CryptoCat x Asia

Heading back to SE-Asia next month.. Any hackers wanna hang out? ๐Ÿ‘€

Join my discord to keep up with the travel plans / arrange meetups: cryptocat.me/discord ๐Ÿ˜‡

#cybersecurity #ethicalhacking #infosec #bugbounty #ctf #asia

15.05.2025 10:34 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image

I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame", at #BHUSA! This is going to be epic, check out the abstract for a teaser โ†“

14.05.2025 13:31 โ€” ๐Ÿ‘ 39    ๐Ÿ” 18    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 1
Preview
Web | CTF Writeups

Writeups too โœ…

book.cryptocat.me/ctf-writeups...

05.05.2025 10:05 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Tsuku CTF Web Challenge Walkthroughs (2025)
YouTube video by CryptoCat Tsuku CTF Web Challenge Walkthroughs (2025)

Video walkthrough for the web challenges from Tsuku CTF ๐Ÿ’œ

youtu.be/qGd4d0zmhy8

05.05.2025 10:05 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Trust Me, Iโ€™m Local: Chrome Extensions, MCP, and the Sandbox Escape Letโ€™s talk about MCPs. Youโ€™ve probably heard of them, and maybe youโ€™ve read the security risks associated with them. Sure, they soundโ€ฆ

We already know that any Web server listening on the loopback interface is a security risk, because it may be accessed by a browser or its extensions.

But the impact may be way bigger if this Web server is a MCP server ๐Ÿ˜ฑ

blog.extensiontotal.com/trust-me-im-...

02.05.2025 17:40 โ€” ๐Ÿ‘ 26    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
CryptoCat's Discord: https://discord.cryptocat.me

CryptoCat's Discord: https://discord.cryptocat.me

Have YOU joined my discord server yet? Click the link below and let's talk about hacking stuff ๐Ÿ’œ

discord.cryptocat.me

01.05.2025 08:46 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
CTF@CIT Web Challenge Walkthroughs
YouTube video by CryptoCat CTF@CIT Web Challenge Walkthroughs

Added a video walkthrough for the web challenges from the recent CTF@CIT ๐Ÿ’œ

youtu.be/ZBdApaw0r0M

#capturetheflag #ctf #websecurity #bugbounty #cybersecurity #ethicalhacking #infosec

29.04.2025 14:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
CIT CTF web challenge writeups

CIT CTF web challenge writeups

Made writeups for the web challs featured in the CTF@CIT competition this weekend ๐Ÿšฉ

1) SQL injection
2) Git repo dumping
3) Local file read with basic filter bypass
4) Flask session cookie tampering + SSTI
5) Credential reuse / HTTP method tampering

book.cryptocat.me/ctf-writeups...

28.04.2025 10:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Next.js Middleware Auth Bypass (CVE-2025-29927) and Local File Read via XXE - HackDonalds Challenge
YouTube video by Intigriti Next.js Middleware Auth Bypass (CVE-2025-29927) and Local File Read via XXE - HackDonalds Challenge

Video for the HackDonalds Challenge by @intigriti.com ๐Ÿ’œ

youtu.be/KwD_TKZr0YY

15.04.2025 15:32 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
3 million views - https://yt.cryptocat.me

3 million views - https://yt.cryptocat.me

My YouTube channel has reached a new milestone; 3 million views! ๐Ÿฅณ๐ŸŽ‰

Next up - 50k subscribers! Help me get there ๐Ÿฅบ

yt.cryptocat.me

07.04.2025 14:42 โ€” ๐Ÿ‘ 5    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

๐Ÿฉธ First blood went to @sebsrt.bsky.social in under 15 mins ๐Ÿ‘

07.04.2025 14:07 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
HackDonalds Challenge - Bug Bounty Program - Intigriti Intigriti offers bug bounty and agile penetration testing solutions powered by Europe's #1 leading network of ethical hackers.

Once you've found the flag, you can report it (along with short steps-to-solve) here โœ…

go.intigriti.com/submit-solut...

07.04.2025 13:35 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
HackDonalds ๐ŸŸ Welcome to the most exploitable fast food chain on the net.

Who wants a bonus @intigriti.com challenge? Easier than usual ๐Ÿ‘€

First blood + best writeup win a โ‚ฌ50 swag voucher ๐Ÿ˜Ž

Find the flag before 15/04/25 ๐Ÿ‘‡

hackdonalds.intigriti.io

07.04.2025 13:35 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image Post image Post image Post image

London ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ™๐ŸŽจ

30.03.2025 08:38 โ€” ๐Ÿ‘ 4    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Exploiting NoSQL Operator Injection to Extract Unknown Fields
YouTube video by Intigriti Exploiting NoSQL Operator Injection to Extract Unknown Fields

Check out the walkthrough for the fourth (and currently final) @portswigger.net lab on NoSQL injection by @cryptocat.me ๐Ÿ˜ผ

youtu.be/aSXlmJ3lN4o

24.03.2025 15:50 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Post image Post image

Almost 600 hackers at ZeroDays CTF in #Dublin this year!! ๐Ÿ’œ

#ZeroDays #CTF #CaptureTheFlag #CyberSecurity #EthicalHacking #InfoSec #BugBounty #Ireland

22.03.2025 15:37 โ€” ๐Ÿ‘ 6    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
18 - API Security (low/med/high) - Damn Vulnerable Web Application (DVWA)
YouTube video by CryptoCat 18 - API Security (low/med/high) - Damn Vulnerable Web Application (DVWA)

As promised, I've updated my YouTube playlist with a walkthrough for the new API testing module in @digi.ninja's Damn Vulnerable Web Application (DVWA) ๐Ÿ’œ

www.youtube.com/watch?v=c_6R...

19.03.2025 15:20 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image Post image Post image

Met so many cool hackers over the past few days in Kuala Lumpur! ๐Ÿ’œ

16.03.2025 15:13 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image

Attending the amazing @1ns0mn1h4ck.bsky.social to represent @intigriti.com today!

Hit me up if you want to chat. I've got stickers and invite codes to hand out ๐Ÿ˜‰.

13.03.2025 10:27 โ€” ๐Ÿ‘ 6    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@cryptocat.me is following 20 prominent accounts