alp1n3 ๐ŸŒฒ's Avatar

alp1n3 ๐ŸŒฒ

@alp1n3.dev.bsky.social

๐Ÿ”ฎ AppSec & Go | Ex: ARCYBER

464 Followers  |  255 Following  |  589 Posts  |  Joined: 04.07.2024  |  2.0111

Latest posts by alp1n3.dev on Bluesky

๐Ÿ’ก Discovery of the week for me:
While reviewing code on a .Net project (CSharp language), I noticed that SemGrep, with its set of community rules, was not effective on this technology.

So I looked for a complement and found Microsoft's DevSkim tool...

06.08.2025 06:07 โ€” ๐Ÿ‘ 4    ๐Ÿ” 1    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
GitHub Security Bug Bounty Program

Here are our July bug bounty stats!
โœ…174 bounty reports submitted
๐Ÿ‘ฅ140 hackers participated in our program
๐Ÿ’ฐ Awarded $103,202 in bounties

Found a vulnerability? Submit it here: bounty.github.com.

06.08.2025 06:57 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

When are you going to drop links to GitHub repos that also contain 100+ links to random Medium articles???

06.08.2025 09:43 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Perplexity is using stealth, undeclared crawlers to evade website no-crawl directives Perplexity is repeatedly modifying their user agent and changing IPs and ASNs to hide their crawling activity, in direct conflict with explicit no-crawl preferences expressed by websites.

It's very cool and good that the ghouls making these things have no regard for even the most minimal of norms to identify themselves.

Now this right here? This is piracy.

blog.cloudflare.com/...

04.08.2025 14:46 โ€” ๐Ÿ‘ 2    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

โ€œWhy use Bash, Python, or Go when you can use JS from the console!โ€

๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚

04.08.2025 09:26 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Canโ€™t wait until someone other than Meta makes a good pair of these. Deleted my FB account a while back and when I went back to sign up again I just got insta-banned :(

01.08.2025 10:03 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Freebies - Mastering Burp Suite Pro Freebies - Mastering Burp Suite Pro

I just added the 15-minute talk I gave at Tumpicon to the "Freebies" section.

This talk covers the extensions Piper and Scalpel, and allows users to easily manipulate encrypted data by shuffling blocks around

hackademy.agarri.fr/freebies

25.07.2025 16:38 โ€” ๐Ÿ‘ 7    ๐Ÿ” 6    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Unsupported Browser | HackerOne

Just had my #bugbounty report disclosed on
#HackerOne ๐Ÿ’ช

TL;DR
RCE via path traversal in the Mozilla VPN Client through the local websocket server (developer mode).

hackerone.com/reports/2995...

29.07.2025 10:46 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1

Thanks for adding support for Zed! Absolutely love it as an IDE.

29.07.2025 11:45 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Sick! ๐Ÿ™Œ

What are you using to record your terminal? Super crisp, and the auto-zoom is pretty handy to show the specific commands.

28.07.2025 10:07 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Video thumbnail

How to grab subs for a target using subfinder, validate them and extract the text body from each response using httpx and jq, extract a wordlist of keywords using NLP then resolve them using puredns to find valid subdomains ๐Ÿ‘‡

28.07.2025 08:28 โ€” ๐Ÿ‘ 5    ๐Ÿ” 2    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Post image Post image

Made the switch from an Apple Watch to Suunto, and Iโ€™m loving it!

Still does everything I used:
- Tracking Training
- Notifications
- Alarms / Timers

Iโ€™ve had it on my wrist for 5 days, and itโ€™s only at 47% battery. Absolutely amazing battery life, and for the price itโ€™s a steal!

27.07.2025 13:09 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I suspect the major negative fallout of vibe coding isnโ€™t going to be taking jobs from software developers but instead an epidemic of insecure apps that get hacked with ease

25.07.2025 19:25 โ€” ๐Ÿ‘ 615    ๐Ÿ” 84    ๐Ÿ’ฌ 30    ๐Ÿ“Œ 20

Part of the job as a cybersecurity professional is in fact arguing to purge and not log information about your customers.

Data is not oil. It's risk.

26.07.2025 00:56 โ€” ๐Ÿ‘ 300    ๐Ÿ” 43    ๐Ÿ’ฌ 11    ๐Ÿ“Œ 3

The web reader to clear up distractions in Safari is one of the best things Iโ€™ve ever used in a browser.

Itโ€™s up there with uBlock Origin.

26.07.2025 13:54 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Who's SHA is it Anyway: Bypassing Google Cloud Build Comment Control for $30,000 Overview I reported a subtle race condition in Google Cloud Buildโ€™s GitHub integration that could have allowed someone to bypass maintainer review when running pull request integrations tests. Google ...

$30,000 for a race condition on Google Cloud Build ๐Ÿ’ฐ by @adnanthekhan.bsky.social

adnanthekhan.com/posts/cloud-...

23.07.2025 15:39 โ€” ๐Ÿ‘ 3    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

If you can afford it, could always try hacking on a VDP that leans towards disclosure in between other projects.

++ for grabbing a pentesting role, you might end up liking it a lot and staying ๐Ÿ˜‰

22.07.2025 19:50 โ€” ๐Ÿ‘ 2    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Post image Post image

๐Ÿ”ฅ Want to think like a hacker and truly understand JavaScript?

๐Ÿ’ป JavaScript for Hackers is your guide to breaking, bending, and mastering the language like never before.

09.07.2025 17:11 โ€” ๐Ÿ‘ 16    ๐Ÿ” 6    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Intigriti July XSS Challenge (0725) | Jorian Woltjer My author's writeup of the July 2025 challenge. Perform Mutation XSS to DOM Clobber an change the insertion point into an iframe, then bypass the CSP using a new useful Socket.IO gadget

I made a hard @intigriti.com XSS challenge this July ๐Ÿ˜…
But, it involves some very interesting Mutation XSS & DOM Clobbering fun combined with a CSP Bypass using the powerful SocketIO gadget.
Everything's explained in my writeup below!
jorianwoltjer.com/blog/p/ctf/i...

19.07.2025 16:18 โ€” ๐Ÿ‘ 6    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

This is pretty cool. Things start getting really confusing when you look into the chunk extensions so... this is a huge help!

22.07.2025 14:00 โ€” ๐Ÿ‘ 2    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Yeah I use the Novablast 2s a lot and like them (good lock in & durability)! The way they pronate isnโ€™t an exact match to me, but thatโ€™s because I wear barefoot shoes when Iโ€™m not running.

If you have a Fleet Feet or something similar nearby, theyโ€™re great for trying on all the brands.

22.07.2025 15:51 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

Congratulations! ๐Ÿพ๐ŸŽ‰

Looking forward to the future SemGrep and security content ๐Ÿ˜๐Ÿ™Œ

22.07.2025 12:13 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Have you tried Brooks or ASICS?

Not sure on the cost there, but I usually am able to find the generation or two behind the current release on sale for about $60-$80 USD.

22.07.2025 12:10 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

haha CVE-2025-53770 whats the big deal amirite

21.07.2025 12:43 โ€” ๐Ÿ‘ 10    ๐Ÿ” 1    ๐Ÿ’ฌ 3    ๐Ÿ“Œ 1

Join the Twitch stream, and follow along with the book by @zachdaniel.dev & @sevensea.cat :
pragprog.com/titles/ldash...

21.07.2025 03:40 โ€” ๐Ÿ‘ 1    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

Is the entry-level price still essentially around $500-$600 for a camera or two + the hub?

Checked into it a while ago because I needed just a single camera + a way to locally control it, but didnโ€™t think it was worth the cost in that instance.

20.07.2025 17:17 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

100%. Same goes for going to the ER as well.

If you have to ask yourself โ€œDo I need to go to the ER?โ€ or have any doubt of your status over the next day or two, you probably do.

And ER =! urgent care.

16.07.2025 14:07 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

As someone who has been debugging Playwright tests primarily via page.pause() and PWDEBUG for the past five years, I am blown away by Trace Viewer and live debugging through their vscode extension.

It's just so. Much. Better.

Use those two, thank me later.

16.07.2025 11:51 โ€” ๐Ÿ‘ 26    ๐Ÿ” 3    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 1
Post image

If I was a bad guy who was looking for memory vulns, I'd be ALL OVER these new hotness web browsers. (Comet, Arc, etc.)

Market share is small but much more valuable targets. - Teams behind them way smaller than ...Google

15.07.2025 19:09 โ€” ๐Ÿ‘ 11    ๐Ÿ” 3    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0

Iโ€™d bet itโ€™s good for any vulns (in general). Thereโ€™s new reports for Chrome everyday, and the add-ons these companies integrate can probably lead to some cool finds!

Saw this post right after I saw one about leaking the IPs of users using the Braveโ€™s integrated TOR browser.

16.07.2025 12:40 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@alp1n3.dev is following 20 prominent accounts