« On est en train de discuter des livres que va lire Nicolas Sarkozy en prison ? Alors qu'il a été condamné pour "association de malfaiteurs". »
@fabricearfi.bsky.social Journaliste d’investigation
La suite :
⏰ 22h50 sur france·tv
➡️https://bit.ly/SarkozyEnPrisonHonneurDeshonneur
🎧en podcast
21.10.2025 18:52 — 👍 2478 🔁 1170 💬 82 📌 110
🤣🤣🤣
21.10.2025 13:49 — 👍 0 🔁 0 💬 0 📌 0
I’m excited to announce that I’ll be presenting The Fragile Lock: Novel Bypasses for SAML Authentication at Black Hat Europe! In this talk, I’ll show how I was able to continuously bypass security patches to achieve complete auth bypass for major libraries. #BHEU @blackhatevents.bsky.social
07.10.2025 14:55 — 👍 25 🔁 6 💬 0 📌 0
Je lance une bouteille à la mer ...
Les @restosducoeur 💞cherchent beaucoup d’ordinateurs portables et tiny (Linux friendly 🐧). Si votre entreprise a du stock dormant ou autre, ça nous aiderait beaucoup !
Repost apprécié :)🫶🏻
06.10.2025 07:57 — 👍 160 🔁 376 💬 16 📌 3
Penetration Testing
Request a penetration test for your AWS cloud infrastructure here.
In case you missed it, AWS updated its policy about pentesting, and "Amazon API Gateway" (used by the extension "IP Rotate") isn't allowed anymore
aws.amazon.com/fr/security/...
01.10.2025 09:21 — 👍 2 🔁 2 💬 1 📌 0
Nice one ! #lichess #chess @lichess.org
26.09.2025 16:03 — 👍 1 🔁 0 💬 0 📌 0
🚨NEW: "The Late Show with Stephen Colbert" just dropped its first response to ABC, FCC chair, and Disney firing Jimmy Kimmel.
Trump ain't sleeping tonight. 🤣
This is a must-watch. 🔥
19.09.2025 03:02 — 👍 5814 🔁 2775 💬 154 📌 338
1st time I start Burp to do bug bounty since the begining of June. Let's see if I still enjoy it or if I need more time to get back at it...
18.08.2025 16:41 — 👍 3 🔁 0 💬 0 📌 0
It's probably a cool research topic then 🙂
08.08.2025 17:59 — 👍 0 🔁 0 💬 1 📌 0
Some good collaborations on the way? 🙂
08.08.2025 08:34 — 👍 1 🔁 0 💬 1 📌 0
How to make $$$ from request smuggling
Step 1) Pick the right target:
11.07.2025 12:15 — 👍 29 🔁 2 💬 2 📌 0
"Ce qu’on est en train de vivre aujourd’hui, c’est les trajectoires qu’on avait imaginées il y a 20 ans. La communauté des climatologues n’est pas du tout surprise par la vague de chaleur qui arrive. Elle est effrayée." @cassouman40.bsky.social ce matin sur @franceinfo.fr #VagueDeChaleur #DontLookUp
20.06.2025 10:34 — 👍 509 🔁 359 💬 8 📌 40
This is so cool! Congrats!
19.06.2025 11:03 — 👍 2 🔁 0 💬 0 📌 0
Looking forward to read the write up 😉
18.06.2025 17:11 — 👍 1 🔁 0 💬 0 📌 0
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame" is coming to #DEFCON33! This talk will feature multiple new classes of desync attack, mass exploitation spanning multiple CDNs, and over $200k in bug bounties. See you there!
10.06.2025 14:20 — 👍 43 🔁 11 💬 0 📌 1
Mais putain 🤦
Enfin, au moins on sait pour qui ils roulent...
31.05.2025 06:39 — 👍 3 🔁 0 💬 0 📌 0
Bye bye full time bug bounty hunting. It's been a hell of a ride, but it's time to move on...
30.05.2025 16:33 — 👍 3 🔁 0 💬 1 📌 0
And that would explain why the desync is so rare ? Or why it happens only in one way ?
I'm not sure to get your point here, sorry.
30.05.2025 12:09 — 👍 0 🔁 0 💬 1 📌 0
AppSec Ezine
AppSec Ezine - 589th edition #AppSec #Security
pathonproject.com/zb/?33afd768...
30.05.2025 09:43 — 👍 5 🔁 5 💬 0 📌 0
And the requests I need to send to trigger the desync are reaaaaaaaaally weird, I'm really wondering what happens in the backend :)
30.05.2025 09:57 — 👍 1 🔁 0 💬 0 📌 0
The single packet attack does not seem to work.
With Turbo Intruder and ffuf running (from another IP) I sometimes see one poisoned response received by ffuf, but it never happens in the other way around.
30.05.2025 09:48 — 👍 0 🔁 0 💬 2 📌 0
Weird, I'm able to poison the queue and send other people responses to my requests (although it requires a lot of requests to be sent. It does not happen often at all).
But so far I can't get other people responses.
30.05.2025 09:28 — 👍 0 🔁 0 💬 2 📌 0
Impressive, congrats ! :)
28.05.2025 20:39 — 👍 1 🔁 0 💬 0 📌 0
Active Scan++ just got sharper - we’ve added new checks for OS command injection, powered by our latest ASCII Control Characters research. Install via Extensions -> BApp Store
28.05.2025 14:56 — 👍 10 🔁 6 💬 1 📌 0
Thanks for the tip !
I'm slowly making progress. For now I can redirect users to arbitrary URLs by poisoning the queue like you showed in your paper.
Stealing other people's responses would be much cooler though :)
28.05.2025 12:47 — 👍 2 🔁 0 💬 1 📌 0
Organizer @nsec.io, Hacker, CTFs, Privacy, Research, Social Tech, Serial Expat 🗺️🧭
Software Supply Chain Red Team. SourceCodeRED & SecureStack founder, dad, startup OG, snowboarder and hacker. Workin on GitHax tool in my spare time. github.com/6mile
@eastsidemccarty from the bird site.
Penetration Tester
@ShielderSec
| Bachelor's Degree in Computer Engineering | IT and Cyber Security lover!
Detection Engineer & Threat Hunter. Livin in the Lou.
Cristão ✝️
Junior DevOps Engineer 🧑💻
Basquete 🏀 | BJJ 🥋
#ThunderUp #studytech
Developer / Ethical Hacker / Bug Bounty Hunter | Lead Platform Architect at http://brella.io | Views are mine
Teacher, neurobiologist, hyper-follower from Milan, Italy.
psychosociology, cybersecurity, writer. queer & disabled activist.
top 5 sleepy AuDHD bearcat dads
they/he 💚
Infosec hobbyist, armchair software developer, and wannabe script kiddie. Konohana Kitan is great. Formerly @ren_daga_otaku on X
[ dad | nerd | coder | gamer | red team | pen tester | tx ]
he/him
Off-white hat hacker
https://yechiel.xyz
He/him - 36. 🔞 🇺🇦 #NAFO - Fearless Era Swiftie - Nashville Eras Tour N2. long walks are the best. QA Engineer / infosec shitposter. no comment should be assumed to refer to any employer.
I am a business researcher. I am also very interested in artificial intelligence and business and education and medicine. Also, I am very interested in popular culture and music. I strive to live a simple healthy life. DTM and CBI.Score counselor.
🇵🇱 Student, nerd. I love free and open source software that I can break and then spend 10 hours trying to fix.
#linux #security #privacy #iusearchbtw
It's not a data breach, it's a surprise backup.
I do tech stuff & post random crap. Wellington Pastafarian CISO/CIO and Wannabe Sci-Fi Author 📚 Tree Hugger 🌎 bass 🎸& bari sax 🎷 NZ/US(NC) he/him
Communauté étudiante de cyber à Polytechnique Montréal (@polymtl.bsky.social) 🚩#CTF
🔗 À propos: polycyber.io
🔗 Notre CTF: pwn.polycyber.io
🔗 Apprendre: ressources.polycyber.io