Mat's 25k Bath to Bristol Railway Run
Help Mat Rollings raise money to support Cool Earth
Since starting my training I've lost over 7kg, dropped 6% body fat, got 4 new Hawaiian shirts, and taken >5mins off my 5k time.
Am I ready? No. But I'll get through it by thinking about the post-run takeaway and bubble bath ๐ Last chance to donate๐
www.justgiving.com/page/oh-no-2...
09.10.2025 09:03 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Stealthcopter
Overly-greedy regex replacements can break HTML sanitisation and lead to XSS. I’ve already pulled in over $6k from this bug class, and there are plenty mo
REGEXSS: How .* Turned Into over $6k in Bounties
Overly-greedy regex replacements can break HTML sanitisation & lead to XSS. Includes a live demo you can try exploiting it yourself!
sec.stealthcopter.com/regexss
#BugBounty #BugBountyTips #XSS #AppSec
24.09.2025 07:50 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Last week I found two regex bugs using regex โ unauth XSS โ 2ร $2k = $4k in bounties ๐ฅณ If youโve been putting it off, learn regex. Seriously.
/regex\+xss/\$4k/
#BugBounty #BugBountyTips
11.09.2025 07:49 โ ๐ 1 ๐ 0 ๐ฌ 1 ๐ 0
Physically & emotionally drained after the rollercoaster that was @yeswehack.bsky.social's LHE at #NullconBerlin2025
@teamviewer.com was a tough target & I nearly gave up but pushed through to snag 10th place overall ๐ฅณ
Thanks to @yeswehack.bsky.social for the support & awesome hosting!
#BugBounty
06.09.2025 08:14 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
๐New plugin in the Caido Store!
Introducing "Exploit Generator" by @stealthcopter
Generate executable proof-of-concept (PoC) code from intercepted requests, in multiple languages and frameworks, such as Python, JavaScript, and Bash/cURL.
Check out more details: github.com/stealthcopte...
16.06.2025 12:25 โ ๐ 5 ๐ 3 ๐ฌ 0 ๐ 0
GitHub - stealthcopter/CaidoExploitGenerator
Contribute to stealthcopter/CaidoExploitGenerator development by creating an account on GitHub.
๐ Just released a new @caido.io plugin: Exploit Generator ๐ฃ
Generate clean, working, customizable PoC exploit scripts instantly in Python, JS, Bash/cURL (more langs & frameworks coming soon)
Live now in the Caido Plugin Store: github.com/stealthcopte...
#Caido #BugBounty
02.06.2025 10:44 โ ๐ 4 ๐ 1 ๐ฌ 0 ๐ 0
Selfie of me running the half marathon with the Clifton suspension bridge in the background
Survived the Bristol Half Marathon (2hr40). Then immediately got a kebab and cheesecake because I am an athlete ๐ช
Next: 25km Bath to Bristol for @coolearthaction.bsky.social. Please donate so the rainforest wins and I continue to question my life choices ๐๐
www.justgiving.com/page/oh-no-2...
12.05.2025 07:44 โ ๐ 5 ๐ 1 ๐ฌ 0 ๐ 0
Signed Hackers movie memorabilia and patchstack metch
Just received the coolest #ctf prize ever from @patchstack.com, signed Hackers memorabilia and swag!
๐พHACK THE PLANET! ๐
#BugBounty #HackThePlanet #Infosec #Hackers
10.04.2025 07:33 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
It's wild that I'm getting paid for this nonsense
#WordPress #BugBounty
10.03.2025 20:31 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Stealthcopter
Explore how creative tricks in PHP and WordPress allow you to bypass restrictions in a fun Patchstack CTF (S02E01) challenge and uncover neat tricks with filter
And for anyone wanting to learn some more PHP tricks ๐ช, here's my other two write ups for the Patchstack #wcasia2025 CTF, Blocked ๐
sec.stealthcopter.com/patchstack-c...
#CTF #WordPress #Hacking
26.02.2025 08:55 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0
Mat's 25k Bath to Bristol Railway Run
Help Mat Rollings raise money to support Cool Earth
I'm running 25k to raise money for Cool Earth. This will be the furthest Iโve ever run, and itโs going to be incredibly difficult!
Any donations are massively appreciated! ๐ Even if you donโt donate, check out the FAQ on my page, itโs worth a read!
www.justgiving.com/page/oh-no-2...
25.02.2025 08:49 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Stealthcopter
This writeup explores a Patchstack WordPress CTF challenge where a vulnerable custom footer feature allows for dynamic function execution. The challenge involve
Woop ๐ฅณI placed 5th in the @patchstack.com CTF at #wcasia2025 ๐ Here's my first write-up covering one of the trickier challenges, diving into PHPโs quirks, like mixed-case function calls and dynamic execution.
sec.stealthcopter.com/patchstack-c...
#CTF #WordPress #Hacking
24.02.2025 10:28 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 0
Unsupported Browser | HackerOne
Second collaboration of the year ๐ฅณ Many more to come ๐คI was awarded a $1,500 bounty on @Hacker0x01! hackerone.com/stealthcopter #TogetherWeHitHarder
12.02.2025 14:51 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 0
Stealthcopter
tldr; On their own, these two vulnerabilities in JupiterX Core wouldn’t have been very impactful or likely to get a bounty; but by chaining them together,
Chained two 'meh' WordPress vulnerabilities into a high-impact exploit on JupiterX Core ๐พ. From low-privilege SVG upload to full RCE, check out the full breakdown and PoC ๐ ๏ธ
#BugBounty #WordPress #Cybersecurity
sec.stealthcopter.com/jupiterx-cha...
01.02.2025 08:47 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
๐งฉ๐๐ง ๐๐ตโ๐ซ๐ โโก๏ธ๐คฏ๐ฉ๐ฅณ
๐งฉ๐๐ง ๐๐ตโ๐ซ๐ โโก๏ธ๐คฏ๐ฉ๐ฅณ
#ctf
22.11.2024 12:01 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
A bug squasher๐๏ธin spirit ๐
๐๐๐๐ฅ
https://github.com/sim4n6/sim4n6
Hacker | Bug Bounty Hunter
Full time bug bounty hunter. Look for โjoaxcarโ on other platforms
Remember, whatever happens... There's always a vulnerability
I enjoy pie.
Social Media FAQ: https://whatever.scalzi.com/2025/04/16/the-official-john-scalzi-social-media-faq/
Iโve boldly gone into the clear blue yonder. Follow for more recipes and tips.
Believe in yourself! Work hard, never give up & anything's possible! OR: Kick back, relax & aim low: You'll never be disappointed...๐ I IGNORE ALL DMs!
๐ฆ Software guy
๐ฆ Brighton chap
๐ช๐บ European fellow
Maker โข Founder & CTO @Popsa
Alaskan first, @raineycenter, energy, elections, info security, former Senate Energy comms guru, journalist, rabbit enthusiast, and lapsed rugger ๐
Cosmopolita, Europeo, Italiano. Non necessariamente in quest'ordine.
Dad โ Husband โ Low-Key Nerd โ EdD / JD
https://substack.com/@logicallyjc ๐ Subscribe
Wind energy engineer, knitter, tubist, Mama. Returned to Hamburg after many years in the UK.
Jazz, Jarre & Rock'n'Roll โข ๐ด๐ป โข Ambitiose Sed Ineptum
Rattsportbubble.