Profile for joern

Display name
joernchen :cute_dumpster_fire:
Username
@joern@threatactor.club
Role
admin

About joern

Bio

Your mom's favorite hacker!

My other account is @joernchen

Stats

Joined
Posts
687
Followed by
1129
Following
261

Recent public posts

exclude boosts
joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @Hetti@chaos.social
Hetti :yayblob: ʷᵃʳᶦ , @Hetti@chaos.social
(open profile)

Hey Fedi,

I am looking for a new Job!

I would be interested in an offensive Security Position, preferred Red Teaming.

100% Remote is OK, but I need to be employable in Austria!

I have two years of professional Pentesting Experience + Trained Trainees IT Basics/programming, 5+ years Linux System Administration, 7+ Year CTFs.

I will make another post later where my CV will be available.

If you have questions, PM me!

:boost_ok: Boost appreciated!

So this threatactor.club is running #gotosocial on a shared VM with 256 MB RAM. I’ve tried something new and used fly.io to host it. Works like a charm so far, with all the rough edges gotosocial still has.

The setup is somewhat similar to what’s described by @mfa in https://madflex.de/setup-fedi-cress-space/. I might post the actual configuration later on.

Short #introduction ahead:

I’m joern and I like to cause dumpster fires. I’m looking back to > 10 years of security consulting and since about three years I’m doing security research over at GitLab.

You can find an almost up to date list of some of the IT security related stuff I did in the past at https://0day.click/page/references/.

Fun fact: @fabs named his SAST tool joern after me :trollface:. Find it at https://joern.io

The exploit I’m most proud of is the one for CVE-2012-0809, a format string issue in sudo. You can find it here: https://gist.github.com/joernchen/618a8940894084102fe2

The most notable shell I popped was on on www.ccc.de, which was due to https://github.com/hukl/cccms/blob/220c6f7bdfc0da33d4284495d6954b2b89f224f6/config/initializers/session_store.rb#L9 :lolol:

Also I did a lot of Ruby on Rails hacking in the early 2010s and wrote about it in http://phrack.org/issues/69/12.html#article

Besides hacking and reading other people’s code I’m practicing Brazilian jiu-jitsu a lot in my spare time.

#introductions #security #infosec #hacking