Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 687
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boostsMust remember not to open twitter anymore
Must remember not to open twitter anymore
Must remember not to open twitter anymore
Must remember not to open twitter anymore
I feel like I need something for my blood pressure after that.
Anyhow, how is everyone doing?
"This issue is Volume One, Issue One, released on November 17, 1985."
Don't mind me, just storing my account recovery codes here because we're all friends.
Dropbox
sqa7 brix
vwaf k2qm
oyda bgck
blmg hhsy
l93f trww
z1cp 0c1l
6vlt 320e
l5hn rwq1
kdnf nmky
9ddn vh61
7147 3084
6298 3780
2148 1878
5145 7791
3876 0444
8851 9256
2864 9061
3518 2411
1516 0291
2696 9257
154891
915269
271083
393744
451820
516234
773634
233741
018590
502965
8092 1121
9389 5246
3872 9286
4760 8952
2566 5417
5864 8282
3296 8476
4689 7152
0387 3760
4304 5896
Boost this toot if you're planning on sticking around Mastodon whether or not it becomes more popular than the birdsite.
Idea for the Windows bug bounty.. I call it the "Prove it" award. If we classify your bug as a DOS or not exploitable and you resubmit the bug with a working exploit that proves us wrong. We pay you 10x (or some large number) the original bounty. thoughts? #bugbounty
We're about 15 seconds away from someone getting Elon to open devtools, type in a console command, and have his creds exfilled
So I messed up the gotosocial instance TLS certs this morning, I ran into the let’s encrypt rate limit for threatactor.club because I forgot to configure a path for the certificates on the persistent volume, and for each new deploy it would pull fresh certificates 
The trick to recover was to first set a path and then manually fetch an EC cert for threatactor.club and another DNS name with certbot. This would not count against the rate limit of threatactor.club as a second name is added (see https://letsencrypt.org/docs/rate-limits/ ). Then I put everything in place on the persistent volume and got the instance back up.
nobody:
absolutely nobody:
yubikey: cccjgjgkhcbbcvchfkfhiiuunbtnvgihdfiktncvlhck
We are hiring - great opportunity to work with the team behind @metasploit as a Lead Security Researcher to address Emergent Threats - more details here: https://www.rapid7.com/careers/jobs/detail/?jid=R5574 #infosec #infosecjobs #cybersecurity
Hey #InfoSec Fedi,
I am looking for a new Job!
I would be interested in an offensive Security Position, preferred Red Teaming.
100% Remote is OK, but I need to be employable in Austria!
I have two years of professional Pentesting Experience + Trained Trainees IT Basics/programming, 5+ years Linux System Administration, 7+ Year CTFs.
I will make another post later where my CV will be available.
If you have questions, PM me!
#lookingforwork #work #job #search
I keep seeing lots of long-time #fediverse users saying 'don't favourite posts it does nothing' but actually when you favourite my posts it makes me smile and I'm sure I'm not the only one.
So this threatactor.club is running #gotosocial on a shared VM with 256 MB RAM. I’ve tried something new and used fly.io to host it. Works like a charm so far, with all the rough edges gotosocial still has.
The setup is somewhat similar to what’s described by @mfa in https://madflex.de/setup-fedi-cress-space/. I might post the actual configuration later on.
Short #introduction ahead:
I’m joern and I like to cause dumpster fires. I’m looking back to > 10 years of security consulting and since about three years I’m doing security research over at GitLab.
You can find an almost up to date list of some of the IT security related stuff I did in the past at https://0day.click/page/references/.
Fun fact: @fabs named his SAST tool joern after me 
The exploit I’m most proud of is the one for CVE-2012-0809, a format string issue in sudo. You can find it here: https://gist.github.com/joernchen/618a8940894084102fe2
The most notable shell I popped was on on www.ccc.de, which was due to https://github.com/hukl/cccms/blob/220c6f7bdfc0da33d4284495d6954b2b89f224f6/config/initializers/session_store.rb#L9 
Also I did a lot of Ruby on Rails hacking in the early 2010s and wrote about it in http://phrack.org/issues/69/12.html#article
Besides hacking and reading other people’s code I’m practicing Brazilian jiu-jitsu a lot in my spare time.
I’m legit @joernchen :D
Just created a secondary account @joern to mess a little with #gotosocial
https://github.com/superseriousbusiness/gotosocial
