Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 687
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boostsThe #cccamp23 orga is still looking for 15-20x 2-person sleeping tents for artists during the event - in the best case incl. sleeping mat/sleeping bag (will also be accepted individually).
If you can spare these things temporarily, please get in touch via email with the subject "Tent-for-artists" to camp2023-orga@cccv.de and write what you can bring in which amount for how long /co
Boosting wanted @c3cert @c3auti @jugendhackt @c3assemblies @haecksen @c3loc @C3Kidspace @c3infodesk
Want to help test the #CCCamp23 app for iOS and macOS? Sign up for TestFlight here: https://testflight.apple.com/join/HdrPYxM5
Remember me warning about Jean Pereira, an #infosec fraud? Well, there's a video detailing just how much he is overplaying his hand. https://youtu.be/duLJUpptSik
Muhahahah brilliant
Considering giving a talk titled: „I made my hobby my profession so I needed a new hobby. Now I’m cuddling grown men in pyjamas trying to choke them out or break their limbs - for fun“
Against earlier statements it looks like I'll be at the CCC Camp with my family. See you all there!
#SchreinerManja und den manischen #Radweg-Wahn der #CDU stoppen? Komm morgen an die Demo! Gemeinsam zum roten Rathaus. 14 Uhr, Eberswalder Straße.
#ADFC #ChanginCities #FridaysForFuture #DerKlimablog #Klimakatastrophe #Zukunft #Sicherheit #Gesundheit
Well, I inadvertently discovered a zero-day RCE in acme.sh and got a Chinese CA to shut down overnight: https://github.com/acmesh-official/acme.sh/issues/4659
The other shell I got was via some funky LDAP truncation issue. Check out the write up at https://0day.click/recipe/pash/
Last Christmas I popped a shell¹ on http://hg.mozilla.org
Here's the fix:
https://hg.mozilla.org/hgcustom/version-control-tools/rev/0b02dd442661b4ada84e4c6dea58ab62cb8fbaca
Can you explain the bug?
FAQ:
- This is an authenticated vuln
- I'll post a writeup in the next days
- Yes, RTFM helps ... as usual
¹) actually it was two shells
Unpopular take: .zip domains were a marketing gag targeting security people.
We found some injection bugs in Go's html/template. That's to say stdlib-level XSS 
