Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 687
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boostsCTF teams compiling ROP gadgets like
The person has several years of experience and a decent CV too, currently working in a senior position.
RE: https://infosec.place/objects/21ef69ce-b684-4e85-af5d-9c8729f3aeca
I'm looking for a used (preferably "used, as new") Lenovo T495s or T14s (16GB or more), so far ebay&co did not deliver convincing options. If you'd like to get rid of yours, let me know. Screen options: low-power or privacy guard variant, no touch. UK keyboard a plus.
Here's a fun story we discovered last year: accessing data in a Bitwarden vault without the password (biometrics, Windows Hello, domain-joined machine) https://blog.redteam-pentesting.de/2024/bitwarden-heist/
░░░░░░░░░░░░░░░ 0%
ping
OH: Intellektuelle Massephase
We disclosed this #hackerone report against #curl when someone asked Bard to find a vulnerability, and it hallucinated together something:
I smell quite some FUD about the alleged Signal 0day.
The recommendation is to turn off link previews, however link previews are generated on the sender side. Just tested, with link previews turned off you’ll still receive them from a device that sends those.
I think this would mean either:
- Turning off link previews isn’t a sufficient mitigation
or
- The vuln is triggering on the sender side that means someone needs to convince you to create a message containing a malicious link
or
- The whole thing is fake and just a nice troll
Irgendwas ist immer.
So hier zieht euch mal rein wie LiveOverflow da einen “Hacker” demontiert:
