Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 687
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boostsOR: Artificial Intelligence Agency (ChatBND)
Indicating how to report a vulnerability forcing going through a bug bounty program and its rules is, imho, plain wrong.
Always allow spontaneous and non binding reporting, not everyone wants (or can) submit to a bug bounty, while wanting to serve public interest.
I've been working on a client-side web app to inspect and analyze arbitrary data.
It's like a lightweight CyberChef that automatically builds recipes by recursively detecting and unpacking layers of encoding and compression.
It also lets you select specific parts of the input with your cursor to focus the inspection, which is neat when analyzing data that consists of multiple parts, or for skipping non-data prefixes and data separators.
I am going to talk at German OWASP Day in Leipzig today and I just learned it will be live streamed.
Tune in if you want to learn about cross-site leaks at 5pm CET (9am US Pacific). There's lots of other interesting stuff before me. The event has already started 😊 https://streaming.media.ccc.de/god2024
Shitpost / Cyber
From now on any instance of the word "cyber" in PowerPoint presentations must be replaced with this font/text. Bonus points if you add animated gifs of dolphins.
#cyber
http://phrack.org/issues/71/1.html new Phrack is out!
My colleague @nickmalcolm made a pretty cool vuln explainer video
PSA: If you use GOGS.io (the predecessor to Gitea and friends), please make sure self-registration is disabled. I reported a trivial RCE a couple months ago, received no reply, and it's starting to look intentional.
how many kernel bugs do u think are left
Earlier this year I found a pretty cool vuln, an arbitrary file write in GitLab.
Here’s the details https://gitlab-com.gitlab.io/gl-security/security-tech-notes/security-research-tech-notes/devfile/
My employer #GitLab is hiring, specifically in the Security division. Security Identity Management is the area, so if you're into #Security and #IAM and you're qualified, apply. If not, a few other positions are available, feel free to poke around. Fully remote. I'm not shopping for a referral, I'm shopping for a work colleague, so apply!
Terrestrische Astronautinnen und Astronauten für Bettruhestudie gesucht
https://www.dlr.de/de/aktuelles/nachrichten/2024/terrestrische-astronautinnen-und-astronauten-fuer-bettruhestudie-gesucht
Today we’re releasing weAudit, the VSCode extension we use during secure code reviews to collaboratively take notes and highlight code regions. https://blog.trailofbits.com/2024/03/19/read-code-like-a-pro-with-our-weaudit-vscode-extension/
weAudit keeps you focused on the code by allowing you to bookmark findings, open detailed GitHub issues, and track audited files without ever leaving VSCode.
Install it through the VSCode marketplace or view the code and send us your feature requests in our GitHub repo vscode-weaudit repo.
https://marketplace.visualstudio.com/items?itemName=trailofbits.weaudit

