Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 686
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boostsPHRACK is coming to #DEFCON! We're printing ~10,000 zines and giving an hour-long talk you won't want to miss! Stay tuned. 🔥 #40yrsOfPhrack #phrack72
My ideal role would be primarily technical, aimed to dissect software to uncover vulnerabilities. Beyond bug mining I'd love to learn to mine better and make new kinds of pickaxes.
My public works and contact info are on my homepage:
https://scrapco.de
Get in touch if you want to know more!
Boosts are appreciated! #FediHire
Veranstaltungshinweis: https://www.eschschloraque.de/neon-bellies-27062025

Sadly, someone dropped a nonsense CVE on DOMPurify and now people are panicking and send us emails asking when the "fix" will be released.
https://security.snyk.io/vuln/SNYK-JS-DOMPURIFY-10176060
Does anyone here has a personal contact at Snyk who might be able to help with getting rid of this?
Speaker @joernchen
Bin ein bisschen aufgeregt wegen https://www.offensivecon.org/speakers/2025/joernchen.html morgen
Parser Differentials have become pretty much my favorite bug class over the last years.
I am absolutely honored to get the chance to present on this topic at OffensiveCon in a few weeks.
Shelly:
Kommt mit Firmware 1.2.X.
Upgrade möglich auf 1.3.X
Von da aus Upgrade auf 1.5.X
Kaufpreis: 20€
Solaranlage:
Kommt mit Firmware 1.0.X.
Aktuelle Firmware 13.212.X
Geht nicht. Supportticket. Tagelang warten. Geht immer noch nicht. Geht dann irgendwann doch.
Kaufpreis:
25000€.
WAS STIMMT BEI SOLAREDGE NICHT
Felt cute, might delete later
AI being useful
Soooo I built a little website based exploit for some CORS issue. Claude was really helpful to not only spit out a reasonably fast portscanner to use to find the target but also I used it to have a dark/light mode with a toggle and detection of the system default for the site.
How do the kids these days do a parasitic traceroute? Dan Kaminsky's (R.I.P.) website is gone, the copy of paketto that Kris Nova (R.I.P.) preserved on github doesn't build out of the box. There surely must be something fancy?
long shot, anyone have a list of every combination of encryption ciphers and cipher modes with references to exploits or implementation flaws that leads to practical attacks?
The BlackHoodie training at OffensiveCon has a whole of 2 seats left, and we will have a special give-away with this edition :) https://blackhoodie.re/Offensivecon2025/

