Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 686
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boostsOk for some reason when I mentioned non-human identities and tracking them, a number of people assumed aliens or something, or just AI agents. What I am looking for are some insights into authentication actions on computer systems - using tokens, APIs, stored secrets, and so on - where a human is not directly involved in the interaction. Yes, AI could be involved, think MCP especially. I know there are tools out there to manage this, just wondering. Think using Okta SSO etc but not human users at all. Thoughts? Opinions? To me this is the next step in zero trust, in that one should have the same principles in place between any and all systems be they human or automated in that are they who or what they claim to be and are they authorized to do go forward and do what they are trying to do. #infosec #security #zerotrust
I wrote a short rant about what irks me when people anthropomorphize LLMs:
https://addxorrol.blogspot.com/2025/07/a-non-anthropomorphized-view-of-llms.html
PHRACK is coming to #DEFCON! We're printing ~10,000 zines and giving an hour-long talk you won't want to miss! Stay tuned. 🔥 #40yrsOfPhrack #phrack72
My ideal role would be primarily technical, aimed to dissect software to uncover vulnerabilities. Beyond bug mining I'd love to learn to mine better and make new kinds of pickaxes.
My public works and contact info are on my homepage:
https://scrapco.de
Get in touch if you want to know more!
Boosts are appreciated! #FediHire
Veranstaltungshinweis: https://www.eschschloraque.de/neon-bellies-27062025

Sadly, someone dropped a nonsense CVE on DOMPurify and now people are panicking and send us emails asking when the "fix" will be released.
https://security.snyk.io/vuln/SNYK-JS-DOMPURIFY-10176060
Does anyone here has a personal contact at Snyk who might be able to help with getting rid of this?
Speaker @joernchen
Bin ein bisschen aufgeregt wegen https://www.offensivecon.org/speakers/2025/joernchen.html morgen
Parser Differentials have become pretty much my favorite bug class over the last years.
I am absolutely honored to get the chance to present on this topic at OffensiveCon in a few weeks.
Shelly:
Kommt mit Firmware 1.2.X.
Upgrade möglich auf 1.3.X
Von da aus Upgrade auf 1.5.X
Kaufpreis: 20€
Solaranlage:
Kommt mit Firmware 1.0.X.
Aktuelle Firmware 13.212.X
Geht nicht. Supportticket. Tagelang warten. Geht immer noch nicht. Geht dann irgendwann doch.
Kaufpreis:
25000€.
WAS STIMMT BEI SOLAREDGE NICHT
Felt cute, might delete later
AI being useful
Soooo I built a little website based exploit for some CORS issue. Claude was really helpful to not only spit out a reasonably fast portscanner to use to find the target but also I used it to have a dark/light mode with a toggle and detection of the system default for the site.

