Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 686
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boostsWant to hack AI things with me?
Took way too long to get this one released https://x41-dsec.de/lab/advisories/x41-2024-004-Medico/
A quick reminder: dueling URL parsers is a path to pain and sorrow.
(blogged two years ago)
https://daniel.haxx.se/blog/2022/01/10/dont-mix-url-parsers/
Ruby's Marshal deserialization has been broken for over a decade, and patches don't solve the fundamental issue. Read our full analysis of 11 years of Ruby deserialization exploits and why fundamental change is needed: https://blog.trailofbits.com/2025/08/20/marshal-madness-a-brief-history-of-ruby-deserialization-exploits/
I’m looking for audio or videos from early Dutch Hacker cons, does anyone know if they exist for Hacking In Progress (HIP97), Hacking at the End of the Universe (HEU93), or Galactic Hacker Party (GHP89) ?
Today I have a more serious topic than usual, please consider reposting for reach:
My wife and I are urgently looking for a specialist in neuropediatrics or a similar field for our autistic child with a diagnosed, but not further specified, movement disorder (myoclonus and/or spasms) to finally find a cause and, above all, an effective therapy. The symptoms are bothering our son ever since he’s born, now for more than nine years, seriously affecting his sleep. The usual processes and medical contact points have failed us unfortunately and he seems stuck in this condition.
We’re based in Berlin, Germany but really any contact with a specialist who would be willing to take on this case we’d be grateful for!
To reach use you can DM me or contact us via Email at unclear.condition@gmail.com
We're still looking for submissions for German OWASP Day in Düsseldorf. The event is on the 26th of November and the CfP closes this week. https://god.owasp.de/2025/en/cfp.html :)
https://scrapco.de/dataslate/phrack/
(Will probably update when 72 comes out)
hey guys isn't it soo annoying when you're using an encrypted messaging app and it tells you "could not decrypt" haha
good news: we're working hard on making this illegal. in a way
Ever wanted to do practical security research on platforms like iOS and Android? Obsessed with digging through system internals, tearing apart proprietary firmware and hardware or breaking down wireless protocols? Maybe you've spent weekends battling in CTFs?
✨📱 🐞💥 🔬 🛰️
I'm growing my team at Hasso Plattner Institute and am looking for a PhD student or Postdoc. It's a full-time, paid position in a supportive academic environment with a focus on impactful, real-world systems security research.
Really a huge honor for me to be invited to give a keynote at NULLCON Berlin in September.
Given my recent work focus at GitLab I'll share my thoughts around LLMs. Make sure to bring some popcorn!
Ok for some reason when I mentioned non-human identities and tracking them, a number of people assumed aliens or something, or just AI agents. What I am looking for are some insights into authentication actions on computer systems - using tokens, APIs, stored secrets, and so on - where a human is not directly involved in the interaction. Yes, AI could be involved, think MCP especially. I know there are tools out there to manage this, just wondering. Think using Okta SSO etc but not human users at all. Thoughts? Opinions? To me this is the next step in zero trust, in that one should have the same principles in place between any and all systems be they human or automated in that are they who or what they claim to be and are they authorized to do go forward and do what they are trying to do. #infosec #security #zerotrust
I wrote a short rant about what irks me when people anthropomorphize LLMs:
https://addxorrol.blogspot.com/2025/07/a-non-anthropomorphized-view-of-llms.html




