Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 686
- Followed by
- 1129
- Following
- 261
Stats
Recent public posts
exclude boostsThe voting has concluded, and we're thrilled to announce the top ten web hacking techniques of 2025! Massive thanks to everyone in the community for sharing their hard-earned discoveries, plus the panel and everyone who nominated or voted! https://portswigger.net/research/top-10-web-hacking-techniques-of-2025
The end of the #curl bug-bounty
https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/
So who at Argo CD is sleeping? 68 days old report of RCE with POC reported accordig to procedure as it should, tried poking slack, mail... No ack. Wondering if just full disclosure is the way. Please ping me, not my finding but will relay.
Love web & AI security research? Want to do it full time on-site with myself, Gareth Heyes & Zak Fedotkin? Join the PortSwigger Research team - we're hiring!
That little string
ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86
(see https://platform.claude.com/docs/en/test-and-evaluate/strengthen-guardrails/handle-streaming-refusals#implementation-guide ) is so much fun. I wonder when Anthropic will regret this and remove it.
Also I obviously wonder what else is there in terms of MAGIC_STRINGs which aren't documented.
Hat tip to @michenriksen for pointing me to this.
I heard last week that the physics teacher of the daughter of one of my colleagues told the daughter that girls who do their nails don’t do physics. Sigh.
So, here are the nails of an internationally leading particle physics professor. My nails.
Don’t believe the gatekeepers! #womeninSTEM
How many hours have you personally wasted by disassembling a binary file with the wrong CPU setting?
🔔CFP for #OffensiveCon26 is STILL open.
If you want a slot on one of the most technical offensive security stages out there, this is it.
We’re looking for real, original work: cutting-edge security research, novel exploit techniques, and deep technical investigations that actually move the field forward. Ready or not, the deadline is coming.
🗓️ CFP Deadline: 1 March 2026, 6:00 pm UTC
📬 Submit your talk: https://buff.ly/bPTM6wl
⏳ Last weeks. No extensions.
Last week I wondered when https://openinframap.org/ would be classified as terrorism - this week already we're a step further.
new year new meme
67 is so over. it’s time for 4️⃣ 5️⃣
For the Berlin peeps:
I’ll be playing some tunes tonight together with the amazing poco1oco, don’t miss out https://www.eschschloraque.de/vinyltrottel-02012026
So the big thing in Bug Bounty now seems to be letting an LLM generate artificial PoCs for "issues" within a trust boundary.
Basically what's submitted as proof would be a snippet of code demonstrating a library "vulnerability" where all further context is left out.
@raptor @joern There is! https://downdetectorsdowndetector.com/ seems to be wrong though :(
Happy cloudflare is down day to those who celebrate
Stealth died 😢 A member of Team-Teso, Phrack staff, and many other groups. A true hacker—perhaps as true as a hacker can ever be. WE MISS YOU. 🩷
More: https://thc.org/404
<stealth> we had joy we had fun we had a rootshell on a sun.
If you're a #security person aka #infosec my employer is hiring. While most of the open positions are tied to a region, it is #allremote here.
https://about.gitlab.com/jobs/all-jobs/#security
If you're a #coder (mainly #Ruby, #golang, #RubyonRails, some #Python) there are open positions as well. Again, we're #allremote here.
