Profile for joern

Display name
joernchen :cute_dumpster_fire:
Username
@joern@threatactor.club
Role
admin

About joern

Bio

Your mom's favorite hacker!

My other account is @joernchen

Stats

Joined
Posts
708
Followed by
1134
Following
263

Recent public posts

exclude boosts

LLMs now do the busywork of finding amazing vulnerabilities for everyone willing to spend the tokens.

But hacking still isn't dead:

  1. We haven't at all solved the underlying problems which come with writing and shipping code.

  2. You still need to understand what you're looking at and what you are operating.

  3. The LLM platforms themselves are a exquisite target for hacking^Wcreative use of the technology.

Now when everyone can pull a CVE or two out of thin silicon and a few kWh of electricity the art of hacking might need adopt and maybe reshape a little but at its core the mind- and skillset will stay as relevant as it always was.

In that sense: keep hacking, keep exploring, break some stuff.

joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @bagder@mastodon.social
daniel:// stenberg:// , @bagder@mastodon.social
(open profile)

If your Open Source project sees a steep increase in number of high quality security reports (mostly done with AI) right now (#curl, Linux kernel, glibc confirmed) please tell me the name of this project.

(I'd like to make a little list for my coming talk on this.)

Lands of Packets

TTL exceeded.

I would like to collect texts from the scene about FX in his memory. A collection of obituaries that will then be posted on phenoelit.de.

If anyone would like to contribute, please contact me.

Mail: joernchen@phenoelit.de
Signal: jrn.07

Due to $reasons I came across this blogpost https://www.elttam.com/blog/env/ about turning ENV variables into code execution which is nice. But the Python vector is depending on Perl, I didn't like that :P.

Digging a bit deeper in the code often helps, so it did this time:

Looking at https://github.com/python/cpython/blob/d73634935cb9ce00a57dcacbd2e56371e4c18451/Lib/webbrowser.py#L51-L52 I could simplify the payload to:

PYTHONWARNINGS='module::antigravity.'  BROWSER='sh -c id #%s' python whatever.py
joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @albinowax@infosec.exchange

That little string
ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86

(see https://platform.claude.com/docs/en/test-and-evaluate/strengthen-guardrails/handle-streaming-refusals#implementation-guide ) is so much fun. I wonder when Anthropic will regret this and remove it.

Also I obviously wonder what else is there in terms of MAGIC_STRINGs which aren't documented.

Hat tip to @michenriksen for pointing me to this.

joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @freyablekman@fediscience.org
Freya Blekman , @freyablekman@fediscience.org
(open profile)

I heard last week that the physics teacher of the daughter of one of my colleagues told the daughter that girls who do their nails don’t do physics. Sigh.

So, here are the nails of an internationally leading particle physics professor. My nails.

Don’t believe the gatekeepers! #womeninSTEM

How many hours have you personally wasted by disassembling a binary file with the wrong CPU setting?

Poll closed , 21 votes total
  • Option 1, I don’t do reversing
    28.57% , 6 votes
  • Option 2, a few
    33.33% , 7 votes
  • Option 3, a lot
    4.76% , 1 vote
  • Option 4, too much
    33.33% , 7 votes
joernchen :cute_dumpster_fire: , @joern
(open profile)
Boost of @offensivecon@mastodon.social
OffensiveCon , @offensivecon@mastodon.social
(open profile)

🔔CFP for #OffensiveCon26 is STILL open.
If you want a slot on one of the most technical offensive security stages out there, this is it.

We’re looking for real, original work: cutting-edge security research, novel exploit techniques, and deep technical investigations that actually move the field forward. Ready or not, the deadline is coming.

🗓️ CFP Deadline: 1 March 2026, 6:00 pm UTC
📬 Submit your talk: buff.ly/bPTM6wl

⏳ Last weeks. No extensions.