Profile for joern
About joern
Fields
- Website
- https://0day.click
- Threema
- https://threema.id/K8J68WTX
Bio
Your mom's favorite hacker!
My other account is @joernchen
- Joined
- Posts
- 708
- Followed by
- 1134
- Following
- 263
Stats
Recent public posts
exclude boostsSend memes my way please!
Niemand: ...
Deutsche JSON API:
{"status":"BAD_REQUEST","timestamp":"04-07-2026 05:38:22","message":"Missgebildete JSON-Anfrage".....
Oh more #fedijobs at Mozilla
Senior Security Engineer (Add-ons) (https://www.mozilla.org/en-US/careers/position/gh/7583571/). This involves building code-review / malware detection pipelines for addons.mozilla.org - really cool team. The same team is also looking for an engineer to implement extension APIs within Firefox, a Senior Platform Engineer (https://www.mozilla.org/en-US/careers/position/gh/7921750/).
Reminder we're active looking for candidates from diverse backgrounds and with perspectives different from our own. Questions? Just ask me :)
Re: https://infosec.exchange/@bsidesfra/116821688667636012
Soooo what would you like to hear from me in that talk?
Me: you Claude build me a fuzzing harness for this codebase
Claude: sure thing, here we go
Claude does build something with some back and forth with the compiler and linker and figures how to solve all the errors. 
Claude: Now let me do a clean build….
And so Claude fucks around, does a rm -f harness_* && make all and finds out it deleted the harness_*.c files as well.
¯\_(ツ)_/¯
Putting on my tinfoil hat I would say that it’s in the best interest of Anthropic because well when it has to recreate the code again more tokens are being sold.
Yeah, so… @joern is doing the keynote.
Just some random guy who’s been in the hacker scene for decades. Nothing special. Get ready for a totally average talk!
Later today (17:00 CEST) I’ll do a public talk on browser security, hosted by calif.io. Livestream: https://youtube.com/live/iZE_iHcv7_0?feature=share There will also be a recording :)
Hey, followers at #OWASP AppSec Vienna, come see my talk about browser-based XSS protections.
I will talk about Content Security Policy, Trusted Types and the Sanitizer API at 3:30pm in Hall G1.
@christopherkunz @janl Die Lösung liegt natürlich auf der Hand. Weniger updaten. 🫣
How do we know that we detect what we intend to detect? There are quite a few answers to that question, regrettably also along the lines of “we’ve implemented the detection, d’oh!”.
In the last two years we have been (and continue to be) busy with improving efficiency and effectiveness in detection engineering. The traditional manual approach clearly doesn’t cut it in a large heterogeneous IT landscapes of today, where security monitoring makes use of more than one or two technologies to gain visibility in a variety of system contexts. We thus quickly moved towards Detection as Code (DaC). The question of how a CI/CD pipeline in this context would look like then swiftly confronted us with the question of testability of detection mechanisms, which led to the question of how to automate tests. Having solved that, we arrived at: “if we agree that we want to verify detection effectiveness anyways, why don’t we define a test for a potential attacker action first, if and only accept detections for that specific vector, if they pass the test?“
Adapting from Kent Beck‘s concept of Test-Driven Development (TDD) in software engineering, we refer to our approach as Test-Driven Detection Engineering (TDDE).
We’ve written up the what and how in a short paper together with @seecurity, which we decided to submit to DIMVA as a mere poster, as all of that is WIP. We‘re happy that our submission has been accepted and I’m looking forward to discuss the approach with attendees and fellow practitioners.
Find a preprint of the short-paper here: https://tilmanfrosch.de/dl/preprint/Test_Driven_Detection_Engineering.pdf
*Studentische Tätigkeit bei Mozilla / Firefox Security*
Momentan suche ich ein/e Werkstudent/in für mein Team bei Mozilla im Bereich Firefox Application Security. Die Stelle richtet sich nicht nur an Studierende mit Security-Vorerfahrung. Als Anforderung gilt, dass Bewerber/innen in Deutschland an einer Universität eingeschrieben sind.
Die Stelle richtet sich nicht nur an Studierende mit Security-Vorerfahrung. Siehe Stellenausschreibung hier https://www.mozilla.org/en-US/careers/position/gh/7998284/
*Student Worker Position in the Mozilla Firefox Application Security Team*
I'm hiring for a part-time student role in Mozilla's Firefox Application Security team in Berlin/Germany (remote possible). We are trying to reach students from a broad range of backgrounds, not only people who already see themselves as "security people". It is required that applicants are enrolled in a university in Germany.
📣 Meine Firma Friday Deployments stellt ein
Ich suche die erste Person für mein Team: einen DevOps-Engineer (m/w/d), remote in Deutschland, Vollzeit/Lifestyle-Teilzeit.
🎯 Fokus: GitLab (inkl. Enterprise-Features), Schulungen, Consulting
💸 Gehalt: bis zu 50k Fix + Gewinn- & Umsatzbeteiligung (nach oben theoretisch offen), flexibler Urlaub, Hardware nach Wahl, kein Micromanagement.
Mehr hier: https://friday-deployments.com/karriere
The S in interoperability (https://frederikbraun.de/the-s-in-interoperability.html): A blog post about standards, their proliferation and the issues that arive over time.
https://github.com/v-p-b/von-neumann
Special thanks to @buherator, best sticker I had in a while. 😍😍😍
https://badhost.org it's really bad. :P
I miss shitposting :(
