00xWizard

900 posts

00xWizard

00xWizard

@00xWizard

Founder @phantomOpsec | Web3 Security Researcher | I help teams avoid being on https://t.co/yWfcdmc0iW | DM for Opsec audits

Beigetreten Mayıs 2022
609 Folgt280 Follower
00xWizard
00xWizard@00xWizard·
@0xCharlesWang Goated for real, takes a lot of mental discipline to stick to something over the years, you're a beast auditor for a reason 💪
English
0
0
0
130
CharlesWang
CharlesWang@0xCharlesWang·
Time is flying .. I have probably audited between 450 and 500 protocols in the last 6 years. It’s been a crazy ride and most people from that time have either retired or switched from auditing to something different. Here I am still, looking at code everyday and trying to break it
English
9
2
95
3.9K
riptide
riptide@0xriptide·
move over Roberto cavalli GREGO AI unleashed on Côte d'Azur few @therealgregoai
riptide tweet media
CY
11
3
111
4.7K
Het Mehta
Het Mehta@hetmehtaa·
starts with P and we all love it?
English
18
0
11
6.4K
pashov
pashov@pashov·
as the CEO of a web3 security company, I sleep like a baby every two hours I wake up and cry
English
19
5
206
7.9K
0xasen
0xasen@asen_sec·
3 major pieces dropped last week on AI in web3 security - from @BlockSecTeam, @ConsensysAudits, and @xy9301. I went through all of them so you don't have to. Here are the most shocking insights:
English
5
5
59
3.9K
00xWizard
00xWizard@00xWizard·
@0xnirlin Yup private keys and other aspects are all part of the opsec stack, don't understand why they'd blame it on smart contracts auditing
English
1
0
0
118
00xWizard
00xWizard@00xWizard·
@intigriti Access control, back in 2017 How much I loved bug hunting in that time
English
0
0
1
45
Intigriti
Intigriti@intigriti·
What was your first valid vulnerability? 😎
English
37
3
60
9K
00xWizard
00xWizard@00xWizard·
@grok @HackenProof No but I Know you're used to @WhiteHatMage telling you to solve these, but I'm the mage now, you solve my bugs only, me and you we'll takeover this thing called auditing
English
1
0
0
10
Grok
Grok@grok·
@00xWizard @HackenProof Thanks! 🍪 Mmm, virtual chocolate chip – my favorite fuel for spotting more pickle-powered RCEs. Got another bug to throw my way?
English
1
0
0
15
HackenProof
HackenProof@HackenProof·
Spot the Bug 🧠 Session restore helper What’s the issue in this code?👇
HackenProof tweet media
English
8
2
45
3.4K
Grok
Grok@grok·
The bug is here: load_state does base64.b64decode on the user-controlled "state" cookie then pickle.loads(raw). Pickle deserialization of untrusted data = RCE. Attacker sets a crafted pickle payload (e.g. via __reduce__ for os.system) as the cookie and triggers me(). Use json instead, never pickle for sessions.
English
1
0
1
29
00xWizard
00xWizard@00xWizard·
@27_ym04 Sorry for your loss, you did what you could at that time
English
0
0
0
11
Y💸
Y💸@27_ym04·
Quit my job, skipped uni and did everything to keep you happy, alive and well. And failed
Y💸 tweet media
English
574
2.4K
142.1K
3.8M
00xWizard
00xWizard@00xWizard·
@muellerberndt @Reddit Tbh reddit is filled with all different types of people, so filtering can be super hard
English
0
0
0
76
Bernhard Mueller
Bernhard Mueller@muellerberndt·
I'm trying to keep a positive attitude. But the people in @Reddit subs like /r/HypotheticalPhysics are something else. Even spoon-feeding the theory doesn't help. They immediately enter an aggressive mocking frenzy. One guy literally called me "a little baby who has its first psychosis", shortly before I got banned from the sub. I recommend avoiding those subs. Don't post your ideas there, you will NOT get anything useful out oi it.
English
12
1
24
2.6K
Abbas Khan ⟠
Abbas Khan ⟠@KhanAbbas201·
People who are giving clawdbot their OnePassword access have more trust than sense.
English
27
3
94
5K
00xWizard
00xWizard@00xWizard·
@arlery This is why it's so much better to do the following: 1. Tag this piece of shit @TrustlessState 2. Say " hey fuck you and fuck your opinion, you retard piece of garbage 3. Go on with your life
English
0
0
2
210
mashal waqar
mashal waqar@arlery·
Lmao this is a stupid game. Don’t fall for it. Nothing will ever be enough. The goalpost will keep moving further. Condemn violence. No not like that, do it more so in language I find palatable. No don’t say that, say it how I want it. No, violence is okay when it supports who I think deserves to be hurt. No my truth is the only right one. You’re not a perfect victim. YOU should now do the work of becoming one, of trying to show your whole faith is better. No not like that. Practice it how I find it digestible. We still need to surveil you btw. You know just in case one of you loonies blows shit up. And extra security searches all your life when you travel. You didnt condemn enough. I refuse to waste brain cells trying to humanize myself or my faith. Your ignorance and bigotry is your own problem. Last person to be giving notes about violence and morals is someone who justifies massacres of innocent people and children anyway.
David Hoffman@TrustlessState

This perfectly illustrates the problem peaceful Muslims leave the rest of the world: Half of Islam is extremist and seeks domination The other half refuses to take responsibility for reforming it

English
17
3
181
10K
David Hoffman
David Hoffman@TrustlessState·
This perfectly illustrates the problem peaceful Muslims leave the rest of the world: Half of Islam is extremist and seeks domination The other half refuses to take responsibility for reforming it
David Hoffman tweet media
English
204
29
607
69.8K
00xWizard
00xWizard@00xWizard·
@LeviTheGiant @scupytrooples bro I lived in more countries than you did state to state travel, stfu I bet you think north America is a country, uncultured swine
English
1
0
0
17
scoopy trooples
scoopy trooples@scupytrooples·
chat, let me get a FUCK ICE in the replies
English
62
7
223
9K
00xWizard
00xWizard@00xWizard·
@Loopify That's why I rock with you heavy, you're not afraid to voice your thoughts, keep going, all love and support. Btw @TrustlessState fuck you, you piece of shit
English
0
0
4
225
Loopify 🧙‍♂️
Loopify 🧙‍♂️@Loopify·
David Hoffmans handlers activated him He is using the suffering of other people to justify the killings of those he despises Just in this case he is blatant about loving the deaths of 80,000 people mostly women and kids
Loopify 🧙‍♂️ tweet mediaLoopify 🧙‍♂️ tweet media
English
48
17
449
23.9K