Maxence SCHMITT

929 posts

Maxence SCHMITT

Maxence SCHMITT

@maxenceschmitt

Senior Application Security @doyensec . I am learning new stuff everyday and I love it.Sapic

Clermont Ferrand - FRANCE Beigetreten Şubat 2010
647 Folgt582 Follower
Maxence SCHMITT retweetet
Doyensec
Doyensec@Doyensec·
🚨 Breaking Secure-Looking Cloud Architectures At #defcon Singapore Demo Labs, we'll show real security bugs involving AWS Cognito multi-SSO user pools & ELB routing paths, including a Malicious OIDC Server & the ELBaph utility! 🔗 defcon.org/html/defcon-si… #appsec #doyensec
Doyensec tweet media
English
0
5
12
674
Maxence SCHMITT retweetet
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
DOMLogger++ v1.0.9 is now out and available! 🎉 This update fixes a lot of issues, including the historical DevTools bug on Chromium 🔥 It also brings full Caido session handling, which is going to be useful in the near future! 👀 👉 github.com/kevin-mizu/dom… 1/2
Kévin GERVOT (Mizu) tweet media
English
2
28
152
7.8K
zere
zere@j_zere·
Just published my first blog post "Cache Deception + CSPT: Turning Non Impactful Findings into Account Takeover" You can read the full write-up here: zere.es/posts/cache-de…
English
26
140
584
49.1K
Maxence SCHMITT
Maxence SCHMITT@maxenceschmitt·
@xssdoctor Nice research 👍. I’m happy to know that my article was useful . Indeed, these upload bypasses an be used in many use cases.
English
1
0
3
430
xssdoctor
xssdoctor@xssdoctor·
In my scenario, I had xss but i needed to import a js file to escalate. The csp was tight, but i was able to upload pdfs to the same domain. I uploaded a pdf with my malicious js in it, and I was off to the races. Enjoy!
English
4
1
79
7.5K
xssdoctor
xssdoctor@xssdoctor·
I just found the coolest csp bypass ever! did you know that a valid pdf can ALSO be valid javascript? (details below)
English
11
121
773
59.8K
Maxence SCHMITT retweetet
xssdoctor
xssdoctor@xssdoctor·
This research is based on this article blog.doyensec.com/2025/01/09/csp… which explains that the magic bytes of a pdf (and webp) file are NOT in the beginning of the file. The article goes on to show that a valid pdf can be valid json
English
3
9
90
5.7K
Maxence SCHMITT retweetet
Doyensec
Doyensec@Doyensec·
Our @73696e65's latest research has resulted in at least 1⃣5⃣ CVEs in ksmbd🤯, including multiple use-after-frees, bounds checks, type confusion and overflows‼️ Check it out today! #ksmbd_linux_security_research_2" target="_blank" rel="nofollow noopener">doyensec.com/research.html#… #doyensec #appsec #security #linux
Doyensec tweet media
English
0
15
37
2.4K
Maxence SCHMITT retweetet
Szymon Drosdzol
Szymon Drosdzol@tell1c0·
After many late nights and busted apps as security consultant at @Doyensec , I trained my spidey senses 🕷️ to detect when an API code is practically begging for an auth vulns. Join me at #CONFidence2025 for common pitfalls, and tips for writing secure authz from the start.
Szymon Drosdzol tweet media
English
1
4
10
823
Maxence SCHMITT retweetet
Doyensec
Doyensec@Doyensec·
🚀#InQL v6.0 is here! Full Kotlin rewrite w/ improved performance & responsiveness! 🆕 Built-in GraphiQL and #GraphQL Voyager visualization regardless of the target 🆕Circular references detector 🆕Improved batch queries screen 🚀 SPEED! #doyensec #appsec github.com/doyensec/inql/…
English
0
11
40
1.7K
Maxence SCHMITT retweetet
Critical Thinking - Bug Bounty Podcast
A crazy client-side exploit chain by @busf4ctor & @xssdoctor: CSPT+JSON+SelfXSS → cookie path → XSS This bug went through CSPT abuse, hidden params, CORs bypass, and CloudFront cache poisoning. Breakdown:
English
2
12
120
6.6K
Maxence SCHMITT retweetet
Doyensec
Doyensec@Doyensec·
🥳The latest !exploitable is here! We're sharing all the joy that comes with exploiting an arbitrary file write in GitLab, while cruising the Mediterranean. 🚢 Everything from onerous configurations to spotty internet! Enjoy! #doyensec #appsec #security blog.doyensec.com/2025/03/18/exp…
Doyensec tweet media
English
0
27
115
6.9K
Maxence SCHMITT retweetet
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
Thanks to the recent @PortSwigger top 10, I finally found the motivation to finish writing the 2nd article about DOMPurify security! 😁 Before releasing it, I would like to share a small challenge 🚩 Challenge link 👇 challenges.mizu.re/xss_04.html 1/2
Kévin GERVOT (Mizu) tweet media
English
1
15
146
12K
Maxence SCHMITT retweetet
Doyensec
Doyensec@Doyensec·
🎉 PESD v2.0 - now in the @BApp_Store ! Effortlessly generate dynamic sequence diagrams directly from #BurpSuite traffic! Now you can also create your own theme, conveniently edit generated diagrams with MD syntax and much more! Install it today! 🎉 #doyensec #appsec #security
GIF
English
0
6
24
1.4K