Perce

93 posts

Perce

Perce

@PerceSecu

CTF player | Bug Hunter | Ex infosec student at @EsnaBretagne

Joined Eylül 2021
325 Following439 Followers
Perce retweeted
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
I'm happy to release the first version of my DOMLogger++ plugin for @CaidoIO! 🔎 It improves the browser extension in several ways: • Persistent, per-project storage • Temporary session recording • AI support • Stack trace reconstitution • ... 👉 github.com/kevin-mizu/dom…
Kévin GERVOT (Mizu) tweet mediaKévin GERVOT (Mizu) tweet mediaKévin GERVOT (Mizu) tweet mediaKévin GERVOT (Mizu) tweet media
English
4
31
176
11.4K
Perce retweeted
Vulnotes
Vulnotes@vulnotes·
Our new website is live 🎉 Check out vulnotes.com and let us know what you think: vulnotes.com
Vulnotes tweet media
English
0
18
92
5.9K
Perce retweeted
sysxplore
sysxplore@sysxplore·
Linux running in a PDF file via a RISC-V emulator compiled to JS
sysxplore tweet media
English
70
393
3.1K
138.1K
Perce retweeted
Profundis.io
Profundis.io@profundisio·
Big update: Subdomain enumeration now uses separate quotas for each plan! This means MORE data for the same price. Plus, our free tier still lets you discover hundreds of subdomains monthly - no payment required. Check out the documentation docs.profundis.io/api/subdomain-… #bugbounty
English
2
7
27
2.2K
Perce retweeted
Noobosaurus R3x 🦖
Noobosaurus R3x 🦖@NoobosaurusR3x·
Guillaume Chouquet, fondateur et directeur de l'ESNA, viré de sa propre école par l'@Formation_bzh !!! Je suis consterné et en colère. C'est affligeant de prendre une telle décision quand on sait tout ce que le bonhomme a fait pour l'école et les alternants !
Français
14
42
102
22.8K
Perce retweeted
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
This is still v1, there's lots to improve and many gadgets to add. If you'd like to contribute or have any feedback, please don't hesitate to reach out 😁 4/4
English
2
2
9
1.8K
Perce retweeted
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
Each library page includes: * Affected versions * A short description * Root cause of the gadget * Related links * Credit to the discoverer * And even a preview button to play with the gadget live! 3/4
Kévin GERVOT (Mizu) tweet mediaKévin GERVOT (Mizu) tweet mediaKévin GERVOT (Mizu) tweet media
English
1
4
11
2.8K
Perce retweeted
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
The wiki lets you filter gadgets by browser, tags, attributes, CSP, and timing, making it as easy as possible to find interesting vectors (at least I hope so!) 🔎 2/4
Kévin GERVOT (Mizu) tweet media
English
1
2
7
1.9K
Perce retweeted
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥 The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇 gmsgadget.com 1/4
Kévin GERVOT (Mizu) tweet media
English
12
172
460
42.4K
Perce retweeted
Geluchat
Geluchat@Geluchat·
Today was my last day as a pentester at Bsecure, and it feels a bit surreal. After a three-year journey of hunting on the side, I’m finally ready to go all-in as a full-time bug bounty hunter. To celebrate this milestone, I've written an article sharing the full story. It’s a transparent look at the path that got me here: the wins, the lessons, the real financial numbers, and my honest advice for anyone considering this adventure. You can read all about my journey from pentester to full-time hunter here: gelu.chat/posts/from-pen…
Geluchat tweet media
English
29
71
372
33.9K
Perce retweeted
Sicarius
Sicarius@ElS1carius·
There we go, after 3 years of work, endless nights of dev and a truckload of coffee. We are finally releasing the biggest project we've done in our entire life. I hope you will like it !
Profundis.io@profundisio

Profundis.io is live! Quickly uncover DNS records, subdomains, hosts, and their historical data directly via your browser. No noise, just the data you need for asset discovery and security research. Explore now: profundis.io

English
9
9
66
7.4K
Perce retweeted
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
DOMLogger++ v1.0.8 is now out and available! 🎉 This update includes several UX improvements, such as syntax highlighting and new shortcuts. Major changes have been made to custom types and several annoying bugs have been fixed 🚀 👉 github.com/kevin-mizu/dom…
Kévin GERVOT (Mizu) tweet media
English
3
21
102
5.9K
Perce retweeted
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
I'm very happy to finally share the second part of my DOMPurify security research 🔥 This article mostly focuses on DOMPurify misconfigurations, especially hooks, that downgrade the sanitizer's protection (even in the latest version)! Link 👇 mizu.re/post/exploring… 1/2
English
4
102
359
36.8K
Perce
Perce@PerceSecu·
📢 SOIRÉE SOCIAL EVENT CE SOIR ! 🎉 📅 15 novembre 2024 🕘 On t’attend !
Perce tweet media
Worty@_Worty

Français
0
0
1
283
Perce retweeted
Sicarius
Sicarius@ElS1carius·
🚀 Exciting News I just released a (dirty) Chrome extension that lets you load all chunks of a React app in seconds. Perfect for finding hidden features using Chrome's inspector or parsing .map files using your browser ! github.com/ElSicarius/chu… #bugbountytips #Pentesting
Sicarius tweet mediaSicarius tweet media
English
6
54
236
18.3K
Perce retweeted
Kévin GERVOT (Mizu)
Kévin GERVOT (Mizu)@kevin_mizu·
DOMLogger++ v1.0.5 is now out and available! It comes with new features, including the ability to remove response headers, a PwnFox integration, and much more 🔥 A new config file is also available for CSPT hunting 👀 More details can be found here 👇 github.com/kevin-mizu/dom…
Kévin GERVOT (Mizu) tweet media
English
6
28
149
10.9K