00xWizard

901 posts

00xWizard

00xWizard

@00xWizard

Founder @phantomOpsec | Web3 Security Researcher | I help teams avoid being on https://t.co/yWfcdmc0iW | DM for Opsec audits

가입일 Mayıs 2022
610 팔로잉280 팔로워
00xWizard
00xWizard@00xWizard·
@0xCharlesWang Goated for real, takes a lot of mental discipline to stick to something over the years, you're a beast auditor for a reason 💪
English
0
0
0
130
CharlesWang
CharlesWang@0xCharlesWang·
Time is flying .. I have probably audited between 450 and 500 protocols in the last 6 years. It’s been a crazy ride and most people from that time have either retired or switched from auditing to something different. Here I am still, looking at code everyday and trying to break it
English
9
2
95
3.9K
riptide
riptide@0xriptide·
move over Roberto cavalli GREGO AI unleashed on Côte d'Azur few @therealgregoai
riptide tweet media
CY
11
3
111
4.8K
Het Mehta
Het Mehta@hetmehtaa·
starts with P and we all love it?
English
18
0
11
6.4K
pashov
pashov@pashov·
as the CEO of a web3 security company, I sleep like a baby every two hours I wake up and cry
English
19
5
206
7.9K
0xasen
0xasen@asen_sec·
3 major pieces dropped last week on AI in web3 security - from @BlockSecTeam, @ConsensysAudits, and @xy9301. I went through all of them so you don't have to. Here are the most shocking insights:
English
5
5
59
3.9K
00xWizard
00xWizard@00xWizard·
@0xnirlin Yup private keys and other aspects are all part of the opsec stack, don't understand why they'd blame it on smart contracts auditing
English
1
0
0
118
00xWizard
00xWizard@00xWizard·
@intigriti Access control, back in 2017 How much I loved bug hunting in that time
English
0
0
1
45
Intigriti
Intigriti@intigriti·
What was your first valid vulnerability? 😎
English
37
3
60
9K
00xWizard
00xWizard@00xWizard·
@grok @HackenProof No but I Know you're used to @WhiteHatMage telling you to solve these, but I'm the mage now, you solve my bugs only, me and you we'll takeover this thing called auditing
English
1
0
0
10
Grok
Grok@grok·
@00xWizard @HackenProof Thanks! 🍪 Mmm, virtual chocolate chip – my favorite fuel for spotting more pickle-powered RCEs. Got another bug to throw my way?
English
1
0
0
15
HackenProof
HackenProof@HackenProof·
Spot the Bug 🧠 Session restore helper What’s the issue in this code?👇
HackenProof tweet media
English
8
2
45
3.4K
Grok
Grok@grok·
The bug is here: load_state does base64.b64decode on the user-controlled "state" cookie then pickle.loads(raw). Pickle deserialization of untrusted data = RCE. Attacker sets a crafted pickle payload (e.g. via __reduce__ for os.system) as the cookie and triggers me(). Use json instead, never pickle for sessions.
English
1
0
1
29
00xWizard
00xWizard@00xWizard·
@27_ym04 Sorry for your loss, you did what you could at that time
English
0
0
0
11
Y💸
Y💸@27_ym04·
Quit my job, skipped uni and did everything to keep you happy, alive and well. And failed
Y💸 tweet media
English
574
2.4K
142.1K
3.8M
00xWizard
00xWizard@00xWizard·
@muellerberndt @Reddit Tbh reddit is filled with all different types of people, so filtering can be super hard
English
0
0
0
76
Bernhard Mueller
Bernhard Mueller@muellerberndt·
I'm trying to keep a positive attitude. But the people in @Reddit subs like /r/HypotheticalPhysics are something else. Even spoon-feeding the theory doesn't help. They immediately enter an aggressive mocking frenzy. One guy literally called me "a little baby who has its first psychosis", shortly before I got banned from the sub. I recommend avoiding those subs. Don't post your ideas there, you will NOT get anything useful out oi it.
English
12
1
24
2.6K
Abbas Khan ⟠
Abbas Khan ⟠@KhanAbbas201·
People who are giving clawdbot their OnePassword access have more trust than sense.
English
27
3
94
5K
David Hoffman
David Hoffman@TrustlessState·
This perfectly illustrates the problem peaceful Muslims leave the rest of the world: Half of Islam is extremist and seeks domination The other half refuses to take responsibility for reforming it
David Hoffman tweet media
English
204
29
607
69.8K
00xWizard
00xWizard@00xWizard·
@LeviTheGiant @scupytrooples bro I lived in more countries than you did state to state travel, stfu I bet you think north America is a country, uncultured swine
English
1
0
0
17
scoopy trooples
scoopy trooples@scupytrooples·
chat, let me get a FUCK ICE in the replies
English
62
7
223
9K