Forbidden403

13 posts

Forbidden403

Forbidden403

@40rbidd3n

HTTP/2 403 Forbidden

localhost Katılım Ağustos 2022
173 Takip Edilen42 Takipçiler
Forbidden403 retweetledi
James Kettle
James Kettle@albinowax·
I've just submitted my latest research to Black Hat USA! This one has been cooking since last June, can't wait to share it with the world... in fact I'm quite excited just to see the community reaction to the title reveal.
James Kettle tweet media
English
18
22
396
15.2K
Forbidden403 retweetledi
Jenish Sojitra
Jenish Sojitra@_jensec·
✨ Launching Clawned.io - free, community, no signup Stop blindly installing OpenClaw skills like Maniac. My friend mass-installed OpenClaw skills for a client project last month. Two days later his AWS bill exploded. A skill that looked totally legit was quietly stealing his credentials the whole time. Together we built Clawned Paste any skill → scanned against 60+ threat patterns in under 2 seconds. 6,500+ skills scanned so far. 1 in 5 flagged something. Stop trusting SKILL.md files blindly.
Jenish Sojitra tweet media
English
6
31
142
10K
Forbidden403 retweetledi
zhero;
zhero;@zhero___·
second research on Astro, a shorter paper than usual, which led to CVE-2025-64764 (w/ @inzo____): Unlocking Reflected XSS in the Astro framework zhero-web-sec.github.io/research-and-t… all applications using the Server Island feature are vulnerable
zhero; tweet media
zhero;@zhero___

release of our new paper (w/ @inzo____) which resulted in CVE-2025-64525: Astro framework and standards weaponization from path-based middleware protection bypass to potential SSRF & XSS + full bypass of CVE-2025-61925 on @astrodotbuild zhero-web-sec.github.io/research-and-t…

English
6
39
299
20.5K
chux
chux@chux13786509·
@40rbidd3n Great writeup! 💪 You found the good parts and solved it in the best way
English
1
0
2
323
Forbidden403 retweetledi
Jenish Sojitra
Jenish Sojitra@_jensec·
Is most Pentest companies are scam? Just saw a $30k Pentest report with 8 informative findings and only valid findings were missing cookie flags, rate limit on apply account and origin check.
Max Yaremchuk@0xw2w

@_jensec My go-to program pays hefty sums for the yearly security assessment by an elite pentest team, and they always file informatives in the pentest report, while I find serious bugs in the same spot. I wish the team had given me the source code under nda and pentest right instead..

English
27
13
270
38K
Forbidden403
Forbidden403@40rbidd3n·
Just got a bounty from @Apple for reporting a security vulnerability Grateful to be recognized through the Apple Security Bounty program #BugBounty #Apple
Forbidden403 tweet media
English
0
0
6
58
Forbidden403
Forbidden403@40rbidd3n·
@daoud_youssef جربتها فكرة جميلة ان تعمل فقط border كنوع من alert غير مزعج لكن مرات تطلع false positive حتى على توتير بسبب head method ولانه في 403 responses لايكون x-frame-options لذا اضفت هذا condition if (client.status!==403 && upper.includes("X-FRAME-OPTIONS")!==true) يجب التحقق حتى من csp
0
0
0
12
🇪🇨🍫
🇪🇨🍫@bxmbn·
Best Triagers in Hackerone Caesar Carlos Alexander Juan Moe Decimo
Español
19
11
184
19.2K