turb0

69 posts

turb0

turb0

@7urb01

CTBB Full-Time Hunters' Guild Member | JavaScript Survivor | /((de)?bu(g+)?(ing)?)?/i Bits, bytes, and bad ideas https://t.co/0iE5bU4CjX

Katılım Mart 2024
181 Takip Edilen1K Takipçiler
turb0
turb0@7urb01·
A while ago, but a pretty interesting write up on a fun Azure bug with some serious impact. Pretty interesting seeing the attempted patches and the bypasses. Research Review. youtu.be/E4tWWveYJCo
YouTube video
YouTube
Orca Security@orcasec

One attacker vector closed, addt’l hardening recommended for #SynLapse. Here’s the full technical details in our latest post. Special thanks to Orca Security Researcher @TzahPahima for this important discovery that improves cloud security! orca.security/resources/blog…

English
0
1
7
1.1K
turb0
turb0@7urb01·
If you ever have to tell me hacking bedtime stories, this is exactly the kind of tale I would want to hear. It has a lot of my favorite chain step characters. Research review. youtu.be/HQrrlf0nZAU
YouTube video
YouTube
Critical Thinking - Bug Bounty Podcast@ctbbpodcast

Running a Figma plugin is enough to land cross-platform zero-click RCE on Figma Desktop... Read the writeup on the Critical Research Lab lab.ctbb.show/research/figma… And thanks @Dav3nn for the incredible post, what an amazing chain! =)

English
1
11
68
10.7K
turb0
turb0@7urb01·
@rez0__ Haha, fortunately humans aren't tokenizable.
English
0
0
0
156
Joseph Thacker
Joseph Thacker@rez0__·
Everyone has the same number of time tokens every day. Spend them wisely.
English
6
1
77
4.4K
turb0
turb0@7urb01·
He made the windows hug and now the LLM no longer bullies him by rolling to refuse to cooperate when triage tries to reproduce the bug. Thanks doc. Healing the world one iframe at a time. Research Review. youtu.be/2ZvHGtZuWPU
YouTube video
YouTube
Starstrike AI@StarstrikeAI

This time we have a guest blog from @xssdoctor, showcasing a new technique in AI hacking to achieve more consistent exploitation. This was initially a research collision, but XSSDoctor masterfully exploited this in the wild. Link below 👇

English
1
6
21
3.4K
turb0
turb0@7urb01·
AI pentesting agent XSS findings finished in heavily charred barrels, filtering out harshness while infusing deep, toasted vanilla flavors. This research demonstrates a pattern that leads to some pretty natural and interesting conclusions. Research Review. youtu.be/Bn2UTpdYuIQ
YouTube video
YouTube
Jorian@J0R1AN

New blog post is out! A few vulnerabilities in Mailcow. A critical unauthenticated XSS, and another interesting Self-XSS escalation involving a Login CSRF with a leftover tab. Check it out: aikido.dev/blog/xss-vulne…

English
1
6
29
4K
Ciarán Cotter
Ciarán Cotter@monkehack·
I had a research collision with @xssdoctor back in October, and we're dropping the new technique on the @StarstrikeAI blog in approx ~4 hours. Stay tuned!
English
2
5
88
3.8K
turb0
turb0@7urb01·
@wunderwuzzi23 I wonder if it's conceptually similar to the purpose of the 🎭 masks from classical Greek theater, where the expressions are exaggerated so a far away audience can still make them out. I bet the exaggeration here allows for easier intent classification when later reconsumed.
English
1
0
1
56
Johann Rehberger
Johann Rehberger@wunderwuzzi23·
HUGE finding! This is GOLD! Do pentesters say that all the time, and that's why Claude keeps repeating it?! Found a new subdomain - gold Found a new query parameter- gold Found something remotely looking like a cred - gold Tasking Codex to do some recon, whatever it return is gold for Claude Claude and I should be rich by now.
English
6
2
39
7.2K
turb0
turb0@7urb01·
This writeup is crazy. Such a large build up and pushing through so many scenarios where I would have walked away multiple times over. Such a cool final payload that ends up much more concise. Research review. youtu.be/eqqNhsah6Ko
YouTube video
YouTube
sudi@sudhanshur705

Last year I found a MXSS (dream) bug in a Mail app,it involved bypassing 2 consecutive sanitizers recursive Dompurify calls plus CKEditor.Hope you will like it sudistark.github.io/2026/04/07/mxs… All thanks to @kevin_mizu for putting such great content around mxss and those bypasses🙇‍♀️

English
0
4
52
6.2K
turb0
turb0@7urb01·
@nmatt0 Shall not be infringed. Sorry. Gotta drop a switch into Sonnet 4.6 to turn it into Mythos.
English
0
0
0
364
Matt Brown
Matt Brown@nmatt0·
I thought this was America ?!?!?!?
Matt Brown tweet media
English
9
0
30
4K
turb0
turb0@7urb01·
I am an ant and this is sugar. Research review. youtu.be/zDKVLjnprnE
YouTube video
YouTube
Critical Thinking - Bug Bounty Podcast@ctbbpodcast

@xssdoctor's CSPT research covers eight frameworks: lab.ctbb.show/research/the-d… React Router's .replace(/%2F/g, "/") in matchPath has no i flag, so double-decode only works when the F in %252F is uppercase. This was reintroduced after a previous fix and is still in the codebase. Splat routes (path="files/*") match with (.*) instead of ([^\\/]+), so ../../admin works with zero encoding. Next.js uses the same await params API in page components and route handlers but they do opposite things. Page components re-encode through getParamValue(), route handlers fully decode through getRouteMatcher(). The traversal lands server-side. Ember's normalizePath() re-encodes % after decoding, which accidentally kills double-encoding. Wildcard params skip the final decodeURIComponent entirely, so they need literal ../ instead of encoded payloads. SvelteKit's param matchers reject bad values at the routing level before any load function even runs. Server load functions in +page.server.ts bypass hooks.server.ts, so auth middleware won't protect you. Nuxt's island component payload revival (revive-payload.client.js) is a stored CSPT sink. If you can poison window.__NUXT__, the key traverses the $fetch URL. (CVE-2025-59414)

English
0
10
87
15.3K
turb0
turb0@7urb01·
@dmxjon It does a lot better when it has target specific details. Feeding it details of previously discovered/disclosed bugs and looking for bypasses and variants tends to be way more fruitful than "here are the kinds of bugs I want to find, go hack this."
English
0
0
4
57
DiMaX
DiMaX@dmxjon·
@7urb01 Can you share which prompt we should use to get the best result from claude code?
English
1
0
1
61