Lauritz

1.6K posts

Lauritz banner
Lauritz

Lauritz

@_lauritz_

IT-Security Researcher, Pentester and Bug Hunter. Passionate about 💻, 🤽‍♂️, ⚜️, 🎸 and ⚽ (@VfLBochum1848eV ) #Kaeferjaeger + H1 Ambassador

Germany Katılım Nisan 2012
997 Takip Edilen2.1K Takipçiler
Lauritz retweetledi
pwn.ai
pwn.ai@pwn_ai·
🚨 ZERODAY: ImageMagick 🚨 Our autonomous pentester pwn.ai just dropped multiple zeroday chains in ImageMagick that achieve RCE and File Leak from a single .jpg or .pdf file, bypassing EVERY security policy (Default, Limited, AND Secure). 🤯 💥 Affects Ubuntu, Debian, WordPress & millions of servers globally. Happy Monday and Happy Hunting! 🥰 pwn.ai/blog/imagemagi…
pwn.ai tweet media
English
6
102
382
30.8K
Lauritz
Lauritz@_lauritz_·
@_ArtSec_ I am very happy with my Air 15". IMO it is a great compromise between large display, good specs (upgraded to 24GB RAM) and weight. The Neo is probably a bit too underpowered.
English
0
0
1
156
ArtSec
ArtSec@_ArtSec_·
Been thinking about getting a Macbook for travel/LHEs but I’m not sure if I need a Macbook Pro or the Air/Neo would be enough. Probably won’t be using too much heavy stuff since I hack on my tower build 99% of the time.
English
3
0
21
1.8K
Lauritz
Lauritz@_lauritz_·
@_ArtSec_ Don't blame yourself for taking a much-needed and well-deserved break in late 2025. And if something already feels off and burnout is creeping in… listen to your body.
English
1
0
2
91
Lauritz
Lauritz@_lauritz_·
@_ArtSec_ Not sure I personally agree with the "momentum" narrative. Sometimes you have a run, but IMO that never lasts forever. Recharging your batteries, on the other hand, is something you should definitely keep an eye on. Everything else is just unsustainable.
English
1
0
1
81
ArtSec
ArtSec@_ArtSec_·
I'm getting very close to a burnout currently, haven't found a bug in 4 weeks and imposter syndrome is rising quickly. I gotta find a way to break out somehow.
English
20
1
140
10.5K
Lauritz
Lauritz@_lauritz_·
@MrTuxracer @Hacker0x01 @printfection Extra work for paper receipts (if any) handed out by delivery persons. Plus having to pay in cash (while the delivery person in most cases has no change). 😂
English
0
0
0
170
Lauritz
Lauritz@_lauritz_·
So: Would it be somehow possible to let the recipient opt to cover the VAT (€1,41) directly during checkout / redemption of swag links, instead of blindly sending the items as-is and letting DHL figure out taxes? 3/3
English
0
0
0
220
Lauritz
Lauritz@_lauritz_·
Why am I asking? While the VAT is not that much (€1,41), @DHLPaket is so nice to add €7,50 to each swag item received from @Hacker0x01, which is suboptimal IMO. To my understanding, this could be prevented if someone covers the extra costs for "DDP" via @printfection. 2/3
Lauritz tweet media
English
1
0
0
313
Lauritz
Lauritz@_lauritz_·
@ITSecurityguard @senorarroz Yeah, I also do not get their wording and especially marketing and timing. Weren't the first concerns regarding the TOS changes posted already early this week? Why not transparently address these first? Instead, vague marketing videos like x.com/hacker0x01/sta… are posted.
HackerOne@Hacker0x01

Point-in-time pentests can’t keep up, while fully autonomous testing creates noise. The solution? HackerOne Agentic PTaaS pairs specially trained AI agents with elite human validation to deliver results based on real-world exploitability, not theory. This 50-second video shows you how it works.

English
0
0
1
193
Lauritz retweetledi
Harley Kimball
Harley Kimball@infinitelogins·
A researcher found that the List-Unsubscribe email header, designed to help users leave mailing lists with one click, can become a stored XSS and blind SSRF gadget when webmail clients auto-render unsubscribe buttons. A single malicious email header becomes a cross-surface attack as JavaScript URIs execute when clicked in Horde Webmail (CVE-2025-68673), while server-side unsubscribe handlers in Nextcloud Mail App trigger blind SSRF to internal destinations. Full write-up by @_lauritz_ 👇 security.lauritz-holtmann.de/post/xss-ssrf-… #BugBounty
English
0
17
119
7.5K
Lauritz
Lauritz@_lauritz_·
Bug Bounty Meetup vol. 5 of the German @Hacker0x01 club will be held Feb 14th to Feb 22nd (remote). 👨‍💻 20 seats, swag, remote space for networking, a bug bounty target and lots of collaboration. RSVP now: h1.community/e/mbcd6v/
Lauritz tweet media
English
1
1
6
388
Lauritz
Lauritz@_lauritz_·
[Blog Post] Turning the List-Unsubscribe SMTP Header into an SSRF/XSS Gadget security.lauritz-holtmann.de/post/xss-ssrf-… Once again, ancient RFCs and overlooked security hot spots in specifications turned out to be worthwhile for security research. Read the spec!
English
0
36
193
8.6K
Lauritz
Lauritz@_lauritz_·
Because the ACTUAL default is: HACKING IS A CRIME, unless you've got PERMISSION TO TEST. Don't be foolish. Don't risk to go to jail folks.
English
0
0
2
202