hakim

275 posts

hakim banner
hakim

hakim

@hakivvi

web pentesting and low level stuff.

Katılım Haziran 2020
324 Takip Edilen469 Takipçiler
hakim retweetledi
m411k
m411k@m411k_·
Did you know that running Chromium with these two flags --disable-web-security & --single-process ANY website can access your local files. mwlik.github.io/2025-08-11-rea…
English
1
4
30
2.5K
hakim retweetledi
Eduardo Vela
Eduardo Vela@sirdarckcat·
I am actually very interested in puzzle design! I spent some time a few years ago working on CTF.guide which (I hoped) would help CTF authors write non-guessy challenges. So I decided to make a "exploratory" style challenge (a collection of a few easy problems) 7/🧵
English
1
3
21
2.3K
hakim retweetledi
m411k
m411k@m411k_·
So this happened a couple of months ago, but we reported an account takeover - in a multimillion users entertainment platform - that earned us $4,500 (Collaborated with @Mr_nyly & @S0nG0ku_H). since it's a private program, I can't disclose a thing, but here are some takeaways 👇
m411k tweet media
English
3
5
22
3.2K
hakim retweetledi
shubs
shubs@infosec_au·
IP whitelisting is fundamentally broken. At @assetnote, we've successfully bypassed network controls by routing traffic through a specific location (cloud provider, geo-location). Today, we're releasing Newtowner, to help test for this issue: github.com/assetnote/newt…
English
16
264
996
57.4K
hakim retweetledi
SinSinology
SinSinology@SinSinology·
Launching a student-only free workshop: ".NET Exploitation Basics" 🪲 If you're a student (or know one), let's write some deserialization exploits, Manchester, July 12. 10 seats. summoning.team/free-training-…
SinSinology tweet media
English
1
24
125
31.9K
hakim
hakim@hakivvi·
@S1r1u5_ spot on! makes it pretty easy to quickly test a wild idea in the most obscure programming language.
English
0
0
0
111
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
man, i’m genuinely grateful for GPTs. they've amplified the way I think by 10x, my thoughts are generally bottlenecked by language, but these models help me articulate ideas so much more clearly.
English
2
0
23
1.7K
hakim retweetledi
@securitymb@infosec.exchange
@[email protected]@SecurityMB·
🔥 A new (more difficult) era for mXSS will come soon! If nothing breaks, Chromium will start escaping "<" and ">" in attributes starting with M138. See chromestatus.com/feature/626498… for details.
English
2
17
89
9.8K
hakim retweetledi
James Kettle
James Kettle@albinowax·
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame", at #BHUSA! This is going to be epic, check out the abstract for a teaser ↓↓↓
James Kettle tweet media
English
29
102
617
87.3K
hakim retweetledi
RET2 Systems
RET2 Systems@ret2systems·
New blogpost! Want to see how we exploited @Synology network-attached-storage devices at Pwn2Own Ireland? RCE to root via out-of-bounds NULL-byte writes, click the embed for a fun little writeup of CVE-2024-10442 🔎🎉 blog.ret2.io/2025/04/23/pwn…
English
1
70
273
17.5K
hakim retweetledi
alphaXiv
alphaXiv@askalphaxiv·
Introducing Deep Research for arXiv Ask questions like 'What are the latest breakthroughs in RL fine-tuning?' and get comprehensive lit reviews with trending papers automatically included Turn hours of literature searches into seconds with AI-powered research context ⚡
English
45
543
3K
372.4K
hakim
hakim@hakivvi·
Just finished my writeup about CVE-2025-23369, an interesting SAML authentication bypass on GitHub Enterprise Server I reported last year. you can read about it here: repzret.blogspot.com/2025/02/abusin…
English
9
92
453
41.1K
hakim
hakim@hakivvi·
I have posted a writeup for a challenge I authored recently that exploits Django's flatpages, read it here: github.com/hakivvi/CTF-Wr…
English
0
1
1
594