Ciarán Cotter

1.5K posts

Ciarán Cotter banner
Ciarán Cotter

Ciarán Cotter

@monkehack

• Irish/Japanese web/AI hacker from Cork, living in Scotland • Founder @StarstrikeAI • Researcher @ctbbpodcast • BT6 Member • Hacker Newsletter @ https://t.co/fZXECNojTz

Edinburgh, Scotland Katılım Mart 2021
608 Takip Edilen5.3K Takipçiler
Sabitlenmiş Tweet
Ciarán Cotter
Ciarán Cotter@monkehack·
Excited to launch this with @busf4ctor. We'll be posting some of our research over the next few weeks 😁 so make sure to follow. Really looking forward to seeing where this goes!
Starstrike AI@StarstrikeAI

Today, we (@busf4ctor and @monkehack), are launching Starstrike: an AI pentesting and research startup. We'll be releasing our first few research articles over the next few weeks, detailing several bugs that helped us net over $100k in total. Follow to ensure you don't miss them!

English
3
2
71
6.3K
Ciarán Cotter retweetledi
Lupin
Lupin@0xLupin·
wtf. the tanstack attack just went live. we flagged this exact chain 25 days ago. april 16. All Depi clients were alerted. if you're using @tan_stack check your manifest files right now 1.166.12, 1.166.15, 1.169.5, 1.169.8 are malicious. clean your cache. rebuild.
Lupin tweet mediaLupin tweet media
English
8
16
127
16.8K
Joseph Thacker
Joseph Thacker@rez0__·
Everyone has the same number of time tokens every day. Spend them wisely.
English
6
1
79
4.3K
Ciarán Cotter
Ciarán Cotter@monkehack·
@valent1nee It’s crazy how often ..; works lmao. Also you can combine it with secondary context so you can traverse a different server due to routing. Like /some/route/..;/manager/html or whatever. Proxies are so fun to mess with
English
1
0
1
302
Valentino Massaro
Valentino Massaro@valent1nee·
@monkehack Brought some memories back :,) If you have a reverse proxy, sometimes /..;/shell.jsp works too.
English
1
0
1
329
Ciarán Cotter
Ciarán Cotter@monkehack·
@rez0__ @xssdoctor Not to mention Waymo in some cities, we have instant video on tiny handheld devices, personal assistant AIs, a hacker is one of the most powerful jobs in the world, and our cities are dying of pollution! Woohoo! Halfway to the post-apocalypse hellscape genre
English
0
0
3
561
Joseph Thacker
Joseph Thacker@rez0__·
I was just telling @xssdoctor this: We are living in a cyberpunk future. - Our cars drive us around (we both have fsd teslas). - We use AI agents to find bugs. - We sometimes get paid in virtual currency. - We use that to buy more AI agents to find us more bugs. ENJOY IT MORE
English
8
10
128
9K
Ciarán Cotter
Ciarán Cotter@monkehack·
Shoutout to @7urb01’s channel. He’s probably one of the best client side guys in the business and you get to witness his unfiltered thought process on his channel as he reviews research and gets sidetracked. This is a MUST follow resource: @7urb0one" target="_blank" rel="nofollow noopener">youtube.com/@7urb0one
English
0
12
107
7.7K
Ciarán Cotter retweetledi
turb0
turb0@7urb01·
He made the windows hug and now the LLM no longer bullies him by rolling to refuse to cooperate when triage tries to reproduce the bug. Thanks doc. Healing the world one iframe at a time. Research Review. youtu.be/2ZvHGtZuWPU
YouTube video
YouTube
Starstrike AI@StarstrikeAI

This time we have a guest blog from @xssdoctor, showcasing a new technique in AI hacking to achieve more consistent exploitation. This was initially a research collision, but XSSDoctor masterfully exploited this in the wild. Link below 👇

English
1
6
21
3.4K
Ciarán Cotter
Ciarán Cotter@monkehack·
Unfortunately, most jurisdictions see the act of using a hardcoded API key to retrieve the data of other users as computer misuse, so more or less yes. It sucks but that's how it is. Without clear permission from the company, they can press charges for that. A lot of us are working hard to try and change that and get better laws in place for responsible disclosure but it's an ongoing process. Personally, I've done an interview with the Irish government to discuss vulnerability disclosure policy. We're all on the same side. Posting stuff like this until those laws are passed is always going to be a risk. Maybe that's a risk you're accepting but that's not my problem.
English
0
0
5
122
impulsive
impulsive@weezerOSINT·
@monkehack @4osp3l "Someday he'll fuck up and get arrested but that sure as hell isn't our problem." Arrested for what exactly? receiving a hardcoded api key on my phone?
English
1
0
0
164
Ciarán Cotter
Ciarán Cotter@monkehack·
LOL what are you talking about? I'm obviously not calling for your arrest. I hope for your sake that you don't get arrested! I'm telling you that there are companies that are much more trigger-happy with lawsuits, and that each time we disclose findings like this, it's always a risk! Look at the CTF guys in Malta who got arrested for responsible disclosure - it can happen to anyone.
English
1
0
0
169
Ciarán Cotter
Ciarán Cotter@monkehack·
I think he's been pretty reasonable in public! So we can agree to disagree there :) many of us who do this for a living actively defend hackers and the hacker cause behind the scenes. Things would be much, much worse if we didn't hack people like him defending hackers directly with the platform staff. :P
English
1
0
2
328
Krigshaw
Krigshaw@krigshaw·
I know rez0 is a good guy. I have seen a lot of what he's done and have learned from him myself. However, what's done behind the scenes is less perceived than what's done in public, and his behavior in public in front of his 71,000+ followers is naturally perceived more. And that's why I said what I said.
English
1
0
6
573
Krigshaw
Krigshaw@krigshaw·
A lot of people probably do not have the guts or balls to say this but I will say it. I have noticed that a lot of known security researchers are almost "in bed" with Hacker platforms and forget where they came from or just don't care anymore because they've already made it. The only one that I haven't seen like this is @Jhaddix. Every single time I see someone stand up for themselves against the atrocious injustices and ACTUAL unethical practices of these Hacker platforms against security researchers, I see these big names white-knighting for the platform, as if the platform isn't already a multi-million or multi-billion dollar corporation with multiple white knights on their payroll already. And it's honestly very disappointing and frustrating. People like @rez0__ and @InsiderPhD are prime examples, and should be using their platform to fight for the bug hunters, not against them. It's honestly not only incredibly disrespectful but also a massive letdown. Like, we see these people as not only peers but pillars in the community. For me personally it pains me to write this this since I followed the Critical Thinking podcast in the past, the podcast "by Hackers for Hackers" by the way, unless apparently you post about a Hacker platform hosting a corrupt program that is ghosting you and not paying you for your find. And that my friends is an example of what's become the downfall of the entire bug bounty ecosystem: say one thing, do another. Hacker platforms say they'll pay you X bounty for Y finding, and when you do the report and follow their own "good-faith" principles, they'll downplay your find, ghost your requests, and scam you of your bounty. And the same people you thought were there to defend you when you try to take a stand are actually waiting to be outraged by your stance instead, because they've "met" and "are friends" and "partied at DEFCON" with employees from these platforms 🤡. STOP defending hacker platforms and START defending the hackers, THE PRODUCT. Without us hackers these platforms would be useless.
English
9
9
62
8K
Ciarán Cotter
Ciarán Cotter@monkehack·
Who wants to meet me at Def Con sticker swap this year to get stickers of the latest infosec drama à la Jonathan Scott?
English
0
0
12
714
Ciarán Cotter
Ciarán Cotter@monkehack·
@Rhynorater He'll do it until a company comes after him with a lawsuit and then he'll realise why the rest of us who've been around for a while don't do that
English
0
0
4
308
Abdillah
Abdillah@abdilahrf·
@Rhynorater But it has been returning good, from dup, informative become bounty 2k 5k what do you think?
English
1
0
1
188