Tomer Zait

664 posts

Tomer Zait banner
Tomer Zait

Tomer Zait

@realgam3

Security Researcher at Stealth

Katılım Şubat 2017
315 Takip Edilen1.3K Takipçiler
Itay Cohen 🌱
Itay Cohen 🌱@megabeets_·
Completed all 9 challenges of #flareon12 🥳Kudos to all challenge authors - you did a great job! No doubt, Reverse Engineering is pure joy and misery. See you all next year
Itay Cohen 🌱 tweet media
English
5
2
106
6.5K
Tomer Zait
Tomer Zait@realgam3·
VRPlayground, Next-gen, Swagger-driven, polyglot labs for modern AppSec training & research. Is a new open source project by @F5 Security Research Team. github.com/f5devcentral/V…
Tomer Zait tweet media
English
1
2
5
810
Tomer Zait
Tomer Zait@realgam3·
Maybe it’s just me, but after a 12-day war with Iran, all I want is an @AdamSandler and @SachaBaronCohen movie. Watched “Don’t Mess with the Zohan” & “The Dictator” for the 99th time, now the world needs “Don’t Mess with the Zohan 2,” starring both.
English
0
0
5
297
Tomer Zait retweetledi
Jonathan Bar Or (JBO) 🇮🇱🇺🇸🇺🇦
פיד ישראל: מקומות שניתן לתרום להם בדולרים ויש להם חשבון ב benevity? 🇮🇱 אשמח אם תעזרו לי להפיץ את ההודעה
עברית
0
3
5
1.4K
Tomer Zait retweetledi
c0mr3x
c0mr3x@c0mr3x·
Get ready, hackers! OWASP Israel I’m excited to invite you to register for the AppSec-IL CTF competition🤩✨ CTF challenges built by our team at F5, just for you! 🔐💻 (F5 is also proud to support this event as a sponsor!)
English
1
4
2
349
Tomer Zait
Tomer Zait@realgam3·
@wa1tf0r_me @0x_shaq ES6+ is pretty decent 😅 You still have JavaScript voodoo magic but with async await syntax they removed the promise hell that removed the callback hell 😂 And they have classes now…
English
0
0
0
28
Tomer Zait
Tomer Zait@realgam3·
In the last INTENT CTF, we had to rate limit but faced a challenge: all participants shared the same IP address. To solve this, CTFd-JWT-Auth was born. Players visit the web URL, auto-login, and their team/user IDs are signed. Then we can decide to rate limit per team or user.
English
1
0
6
585
Tomer Zait retweetledi
faulty *ptrrr
faulty *ptrrr@0x_shaq·
Squirrel Sandbox Escape: I'm publishing my VR journal for a 1day I was curious about for years now. I have around six days of raw footage: from initial analysis all the way to PC takeover, so there should be more episodes coming soon :^) Link: youtube.com/watch?v=h__rwI…
YouTube video
YouTube
faulty *ptrrr tweet media
English
3
20
84
12.6K
Tomer Zait
Tomer Zait@realgam3·
@0x_shaq Don’t forget it’s a windows git installer 😂 The Linux one configure vim automatically and kick you
English
0
0
2
96
faulty *ptrrr
faulty *ptrrr@0x_shaq·
lol git installer is so salty
faulty *ptrrr tweet media
English
4
0
27
2.8K
Tomer Zait retweetledi
shubs
shubs@infosec_au·
My colleague @hash_kitten and I discovered a full-read SSRF vulnerability in Next.js (CVE-2024-34351). We published our research today on @assetnote's blog: assetnote.io/resources/rese…. Thank you to the Vercel team for a smooth disclosure process.
shubs tweet media
English
17
181
783
95.4K
faulty *ptrrr
faulty *ptrrr@0x_shaq·
DevOps are the biggest hackers fr
English
2
1
6
1.2K
Tomer Zait
Tomer Zait@realgam3·
Open Source January 🤣
Tomer Zait tweet media
English
0
0
4
457
Tomer Zait
Tomer Zait@realgam3·
My friend @m417z developed an incredible tool called #Windhawk. It's similar to Grease Monkey, but for the operating system. Now, you can create custom hooks for any process you desire. What did I do? I brought Linux to Windows! 😂 windhawk.net/mods/dot-hide
English
2
3
12
1.6K