Mat Rollings

125 posts

Mat Rollings banner
Mat Rollings

Mat Rollings

@stealthcopter

Bug bounty hunter, AppSec engineer and CTF player. Developer of PortDroid, deepce, Nexus Revamped and some other junk

เข้าร่วม Aralık 2009
280 กำลังติดตาม808 ผู้ติดตาม
Vitor Falcão "busfactor"
Vitor Falcão "busfactor"@busf4ctor·
ok, I need to get this off my chest. I'm hacking on this target, and I found something crazy. It should not work. The question is: WHY did the developers make CSP a feature flag you can disable???? LOL
English
5
0
59
4.2K
Mat Rollings รีทวีตแล้ว
ArtSec
ArtSec@_ArtSec_·
Thank you so much for the great feedback on the XSS-LABS! I dropped a new version that adds "completed" checks and keeps levels solved when you re-enter them. Thank you to @stealthcopter for adding Docker Support and constructive feedback on checks! artsec.me/projects
ArtSec tweet media
English
2
10
35
1.5K
Ciarán Cotter
Ciarán Cotter@monkehack·
I am conflicted between working on things that are useful for my career, and just building the dumbest shit I can think of for the hell of it
English
3
0
25
1.6K
Mat Rollings
Mat Rollings@stealthcopter·
@dropn0w @PinkDraconian It's somewhat common in app dev to have a cloud config to pull your API keys from rather than hardcoding them. Firebase Remote Config is the one I'm aware of. Also generally in mobile dev a google maps api key is tied to the app's signature. So it's less of an issue.
English
0
0
1
56
drop
drop@dropn0w·
@PinkDraconian Difficult to say. In mobile apps many API keys like those are exposed, but in more mature apps you don’t usually see the API key directly. they still use it somewhere. From a black box perspective this looks like a middleware layer, but I can’t confirm that.
English
1
0
1
428
PinkDraconian
PinkDraconian@PinkDraconian·
I still don't understand Google Maps API keys. If you're showing a map on your website, the API key is in your client-side code. An attacker can use this API key to send millions of requests and you're paying for it. There's no way to secure it?
English
282
84
3.9K
850K
Mat Rollings
Mat Rollings@stealthcopter·
That time of year again, another totally human Black Friday / Cyber Monday for PortDroid: 💸>50% off Lifetime 🔍Port Scanner for Android 👨‍💻I wrote it 🍺Share it somewhere useful and I'll buy you a drink Buy it, capitalism demands it. Or don't portdroid.net/bf-25
English
0
0
2
370
Mat Rollings
Mat Rollings@stealthcopter·
Since starting my training I've lost over 7kg, dropped 6% body fat, got 4 new Hawaiian shirts, and taken >5mins off my 5k time. Am I ready? No. But I'll get through it by thinking about the post-run takeaway and bubble bath 🛀 Last chance to donate🙏 justgiving.com/page/oh-no-25k…
English
0
0
4
548
Mat Rollings
Mat Rollings@stealthcopter·
@0xTib3rius It was before vibe-coding kicked off but I've seen SECRET_KEY="uuid" in the wild 🙃
English
1
0
2
379
Tib3rius
Tib3rius@0xTib3rius·
Been playing around with vibe-coding a little recently. I'd be willing to bet there's probably quite a few vibe-coded Flask apps running on the Internet with a secret key of "your-secret-key-here".
English
9
4
144
16.5K
Mat Rollings
Mat Rollings@stealthcopter·
@hamidonsolo Nope, this was simple regex bugs on content. Working on a blog post for it 🙂 coming soon ™
English
1
0
2
235
Mat Rollings
Mat Rollings@stealthcopter·
Last week I found two regex bugs using regex → unauth XSS → 2× $2k = $4k in bounties 🥳 If you’ve been putting it off, learn regex. Seriously. /regex\+xss/\$4k/ #BugBounty #BugBountyTips
English
3
7
104
5.7K
Mat Rollings
Mat Rollings@stealthcopter·
@AatankBadb16659 This was using regex to find overly greedy regex replacements that could be abused to get XSS
English
0
0
1
113
Pranav
Pranav@AatankBadb16659·
@stealthcopter Its awesome , So you use regex for finding xss sinks or source ?
English
1
0
1
135
Mat Rollings
Mat Rollings@stealthcopter·
@AatankBadb16659 Yeah, I'll do a blog post towards the end of the month when I've got a few more examples 🙂
English
1
0
3
302
thatchersgold
thatchersgold@carbonmanx·
@stealthcopter Yeah I am, figured it's also an excuse to see Lisbon as I've not been before! Tickets bought 👍
English
1
0
1
85
Mat Rollings
Mat Rollings@stealthcopter·
Really enjoyed these AI hacking challenges by HackAIcon, the last one had some fun little twists: hacktheagent.com #ctf
Mat Rollings tweet media
English
1
0
10
803