Lupin (@0xlupin) 's Twitter Profile
Lupin

@0xlupin

Roni Carta alias Lupin. Co-Founder of Lupin & Holmes. R&D. Red Teamer. Bug Hunter. Musician 🤘

ID: 1214634513340481543

linkhttps://www.landh.tech calendar_today07-01-2020 19:47:19

3,3K Tweet

16,16K Followers

641 Following

Lupin (@0xlupin) 's Twitter Profile Photo

Hey! Just wanted to take the time to congratulate Team Spain for winning the HackerOne World Cup this year. You guys are beasts 🇪🇸🥳

Lupin (@0xlupin) 's Twitter Profile Photo

I'm starting to get some pingbacks from a User-Agent like: npm/9.2.0 node/v18.19.0 linux x64 workspaces/false Google Geminibot Coming from a Google IP and at this point I don't know what is this and where does it come from. Afaik Gemini doesn't have Code Execution outside

Lupin (@0xlupin) 's Twitter Profile Photo

Ok this is getting more and more creepy. After someone impersonating me on Instagram, someone is impersonating me on Facebook ... Just FYI: I only have Linkedin and Twitter, any other accounts are not me so please be careful

Ok this is getting more and more creepy. After someone impersonating me on Instagram, someone is impersonating me on Facebook ...

Just FYI: I only have Linkedin and Twitter, any other accounts are not me so please be careful
Lupin (@0xlupin) 's Twitter Profile Photo

I'm currently reading so much research by Nicholas Carlini on A.I Security. Been a fan of the research on "Scalable Extraction of Training Data from (Production) Language Models" and now discovering some new stuff" 🤯 nicholas.carlini.com

shubs (@infosec_au) 's Twitter Profile Photo

IP whitelisting is fundamentally broken. At Assetnote, we've successfully bypassed network controls by routing traffic through a specific location (cloud provider, geo-location). Today, we're releasing Newtowner, to help test for this issue: github.com/assetnote/newt…

shubs (@infosec_au) 's Twitter Profile Photo

I won the Most Valuable Hacker award for the Salesforce H1-6102 live hacking event in Sydney (my hometown)! I enjoyed working with some very talented hackers, including RyotaK, Geluchat, and Kévin GERVOT (Mizu). This is my third MVH award, and I'm grateful to be able to compete.

Lupin (@0xlupin) 's Twitter Profile Photo

Ran Depi against a fresh target this week: two critical Software Supply Chain bugs found and auto-exploited end to end. My only input was hitting "confirm." Payout: $29,500 😁

Adnan Khan (@adnanthekhan) 's Twitter Profile Photo

Posted this a while back but didn’t tweet it: adnanthekhan.com/posts/dependab… A new-ish variation of Actions TOCTOU for a High submission to GitHub Security #BugBounty

HackerOne (@hacker0x01) 's Twitter Profile Photo

Congrats to these award winners for their innovation, collaboration, and relentless pursuit of impact. 🔥 Most Valuable Hacker | Top Criticality, Community, & Consistency of the event >>WINNER: shubs 🕷️ Exterminator | Best/most Impactful bug of the event >>WINNERS:

Congrats to these award winners for their innovation, collaboration, and relentless pursuit of impact.

🔥 Most Valuable Hacker | Top Criticality, Community, & Consistency of the event
>>WINNER: shubs

🕷️ Exterminator | Best/most Impactful bug of the event 
>>WINNERS:
Lupin (@0xlupin) 's Twitter Profile Photo

Who thought about creating dynamic manifest file definition for dependencies, where it bases the dependency name on the env variables or the version of your programming language ??? Funny way to get Dependency Confusion in the morning haha

Lupin (@0xlupin) 's Twitter Profile Photo

With Adnan Khan we ended up finding the vulnerability we brainstormed together. Identified it on OpenSea and they awarded a $10,000 bounty ! 🔥 Hopefully we can disclose this report 😁

With <a href="/adnanthekhan/">Adnan Khan</a> we ended up finding the vulnerability we brainstormed together.

Identified it on <a href="/opensea/">OpenSea</a> and they awarded a $10,000 bounty ! 🔥

Hopefully we can disclose this report 😁