mokusou (@mokusou4) 's Twitter Profile
mokusou

@mokusou4

✝️ | 🇯🇵 | bug bounty hunter |🗣 日本語, English, Français | So Sakaguchi

ID: 1350687756515569665

linkhttps://hackerone.com/mokusou calendar_today17-01-2021 06:13:57

147 Tweet

634 Followers

169 Following

Masato Kinugawa (@kinugawamasato) 's Twitter Profile Photo

#Security_Tokyo の発表資料を公開しました。最近よく見るクライアントサイドのパストラバーサルと、いつまで経ってもよく見るpostMessage経由の脆弱性について話しました。聴いてくださった皆様ありがとうございました! speakerdeck.com/masatokinugawa…

Sonar Research (@sonar_research) 's Twitter Profile Photo

🔥Multiple XSS vulnerabilities in popular CMS Joomla! (CVE-2024-21726) 🔥 PHP bug could be used to bypass sanitization - We just disclosed the technical details behind the recent Joomla vulnerability: sonarsource.com/blog/joomla-mu…

🔥Multiple XSS vulnerabilities in popular CMS Joomla! (CVE-2024-21726) 🔥

PHP bug could be used to bypass sanitization - We just disclosed the technical details behind the recent Joomla vulnerability:

sonarsource.com/blog/joomla-mu…
Ngo Wei Lin (@creastery) 's Twitter Profile Photo

Check out my write-up on a seemingly harmless and limited send() in GitHub (CVE-2024-0200) and how it could be used to obtain environment variables from a production container and to achieve remote code execution in GitHub Enterprise Server: starlabs.sg/blog/2024/04-s…

Rebane (@rebane2001) 's Twitter Profile Photo

just finished a new blogpost on how i exploited the V8 javascript engine at a CTF! it's a beginner friendly journey from a memory corruption to a browser pwn, and features lots of cool CSS to help you understand various concepts along the way. have fun!! lyra.horse/blog/2024/05/e…

Harel (@h4r3l) 's Twitter Profile Photo

New blog! This time a high severity session takeover in Zoom worth $15,000. Read the story of how sudi , BrunoZero and I chained 2 completely useless XSS vulns to steal OAuth tokens, hijack browser permissions, and more: nokline.github.io/bugbounty/2024…

zhero; (@zhero___) 's Twitter Profile Photo

happy to release my new article entitled: Next.js and cache poisoning: a quest for the black hole zhero-web-sec.github.io/research-and-t… good reading;

happy to release my new article entitled:

Next.js and cache poisoning: a quest for the black hole

zhero-web-sec.github.io/research-and-t… 

good reading;
spaceraccoon | Eugene Lim (@spaceraccoonsec) 's Twitter Profile Photo

I love crossover bugs that go between web/mobile/native because there's so much strange interactions that occur and a lot can go wrong - this research was another result of this! spaceraccoon.dev/universal-code…

mokusou (@mokusou4) 's Twitter Profile Photo

public programとか関係なく、bug bounty激ヤバ脆弱性を無限に刺せる人々がいるようです(今日だけで3人確認) 頑張れば見つけられるんやな、と嬉しくなったため頑張ります

Adnan Khan (@adnanthekhan) 's Twitter Profile Photo

Omar Zaki aka brainded is now banned from Immunefi. Their response to a valid report was to first ignore it for months, then claim that I got access by hacking GitHub, Hetzner, or one of their employees. Then after a more overt PoC per their request they went back to ignoring it.

<a href="/ComposableFDN/">Omar Zaki aka brainded</a> is now banned from <a href="/immunefi/">Immunefi</a>. Their response to a valid report was to first ignore it for months, then claim that I got access by hacking GitHub, Hetzner, or one of their employees. Then after a more overt PoC per their request they went back to ignoring it.
Masato Kinugawa (@kinugawamasato) 's Twitter Profile Photo

Due to this change: groups.google.com/a/chromium.org… now Chrome 130 also parses non-special scheme URLs including javascript: URLs "correctly", like the attached image.

Due to this change: groups.google.com/a/chromium.org…
now Chrome 130 also parses non-special scheme URLs including javascript: URLs "correctly", like the attached image.
Rebane (@rebane2001) 's Twitter Profile Photo

new blogpost time!! this one's a fun writeup on a vulnerability chain i found across multiple google services that earned me a $4133.70 bounty lots of fun css as usual! i had to recreate a bunch of drive/docs/gmail/youtube UIs c: have fun! lyra.horse/blog/2024/09/u…

El Mehdi (@elmehdimee) 's Twitter Profile Photo

I published a blog post about two XSS vulnerabilities I found in Excalidraw that were affecting Meta. elmehdi.me/2024/10/25/xss…

Kévin GERVOT (Mizu) (@kevin_mizu) 's Twitter Profile Photo

I'm thrilled to finally share my research on HTML parsing and DOMPurify at @GreHack 2024 📜 The research article is available here: mizu.re/post/exploring… The slides are available here: slides.com/kevin-mizu/gre… 1/3

I'm thrilled to finally share my research on HTML parsing and DOMPurify at @GreHack 2024 📜

The research article is available here: mizu.re/post/exploring…
The slides are available here: slides.com/kevin-mizu/gre…

1/3
rez0 (@rez0__) 's Twitter Profile Photo

I'm a hacker and AI researcher who has reported vulnerabilities to OpenAI, Google, and others. I wrote this guide as a reference of all of the ways that you can hack AI. It has saved me hours. Bookmark this if you need a reference for what all to try (AND includes mitigations).

I'm a hacker and AI researcher who has reported vulnerabilities to OpenAI, Google, and others. I wrote this guide as a reference of all of the ways that you can hack AI. 

It has saved me hours. Bookmark this if you need a reference for what all to try (AND includes mitigations).