Johan Carlsson (@joaxcar) 's Twitter Profile
Johan Carlsson

@joaxcar

Father and full time bug hunter 🐞 currently on joaxcar.bsky.social

ID: 1478102382911311872

linkhttps://joaxcar.bsky.social calendar_today03-01-2022 20:35:31

1,1K Tweet

5,5K Followers

178 Following

Johan Carlsson (@joaxcar) 's Twitter Profile Photo

Life doing deep dive: Monday->Thursday nothing->Friday a nice finding->Next week report->in 2 weeks triage->Sometime around 3 months from now payout No need to rush report as there is 0% chance of duplicate. Lets just leave the bug there and take a weekend with family

Kévin GERVOT (Mizu) (@kevin_mizu) 's Twitter Profile Photo

I was really surprised to see that the Cache API is exposed on window, allowing a simple XSS to hijack a service worker and achieve persistent XSS on most pages of a vulnerable website! It might not be a new, but I feel like it is an incredible XSS leveraging gadget :D

I was really surprised to see that the Cache API is exposed on window, allowing a simple XSS to hijack a service worker and achieve persistent XSS on most pages of a vulnerable website!

It might not be a new, but I feel like it is an incredible XSS leveraging gadget :D
STÖK ✌️ (@stokfredrik) 's Twitter Profile Photo

Ben Sadeghipour The most valuable thing iv learned that reaches way beyond bounties is expectations management! its never personal. If a report gets valued in a different way than you wanted, or the triager dont understand the impact. work on your soft skills. i know it sounds off, but being

Johan Carlsson (@joaxcar) 's Twitter Profile Photo

An interesting take on the behavior of SAAS companies to put security features in paid plans by Rasmus Holm. With an accompanying "name and shame" list

Johan Carlsson (@joaxcar) 's Twitter Profile Photo

I have been doing some JS challenges over on Bluesky. Traction is a bit harder to achieve, but I will stay true to only posting new stuff there for now. If you are in to JS quirks it could be worth jumping over to have a look, also a small writeup bsky.app/profile/joaxca…

Bug Bounty Reports Explained (@gregxsunday) 's Twitter Profile Photo

SSRFs can be tough to make critical without metadata, especially against a target like GitLab that strengthens its infra with every SSRF. Yet Johan Carlsson broke through with the first critical SSRF on GitLab since 2020. Enjoy our explanation from Sweden🇸🇪🔥 youtu.be/YQ5ixykKnyY

Johan Carlsson (@joaxcar) 's Twitter Profile Photo

How hard can it be to give me my data... I am on a slow move to remove my account from here. I just need Twitter to give me my zip file, and then I am off Feel free to follow me on joaxcar.bsky.social if you want to keep in touch! 👋