rayanlecat (@rayanlecat) 's Twitter Profile
rayanlecat

@rayanlecat

Pentester

ID: 891705900137893888

linkhttps://rayanle.cat calendar_today30-07-2017 17:03:48

1,1K Tweet

1,1K Followers

910 Following

PwnMe CTF 2025 (@pwnmectf) 's Twitter Profile Photo

PwnMe CTF 2025 2025 finals were intense! 12 teams from 9 countries battled it out at ecole2600 25 hardcore challenges, 9h of hacking, pizza & passion🍕⚡ 🥇Huge GG to RedRocket.Club for the 1st place! Massive shoutout to all players, speakers, and sponsors. See you in 2026!

<a href="/pwnmectf/">PwnMe CTF 2025</a> 2025 finals were intense!
12 teams from 9 countries battled it out at <a href="/ecole2600/">ecole2600</a>
25 hardcore challenges, 9h of hacking, pizza &amp; passion🍕⚡

🥇Huge GG to <a href="/redrocket_ctf/">RedRocket.Club</a> for the 1st place!

Massive shoutout to all players, speakers, and sponsors. 
See you in 2026!
quarkslab (@quarkslab) 's Twitter Profile Photo

While casually reading Moodle's code @coiffeur0x90 found a SSRF bug exploitable by any authenticated user. Fun twist? This vuln matches exactly the example Orange Tsai 🍊 presented at Black Hat 2017. Real life imitates conference slides 😅 Details here: blog.quarkslab.com/auditing-moodl…

While  casually reading Moodle's code @coiffeur0x90 found a SSRF bug exploitable by any authenticated user. 
Fun twist?  This vuln matches exactly the example <a href="/orange_8361/">Orange Tsai  🍊</a> presented at Black Hat 2017. 
Real life imitates conference slides 😅
Details here:
blog.quarkslab.com/auditing-moodl…
Worty (@_worty) 's Twitter Profile Photo

During last week, I've played FCSC2025 and managed to reach first place in the web category ! I've written two writeups this year: one about pwning a Chrome extension, and another about a PostgREST service. worty.fr/post/writeups/… worty.fr/post/writeups/… Enjoy the read !

During last week, I've played FCSC2025 and managed to reach first place in the web category !

I've written two writeups this year: one about pwning a Chrome extension, and another about a PostgREST service.

worty.fr/post/writeups/…
worty.fr/post/writeups/…

Enjoy the read !
Kévin GERVOT (Mizu) (@kevin_mizu) 's Twitter Profile Photo

The #FCSC2025 ended yesterday, and my write-ups are now available here 👇 mizu.re/post/fcsc-2025… Btw, like every year, all the challenges have also been added to hackropole.fr! 🚩 1/2

The #FCSC2025 ended yesterday, and my write-ups are now available here 👇

mizu.re/post/fcsc-2025…

Btw, like every year, all the challenges have also been added to hackropole.fr! 🚩

1/2
quarkslab (@quarkslab) 's Twitter Profile Photo

Look at those cute little blobs in your internal network. They look harmless, but how about the one carrying SOCKS? It's ProxyBlob, a reverse proxy over Azure. Check out Atsika's article on how it came to exist after an assumed breach mission ⤵️ 👉 blog.quarkslab.com/proxyblobing-i…

Look at those cute little blobs in your internal network. They look harmless, but how about the one carrying SOCKS? It's ProxyBlob, a reverse proxy over Azure.
Check out <a href="/_atsika/">Atsika</a>'s article on how it came to exist after an assumed breach mission ⤵️
👉 blog.quarkslab.com/proxyblobing-i…
Atsika (@_atsika) 's Twitter Profile Photo

ProxyBlob is alive ! We’ve open-sourced our stealthy reverse SOCKS proxy over Azure Blob Storage that can help you operate in restricted environments 🔒 🌐 github.com/quarkslab/prox… Blog post for more details right below ⬇️

quarkslab (@quarkslab) 's Twitter Profile Photo

Quarkslab was glad to sponsor the Real World Cryptography Paris Meetup 4 hosted by Ledger last night. Julio Loayza Meneses talked about crypto-condor, our open source tool to test cryptography implementations. You can learn more about it here: quarkslab.github.io/crypto-condor/…

Quarkslab was glad to sponsor the Real World Cryptography Paris Meetup 4 hosted by <a href="/Ledger/">Ledger</a> last night.
Julio Loayza Meneses talked about crypto-condor, our open source tool to test cryptography implementations.
You can learn more about it here:
quarkslab.github.io/crypto-condor/…
watchTowr (@watchtowrcyber) 's Twitter Profile Photo

Our client base has been feeding us rumours about in-the-wild exploited SonicWall SMA n-days (CVE-2023-44221, CVE-2024-38475) for a while... Given these are now CISA KEV, enjoy our now public analysis and reproduction :-) labs.watchtowr.com/sonicboom-from…

Hack'In (@_hackiin) 's Twitter Profile Photo

🎤 "How we successfully failed a Red Team ?" Un talk drôle et formateur par Rayan Bouyaiche (rayanlecat ) & Brahim El Fikhi sur leur 1ère mission Red Team : fails, réussites, intrusion physique & conseils pour les juniors en cyber. 🔥 #CTF #RedTeam #CyberSecurity

🎤 "How we successfully failed a Red Team ?"
Un talk drôle et formateur par Rayan Bouyaiche (<a href="/rayanlecat/">rayanlecat</a> ) &amp; Brahim El Fikhi sur leur 1ère mission Red Team : fails, réussites, intrusion physique &amp; conseils pour les juniors en cyber. 🔥 #CTF #RedTeam #CyberSecurity
watchTowr (@watchtowrcyber) 's Twitter Profile Photo

Back in December, we disclosed numerous vulnerabilities to SysAid (who struggle to use email, it seems..) - eventually building a full pre-auth RCE chain. Join us on yet another journey..... labs.watchtowr.com/sysowned-your-…

Off-By-One Conference (@offbyoneconf) 's Twitter Profile Photo

pappy from quarkslab, our keynote speaker marks the start of 2nd edition of Off-By-One Conference with his highly anticipated presentation 𝐒𝐩𝐲𝐰𝐚𝐫𝐞 𝐟𝐨𝐫 𝐫𝐞𝐧𝐭 & 𝐭𝐡𝐞 𝐰𝐨𝐫𝐥𝐝 𝐨𝐟 𝐨𝐟𝐟𝐞𝐧𝐬𝐢𝐯𝐞 𝐜𝐲𝐛𝐞𝐫! Off-By-One Conference go! 🚀

<a href="/fredraynal/">pappy</a> from <a href="/quarkslab/">quarkslab</a>, our keynote speaker marks the start of 2nd edition of <a href="/offbyoneconf/">Off-By-One Conference</a>  with his highly anticipated presentation 𝐒𝐩𝐲𝐰𝐚𝐫𝐞 𝐟𝐨𝐫 𝐫𝐞𝐧𝐭 &amp; 𝐭𝐡𝐞 𝐰𝐨𝐫𝐥𝐝 𝐨𝐟 𝐨𝐟𝐟𝐞𝐧𝐬𝐢𝐯𝐞 𝐜𝐲𝐛𝐞𝐫!
<a href="/offbyoneconf/">Off-By-One Conference</a>  go! 🚀
Off-By-One Conference (@offbyoneconf) 's Twitter Profile Photo

Tom Mansion from quarkslab in action! After a game of hide and seek, we now 𝐒.𝐇.𝐈.𝐄.𝐋.𝐃: 𝐒𝐜𝐮𝐝𝐨 𝐇𝐞𝐚𝐩 𝐈𝐦𝐩𝐥𝐞𝐦𝐞𝐧𝐭𝐚𝐭𝐢𝐨𝐧 𝐄𝐱𝐩𝐥𝐨𝐢𝐭𝐬, 𝐋𝐞𝐚𝐤𝐬, 𝐚𝐧𝐝 𝐃𝐞𝐟𝐞𝐧𝐬𝐞𝐬 at Off-By-One Conference 2025!

<a href="/philipp0x90/">Tom Mansion</a> from <a href="/quarkslab/">quarkslab</a>  in action! After a game of hide and seek, we now 𝐒.𝐇.𝐈.𝐄.𝐋.𝐃: 𝐒𝐜𝐮𝐝𝐨 𝐇𝐞𝐚𝐩 𝐈𝐦𝐩𝐥𝐞𝐦𝐞𝐧𝐭𝐚𝐭𝐢𝐨𝐧 𝐄𝐱𝐩𝐥𝐨𝐢𝐭𝐬, 𝐋𝐞𝐚𝐤𝐬, 𝐚𝐧𝐝 𝐃𝐞𝐟𝐞𝐧𝐬𝐞𝐬 at <a href="/offbyoneconf/">Off-By-One Conference</a>  2025!
zhero; (@zhero___) 's Twitter Profile Photo

publication of my latest modest paper; Eclipse on Next.js: Conditioned exploitation of an intended race-condition - (CVE-2025-32421) enabling a partial bypass of my previous vulnerability, CVE-2024-46982 by chaining a race-condition to a cache-poisoning zhero-web-sec.github.io/research-and-t…

publication of my latest modest paper;

Eclipse on Next.js: Conditioned exploitation of an intended race-condition - (CVE-2025-32421)

enabling a partial bypass of my previous vulnerability, CVE-2024-46982 by chaining a race-condition to a cache-poisoning

zhero-web-sec.github.io/research-and-t…
Sylvain HAJRI (@navlys__) 's Twitter Profile Photo

Attention all #OSINT enthusiasts! 🌐 Join us for an exciting event at leHACK #OsintVillage2025 in Paris on Friday, June 27th. 🗓️ We're hosting an in-person Trace Labs Search Party to support the vital mission of accelerating the reunification of missing persons. 🌍

Attention all #OSINT enthusiasts! 🌐 
Join us for an exciting event at <a href="/_leHACK_/">leHACK</a> #OsintVillage2025 in Paris on Friday, June 27th. 🗓️ 

We're hosting an in-person <a href="/TraceLabs/">Trace Labs</a> Search Party to support the vital mission of accelerating the reunification of missing persons. 🌍
Hack In Provence (@hackinprovence) 's Twitter Profile Photo

🚨 Réservez vos places pour #HackIn2025 ! 🚨 📅 14-15 juin @ Aix-en-Provence 🎤 Conférences top avec @agarri_fr, rayanlecat, @Shutdown, mpgn + surprise ! 💻 CTF nocturne avec 2000€ et plein de lots à gagner 🎁 Inscrivez-vous vite 👉 lnkd.in/eQkgD5sG

🚨 Réservez vos places pour #HackIn2025 ! 🚨

📅 14-15 juin @ Aix-en-Provence
🎤 Conférences top avec @agarri_fr, <a href="/rayanlecat/">rayanlecat</a>, @Shutdown, <a href="/mpgn_x64/">mpgn</a> + surprise !
💻 CTF nocturne avec 2000€ et plein de lots à gagner 🎁

Inscrivez-vous vite 👉 lnkd.in/eQkgD5sG
Dirk-jan (@_dirkjan) 's Twitter Profile Photo

Looking forward to returning to x33fcon with a brand new talk on bringing your own OIDC provider and play around with Entra external auth methods, federated credentials, and more!

rayanlecat (@rayanlecat) 's Twitter Profile Photo

Next week I’ll be at Hack'In giving a talk with NOODLE, and I’ve created an Active Directory lab for the CTF. If you’re interested, grab your spot ➡️ helloasso.com/associations/h…

Next week I’ll be at <a href="/_hackiin/">Hack'In</a> giving a talk with <a href="/bragames2/">NOODLE</a>, and I’ve created an Active Directory lab for the CTF. If you’re interested, grab your spot ➡️ helloasso.com/associations/h…
Jean (@jean_maes_1994) 's Twitter Profile Photo

🚀 Alpha drop: TTP.Exchange is live! A gated marketplace where vetted security researchers & red-teamers trade battle-tested TTPs that still beat modern defenses. Explore, stress-test, and send us your feedback so we can build it right. 🔐🛠️

Toffy (@toffyrak) 's Twitter Profile Photo

🔍 New research on a niche technique to abuse "GPP Local Users and Groups" to elevate privileges locally through sAMAccountName hijacking. This research comes with a new GPOHound update to detect this misconfiguration. 🔗 Read more: cogiceo.com/en/whitepaper_…

🔍 New research on a niche technique to abuse "GPP Local Users and Groups" to elevate privileges locally through sAMAccountName hijacking.

This research comes with a new GPOHound update to detect this misconfiguration.

🔗 Read more: cogiceo.com/en/whitepaper_…