Sign in

Antoine Roly

@aroly.bsky.social
280 followers 851 following 106 posts

Hacker, Bug Bounty Hunter, Pentester,... From Namur, BE.

PostsRepliesMedia
Reposted by Antoine Roly
James Kettle @jameskettle.com · 07/08/2026
90 minutes till "Can AI do novel security research? Meet the HTTP Terminator" kicks off at #DEFCON main stage 3! Watch the live-stream here at 1200 PDT www.youtube.com/watch?v=9go8...
youtube.com
DEFCON 34: Track 3 Talks
YouTube video by DEFCONConference
092
Antoine Roly @aroly.bsky.social · 19/05/2026
This looks so cool! Congrats!
010
Reposted by Antoine Roly
James Kettle @jameskettle.com · 14/04/2026
I'm thrilled to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" will premiere at Black Hat USA! Check out the abstract: blackhat.com/us-26/briefi...
0135
Reposted by Antoine Roly
Samir Daoulette @samirdao.eurosky.social · 18/02/2026
blog.mondediplo.net/les-collabor...
528662
Reposted by Antoine Roly
Mark Lemley @marklemley.bsky.social · 09/01/2026
429247518953
Antoine Roly @aroly.bsky.social · 05/12/2025
C'est être parent, nuance ;)
010
Reposted by Antoine Roly
harisec @harisec.bsky.social · 03/12/2025
I wrote a blog post about how I use Claude Code (and other models) in my work: invicti.com/blog/securit...
invicti.com
Security Research in the Age of AI Tools
Learn how AI tools can support security researchers in investigating vulnerabilities and designing security checks to detect them.
073
Antoine Roly @aroly.bsky.social · 18/11/2025
Yeah it's totally understandable of course. Keep up the good work, can't wait to read your next blog post :)
010
Antoine Roly @aroly.bsky.social · 18/11/2025
Trailer ? Range ? Im really curious :)
100
Reposted by Antoine Roly
Electronic Frontier Foundation @eff.org · 29/10/2025
“We should have banned government use of face recognition when we had the chance because it is dangerous, invasive, and an inherent threat to civil liberties,” EFF’s @MGuariglia.bsky.social told @404Media.co. www.404media.co/ice-and-cbp...
404media.co
ICE and CBP Agents Are Scanning Peoples’ Faces on the Street To Verify Citizenship
Videos on social media show officers from ICE and CBP using facial recognition technology on people in the field. One expert described the practice as “pure dystopian creep.”
7297119
Reposted by Antoine Roly
C Ce Soir @ccesoir.bsky.social · 21/10/2025
« On est en train de discuter des livres que va lire Nicolas Sarkozy en prison ? Alors qu'il a été condamné pour "association de malfaiteurs". » @fabricearfi.bsky.social Journaliste d’investigation La suite : ⏰ 22h50 sur france·tv ➡️https://bit.ly/SarkozyEnPrisonHonneurDeshonneur 🎧en podcast
8124641156
Antoine Roly @aroly.bsky.social · 21/10/2025
🤣🤣🤣
010
Reposted by Antoine Roly
d4d @zakfedotkin.bsky.social · 07/10/2025
I’m excited to announce that I’ll be presenting The Fragile Lock: Novel Bypasses for SAML Authentication at Black Hat Europe! In this talk, I’ll show how I was able to continuously bypass security patches to achieve complete auth bypass for major libraries. #BHEU @blackhatevents.bsky.social
0266
Reposted by Antoine Roly
Julien Briault 🩷💿💜 @juhnny5.bsky.social · 06/10/2025
Je lance une bouteille à la mer ... Les @restosducoeur 💞cherchent beaucoup d’ordinateurs portables et tiny (Linux friendly 🐧). Si votre entreprise a du stock dormant ou autre, ça nous aiderait beaucoup ! Repost apprécié :)🫶🏻
16160372
Reposted by Antoine Roly
Mastering Burp Suite @mastering-burp.agarri.fr · 01/10/2025
In case you missed it, AWS updated its policy about pentesting, and "Amazon API Gateway" (used by the extension "IP Rotate") isn't allowed anymore aws.amazon.com/fr/security/...
aws.amazon.com
Penetration Testing
Request a penetration test for your AWS cloud infrastructure here.
122
Antoine Roly @aroly.bsky.social · 26/09/2025
Nice one ! #lichess #chess @lichess.org
020
Reposted by Antoine Roly
CALL TO ACTIVISM @calltoactivism.bsky.social · 19/09/2025
🚨NEW: "The Late Show with Stephen Colbert" just dropped its first response to ABC, FCC chair, and Disney firing Jimmy Kimmel. Trump ain't sleeping tonight. 🤣 This is a must-watch. 🔥
15457752754
Reposted by Antoine Roly
d4d @zakfedotkin.bsky.social · 03/09/2025
We've just published a novel technique to bypass the __Host and __Secure cookie flags, to achieve maximum impact for your cookie injection findings: portswigger.net/research/coo...
portswigger.net
Cookie Chaos: How to bypass __Host and __Secure cookie prefixes
Browsers added cookie prefixes to protect your sessions and stop attackers from setting harmful cookies. In this post, you’ll see how to bypass cookie defenses using discrepancies in browser and serve
11214
Antoine Roly @aroly.bsky.social · 21/08/2025
media.tenor.com
a man in a cowboy hat says you can do it in front of a crowd of people
ALT: a man in a cowboy hat says you can do it in front of a crowd of people
010
Antoine Roly @aroly.bsky.social · 18/08/2025
1st time I start Burp to do bug bounty since the begining of June. Let's see if I still enjoy it or if I need more time to get back at it...
030
Antoine Roly @aroly.bsky.social · 08/08/2025
It's probably a cool research topic then 🙂
100
Antoine Roly @aroly.bsky.social · 08/08/2025
Some good collaborations on the way? 🙂
110
Reposted by Antoine Roly
James Kettle @jameskettle.com · 11/07/2025
How to make $$$ from request smuggling Step 1) Pick the right target:
2292
Antoine Roly @aroly.bsky.social · 25/06/2025
Euro de basket : les Belgian Cats brillent face à l’Allemagne et filent en demi-finale (83-59) www.lesoir.be/684043/artic... #belgiancats
lesoir.be
Euro de basket : les Belgian Cats brillent face à l’Allemagne et filent en demi-finale (83-59)
L’équipe nationale féminine belge de basket a poursuivi sur la lancée de son excellent début de tournoi ce mercredi. Une victoire qui leur permet de rejoindre l’Italie en demi-finale.
020
Reposted by Antoine Roly
Mathieu Lehot-Couette @math-lehot.bsky.social · 20/06/2025
"Ce qu’on est en train de vivre aujourd’hui, c’est les trajectoires qu’on avait imaginées il y a 20 ans. La communauté des climatologues n’est pas du tout surprise par la vague de chaleur qui arrive. Elle est effrayée." @cassouman40.bsky.social ce matin sur @franceinfo.fr #VagueDeChaleur #DontLookUp
8502350
Antoine Roly @aroly.bsky.social · 19/06/2025
This is so cool! Congrats!
020
Antoine Roly @aroly.bsky.social · 18/06/2025
Looking forward to read the write up 😉
010
Reposted by Antoine Roly
James Kettle @jameskettle.com · 10/06/2025
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame" is coming to #DEFCON33! This talk will feature multiple new classes of desync attack, mass exploitation spanning multiple CDNs, and over $200k in bug bounties. See you there!
04311
Antoine Roly @aroly.bsky.social · 31/05/2025
Mais putain 🤦 Enfin, au moins on sait pour qui ils roulent...
030
Antoine Roly @aroly.bsky.social · 30/05/2025
Bye bye full time bug bounty hunting. It's been a hell of a ride, but it's time to move on...
130
Antoine Roly @aroly.bsky.social · 30/05/2025
media.tenor.com
a close up of a statue of yoda with the words `` thank you wise one '' written below him .
ALT: a close up of a statue of yoda with the words `` thank you wise one '' written below him .
000
Antoine Roly @aroly.bsky.social · 30/05/2025
And that would explain why the desync is so rare ? Or why it happens only in one way ? I'm not sure to get your point here, sorry.
100
Reposted by Antoine Roly
Nicolas Grégoire @agarri.fr · 30/05/2025
AppSec Ezine - 589th edition #AppSec #Security pathonproject.com/zb/?33afd768...
pathonproject.com
AppSec Ezine
055
Antoine Roly @aroly.bsky.social · 30/05/2025
And the requests I need to send to trigger the desync are reaaaaaaaaally weird, I'm really wondering what happens in the backend :)
010
Antoine Roly @aroly.bsky.social · 30/05/2025
The single packet attack does not seem to work. With Turbo Intruder and ffuf running (from another IP) I sometimes see one poisoned response received by ffuf, but it never happens in the other way around.
200
Antoine Roly @aroly.bsky.social · 30/05/2025
Weird, I'm able to poison the queue and send other people responses to my requests (although it requires a lot of requests to be sent. It does not happen often at all). But so far I can't get other people responses.
200
Antoine Roly @aroly.bsky.social · 28/05/2025
Impressive, congrats ! :)
010
Reposted by Antoine Roly
d4d @zakfedotkin.bsky.social · 28/05/2025
Active Scan++ just got sharper - we’ve added new checks for OS command injection, powered by our latest ASCII Control Characters research. Install via Extensions -> BApp Store
1106
Antoine Roly @aroly.bsky.social · 28/05/2025
Thanks for the tip ! I'm slowly making progress. For now I can redirect users to arbitrary URLs by poisoning the queue like you showed in your paper. Stealing other people's responses would be much cooler though :)
120
Antoine Roly @aroly.bsky.social · 28/05/2025
That, or localhost or admin interface on the backend.
010
Antoine Roly @aroly.bsky.social · 28/05/2025
Yep I'm able to cause a desync on another target vulnerable to the same kind of thing. But I'm struggling to show "real" impact, for now I can only send back harmless responses. I only have access to a couple of endpoints because I don't have creds.
100
Antoine Roly @aroly.bsky.social · 28/05/2025
And regarding the exploitation, I'm re-reading the Portswigger papers to see what I can do. One thing is I can hit the backend with a different Host header, which is normally not possible at all. I can also cause desync on another target with the same technique.
100
Antoine Roly @aroly.bsky.social · 28/05/2025
Request splitting is actually not that uncommon. I found it a couple of times but the exploitation is sometimes tricky. The best one I found was this one: bsky.app/profile/arol... I was able to serve my own content on some website due to CRLF injection and a really weird setup
120
Antoine Roly @aroly.bsky.social · 28/05/2025
No clue if this will be exploitable, but it's at least interesting: when I add an incorrect "X-Forwarded-Port" header using HTTP Request Splitting (CRLF injection with Nginx proxy), I trigger a HTTP 400 and I can then tunnel other HTTP1 requests to the backend. Poke @t0xodile.com for the tunneling
250
Antoine Roly @aroly.bsky.social · 27/05/2025
I often end up testing weird things, but my current test is so weird that @burpsuite.bsky.social can't even handle in propery if I use the Repeater custom action 😅
010
Antoine Roly @aroly.bsky.social · 27/05/2025
First one on @yeswehack.bsky.social :)
030
Antoine Roly @aroly.bsky.social · 26/05/2025
It's fun, I'm currently playing with a website which has pipelining enabled, Nginx CRLF injection leading to HTTP Request splitting, which in turns causes HTTP desync. And it gets me all kind of weird responses like that, stuff being concatenated, consecutive requests with different responses...
000
Antoine Roly @aroly.bsky.social · 23/05/2025
Or pipelining, because of the incorrect header.
000
Antoine Roly @aroly.bsky.social · 23/05/2025
Smuggling?
100