Sign in

harisec

@harisec.bsky.social
2.4K followers 750 following 36 posts

Interested in web security, bug bounties, machine learning and investing. SolidGoldMagikarp

PostsRepliesMedia
harisec @harisec.bsky.social · 03/12/2025
I wrote a blog post about how I use Claude Code (and other models) in my work: invicti.com/blog/securit...
invicti.com
Security Research in the Age of AI Tools
Learn how AI tools can support security researchers in investigating vulnerabilities and designing security checks to detect them.
073
harisec @harisec.bsky.social · 06/11/2025
I generated 20k vibe-coded web applications using various models via the OpenRouter API and analyzed them for security issues. The apps are available for download if anyone wants to take a look. www.invicti.com/blog/securit...
invicti.com
Security Issues in Vibe-Coded Web Apps: Analysis, Vulnerabilities, Scanning
Learn about common security issues in AI-generated software, based on an analysis of over 20,000 vibe-coded web apps.
062
harisec @harisec.bsky.social · 24/09/2025
I wrote a blog post about enumerating and testing tool usage in web applications that use LLMs: www.invicti.com/blog/securit...
invicti.com
LLM Tool Usage Security
Learn how attackers can exploit LLM tool usage and MCP servers, why this expands the attack surface, and how automated DAST scanning strengthens LLM security in web applications.
042
harisec @harisec.bsky.social · 28/06/2025
Here are the slides from my @tumpicon.org talk: Teaching LLMs how to XSS - An introduction to fine-tuning and reinforcement learning (using your own GPU) docs.google.com/presentation...
docs.google.com
Teaching LLMs how to XSS
Teaching LLMs how to XSS An introduction to fine-tuning and reinforcement learning (using your own GPU)
0196
harisec @harisec.bsky.social · 13/01/2025
The article: www.invicti.com/blog/securit...
invicti.com
First Tokens: The Achilles’ Heel of LLMs
The Assistant Prefill feature available in many LLMs can open up models to jailbreaking, including the possibility of persistent prefills to bypass LLM safety alignments.
2111
harisec @harisec.bsky.social · 13/01/2025
I wrote an article about how it's possible to use Assistant Prefill to jailbreak LLMs (Large Language Models). Here is an example of the latest model from Microsoft (Phi-4) writing a phishing email:
141
harisec @harisec.bsky.social · 02/01/2025
My favorite talk from #38c3: From Pegasus to Predator - The evolution of Commercial Spyware on iOS - media.ccc.de/v/38c3-from-...
media.ccc.de
From Pegasus to Predator - The evolution of Commercial Spyware on iOS
My talk explores the trajectory of iOS spyware from the initial discovery of Pegasus in 2016 to the latest cases in 2024. The talk will ...
080
harisec @harisec.bsky.social · 31/12/2024
Great paper from Orange Tsai about unicode transformations: worst.fit/assets/EU-24...
worst.fit
0124
harisec @harisec.bsky.social · 20/12/2024
OpenAI o3 model just achieved unbelievable scores (75% and 87%) on ARC-AGI, the previous models made maximum 20% and humans make around 85%. arcprize.org/blog/oai-o3-...
arcprize.org
OpenAI o3 Breakthrough High Score on ARC-AGI-Pub
OpenAI o3 scores 75.7% on ARC-AGI public leaderboard.
031
harisec @harisec.bsky.social · 17/12/2024
Must read if you are interested in test-time compute: huggingface.co/spaces/Huggi...
huggingface.co
Scaling test-time compute - a Hugging Face Space by HuggingFaceH4
Discover amazing ML apps made by the community
020
harisec @harisec.bsky.social · 12/12/2024
Great read: semianalysis.com/2024/12/11/s...
semianalysis.com
Scaling Laws – O1 Pro Architecture, Reasoning Training Infrastructure, Orion and Claude 3.5 Opus “Failures”
There has been an increasing amount of fear, uncertainty and doubt (FUD) regarding AI Scaling laws. A cavalcade of part-time AI industry prognosticators have latched on to any bearish narrative the…
051
Reposted by harisec
RyotaK @ryotak.net · 07/12/2024
If you're interested in the technical details, I wrote the blog post here: flatt.tech/research/pos... For the further details, please check out the announcement from the OpenWrt team: lists.openwrt.org/pipermail/op... (2/2)
flatt.tech
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...
0178
Reposted by harisec
ϻг_ϻε @steven.srcincite.io · 06/12/2024
Here is a great follow up blog post to my blog Remote Code Execution with Spring properties written by Elliot Ward: snyk.io/articles/rem...
snyk.io
Remote Code Execution with Spring Boot 3.4.0 Properties | Snyk
this article introduces two methods for leveraging Logback configuration to achieve Remote Code Execution (RCE) in Spring Boot applications. These techniques are effective on the latest version of Spr...
0218
Reposted by harisec
renniepak @renniepak.nl · 04/12/2024
Pro tip for if you have XSS but you can only use upper case: aem1k.com/transliterat... transliterate.js by @aemkei.bsky.social works great!
aem1k.com
transliterate.js
Translate any JavaScript code to foreign writing systems. Created by Martin Kleppe aka @aemkei.
0216
harisec @harisec.bsky.social · 30/11/2024
embracethered.com/blog/posts/2...
embracethered.com
DeepSeek AI: From Prompt Injection To Account Takeover · Embrace The Red
This post discusses how I found and responsibly disclosed a Cross Site Scripting in DeepSeek and it was possible to trigger it via Prompt Injection to achieve complete account takeover. The issue was ...
0122
harisec @harisec.bsky.social · 29/11/2024
Starter packs
030
Reposted by harisec
Jeremy Howard @howard.fm · 28/11/2024
FYI, here's the entire code to create a dataset of every single bsky message in real time: ``` from atproto import * def f(m): print(m.header, parse_subscribe_repos_message()) FirehoseSubscribeReposClient().start(f) ```
1944262
harisec @harisec.bsky.social · 28/11/2024
As most people know, it's trivial to save all the bsky posts.
010
Reposted by harisec
Jeremy Howard @howard.fm · 28/11/2024
A librarian that previously worked at the British Library created a relatively small dataset of bsky posts, hundreds of times smaller than previous researchers, to help folks create toxicity filters and stuff. So people bullied him & posted death threats. He took it down. Nice one, folks.
2858258
Reposted by harisec
Simon Willison @simonwillison.net · 28/11/2024
qwq is a new openly licensed LLM from Alibaba Cloud's Qwen team. It's an attempt at the OpenAI o1 "reasoning" trick that runs on my Mac (20GB download) via Ollama... and it's pretty good! My detailed notes here: simonwillison.net/2024/Nov/27/... - here's its attempt an SVG pelican riding a bicycle.
An SVG of a pelican riding a bicycle. It's quite abstract. The bicycle is two half circles and a simple frame. The pelican is sky blue with spread wings and a curved neck leading to a small head. It has definite pelican vibes.
48010
harisec @harisec.bsky.social · 28/11/2024
Interesting, I've been playing with URLTeam as well but for other purposes, there is definitely a lot of noise. That's basically my main problem, how to filter out the noise. I did not found a solution until now.
000
harisec @harisec.bsky.social · 27/11/2024
Made a NotebookLM podcast about this, from a few .ro articles, if people are interested: notebooklm.google.com/notebook/742...
notebooklm.google.com
Sign in - Google Accounts
000
harisec @harisec.bsky.social · 27/11/2024
I'm from Romania, TikTok is hugely popular here, we have over 8.9 million TikTok user (from 19 million total population). Many influencers were paid to promote TikTok tags (like #echilibrușiverticalitate - this one received 2.4 million views) that were later used to promote Calin Georgescu.
120
harisec @harisec.bsky.social · 26/11/2024
CommonCrawl is this: commoncrawl.org - they have 17 of crawled data is one of the sources LLMs use for training. I think it's a great source for building links between links.
commoncrawl.org
Common Crawl - Open Repository of Web Crawl Data
We build and maintain an open repository of web crawl data that can be accessed and analyzed by anyone.
140
harisec @harisec.bsky.social · 26/11/2024
Build a huge database for that and use it to suggest new links based on links you already discovered. I think that has big potential. In the beggining I was thinking to finetune an LLM but I think a DB should be enough.
110
harisec @harisec.bsky.social · 26/11/2024
Thanks, that means a lot to me. About statistical data: i had a similar idea for a long time.I was thinking to read all the URLs from all the crawls available in CommonCrawl and then build a database with relations between links. If /wp-login.php is found you might try /wp-register.php, xmlrpc.php
110
harisec @harisec.bsky.social · 26/11/2024
I wrote an article about the ideas behind this tool: www.invicti.com/blog/securit... The tool: github.com/Invicti-Secu...
invicti.com
Brainstorm Tool Release: Optimizing Web Fuzzing With Local LLMs
Brainstorm is a new, smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery
050
harisec @harisec.bsky.social · 26/11/2024
I've released 'brainstorm': an alternative way to do web fuzzing combining my fav fuzzing tool 'ffuf' (from @joohoi.bsky.social )with local LLMs (via Ollama API) to generate smarter filename tests. It usually finds more endpoints with fewer requests. Added a IIS shortname support @irsdl.bsky.social
5389
Reposted by harisec
Jake Handy @jakehandy.com · 24/11/2024
Cursor, the top performing #AI IDE, launched version 0.43 today with support for 🥁… Agents! Composer can now “pick its own context, use terminal, and complete entire tasks” give it a whirl: www.cursor.com
253
harisec @harisec.bsky.social · 24/11/2024
You need some type of reasoning traces to finetune a LLM and CTF solutions are providing that.
020
harisec @harisec.bsky.social · 24/11/2024
I suspect (i might be wrong) they use flags because they are very common in ctfs and i suspect xbow was trained on ctf solutions, that's the only public source of data available at large for training, related with offensive sec. Also @moyix.net published some papers related with ctfs as well.
230
harisec @harisec.bsky.social · 24/11/2024
I'm also very impressed, there is clearly big potential here. However, I agree with Alex, it might work and scale on test websites where you KNOW there is an issue but i'm not sure at all it will scale on thousands of sites, each one having thousands of links and you have no idea if there are bugs
130
Reposted by harisec
shubs @shubs.io · 22/11/2024
Earlier this year, Assetnote's Security Research team discovered a vulnerability in Sitecore XP (CVE-2024-46938) that can lead to pre-authentication RCE. Order of operations bugs are one of my favorite types of bugs :) Write up and exploit script here: assetnote.io/resources/re...
15023
Reposted by harisec
Gynvael Coldwind @gynvael.bsky.social · 20/11/2024
We're doing a cool online talk tomorrow btw – hexarcana.ch/workshops/cv...
hexarcana.ch
CVEs of SSH
A talk about recent high-profile issues related to the SSH ecosystem.
2218
Reposted by harisec
terjanq @terjanq.me · 19/11/2024
Great article about multipart parsing. Reminds me about the bypasses I found in modsec parser medium.com/@terjanq/waf...
medium.com
WAF bypasses via 0days
based on findings from a live hacking event
1237
harisec @harisec.bsky.social · 19/11/2024
I use it a lot instead of Google.
010
Reposted by harisec
Sam Stepanyan @securestep9.bsky.social · 19/11/2024
#WAF: "When WAFs Go Awry: Common Detection & Evasion Techniques for Web Application Firewalls" - by @MDSecLabs: 👇 www.mdsec.co.uk/2024/10/when...
mdsec.co.uk
When WAFs Go Awry: Common Detection & Evasion Techniques for Web Application Firewalls - MDSec
Web Application Firewalls (WAFs) help to protect web applications by monitoring, filtering, and blocking HTTP traffic to and from a web service. However, WAFs are too often relied upon as...
162
harisec @harisec.bsky.social · 19/11/2024
For sure they are not the same technically, also DOM XSS-es are usually harder (more work required) to exploit. But if you look from the point of view of impact, they are the same. I'm not doing bounties now but remember Synack was paying more for DOM XSS. DOM XSS was $7xx and Reflected $3xx
020
harisec @harisec.bsky.social · 19/11/2024
It's usually considered same impact as a Reflected XSS?
110
Reposted by harisec
jiska @naehrdine.bsky.social · 17/11/2024
How does the new iOS inactivity reboot work? What does it protect from? I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented. naehrdine.blogspot.com/2024/11/reve...
naehrdine.blogspot.com
Reverse Engineering iOS 18 Inactivity Reboot
Wireless and firmware hacking, PhD life, Technology
12277106
Reposted by harisec
Matthew Cashew @cashewsec.bsky.social · 18/11/2024
As a pentester and security engineer, I found this talk to be very inspiring. I haven't been able to use the tool yet, but you can bet I will soon! youtu.be/bCNnloBaw_U?...
youtu.be
The Dangers of Building a Recursive Internet Scanner by Joel Moore | BSides CHS 2024
YouTube video by BSidesCHS
0144
harisec @harisec.bsky.social · 17/11/2024
This is very interesting, thank you!
010
harisec @harisec.bsky.social · 14/11/2024
xbow.com/blog/xbow-sc...
xbow.com
XBOW – How XBOW found a Scoold authentication bypass
As we shift our focus from benchmarks to real world applications, we will be sharing some of the most interesting vulnerabilities XBOW has found in real-world, open-source targets. The first of these ...
000
harisec @harisec.bsky.social · 14/11/2024
There is an up-to-date Github repo with all BB domains: github.com/arkadiyt/bou...
github.com
GitHub - arkadiyt/bounty-targets-data: This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports
This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports - arkadiyt/bounty-targets-data
010
harisec @harisec.bsky.social · 14/11/2024
You could try the Internet BB program. hackerone.com/ibb?type=team However, Spring is the most commonly used Java framework so it's used a lot in BB programs. I would just scan all the BB programs and report individually to each one affected.
110
harisec @harisec.bsky.social · 13/11/2024
That's helpful, thanks!
010
harisec @harisec.bsky.social · 13/11/2024
I will definitelly do something with the BlueSky Firehose, that sounds very interesting. joelgustafson.com/posts/2024-1...
joelgustafson.com
Visualizing 13 million BlueSky users | Joel Gustafson
000
harisec @harisec.bsky.social · 12/11/2024
Recraft's new model, unlike typical diffusion models, can handle math and geography - a surprising capability for an image generator. I wrote an article about abusing this functionality to leak its system prompt (using only generated images). www.invicti.com/blog/securit...
invicti.com
System prompt exposure: how AI image generators may leak sensitive instructions
Recraft's image generation service uses a unique architecture combining an LLM (Claude) with a diffusion model. Learn what led to the discovery that carefully crafted prompts could expose the system's...
010
harisec @harisec.bsky.social · 29/10/2024
I wrote a blog post about analyzing WordPress hack access logs with #NotebookLM www.invicti.com/blog/securit...
invicti.com
Analyzing WordPress Hack Access Logs With NotebookLM
Learn how to analyze WordPress hack access logs using Google's NotebookLM, featuring a real-world case study of detecting and investigating a CVE-2023-6961 exploit in the WP Meta SEO plugin through in...
040