Sign in

Pieter Hiele

@honoki.net
374 followers 459 following 277 posts

💻 hacker / relapsed bug bounty hunter 💤 mostly tired of tech ✍️ occasional blogger 🎵 amateur jazz pianist ⁉️ chess enthusiast 🤿 daydreaming of scuba diving 🌐 honoki.net

PostsRepliesMedia
Pieter Hiele @honoki.net · 01/08/2026
Frank dat is een closeup van Jupiter
Een NASA foto van Jupiter met exact dezelfde schakeringen als de zonsondergang van Frank
000
Pieter Hiele @honoki.net · 31/07/2026
met this guy in the English countryside, wanted a word with me
A photogenic, smiling sheep staring over a hedge right into my very soul, laying bare the secrets of my heart, and hushing my most existential doubts with its reassuring eyes.
000
Pieter Hiele @honoki.net · 12/07/2026
Historical plague doctor mask, which looks suspiciously like the heavy machinery in OP’s post.
110
Pieter Hiele @honoki.net · 29/06/2026
So these monstrosities exist and I feel like I shouldn’t be alone to carry the curse of that knowledge.
100
Pieter Hiele @honoki.net · 10/05/2026
It’s so pretty! We have a photograph on our mantelpiece of our beautiful dog with The Crescent in the background on our last summer trip before he passed.
000
Pieter Hiele @honoki.net · 26/04/2026
This but with software.
XKCD comic of a person pointing at a box labeled $80 saying: "They want $80 for this? I could make one myself for $10 in parts, an hour of work, a trip to the hardware store, another $30 in parts, another few hours of work, two more trips to the store for $20 more in parts, another hour to redo the first hour of work because I messed up, and $80 to buy this when the one I made breaks."
000
Pieter Hiele @honoki.net · 04/03/2026
What a delight to see @daraobriain.bsky.social kick off (?) the continental leg of his tour in Brussels tonight. (I had no idea there were so many Irishfolk around Brussels!) Go see him if you can!
An atmospheric shot of the beautiful Koninklijk Circus / Cirque Royal in Brussels, with a blue-lit dome while the crowd pours in.
030
Pieter Hiele @honoki.net · 06/02/2026
Got myself this sweet new toy yesterday, and spent all evening pretending to groove from the comfort of my couch. Fun stuff!
Stock photo of the AKAI LPK 25, a mini USB input device with 25 keys, looking all bubbly and cute.
020
Pieter Hiele @honoki.net · 27/01/2026
Wat zouden we toch doen zonder onze media… @vrtnws.be
De aarde zou op 12 augustus 2026 7
seconden haar zwaartekracht verliezen, met miljoenen doden als gevolg. Volgens video's op sociale media zou NASA daarvan op de hoogte zijn, maar die informatie geheimhouden. Dat klopt niet, want de aarde kan haar zwaartekracht niet zomaar ineens kwijtraken.
000
Pieter Hiele @honoki.net · 19/01/2026
Ik kan er mijn vinger niet opleggen maar er is iets grondig mis met het lettertype in dat logo. Alsof de drukker bij het ter perse gaan nog vroeg “die OTF heb ik niet, mag het iets anders zijn?”
Anders, het nieuwe logo van wijlen Open VLD
100
Pieter Hiele @honoki.net · 04/01/2026
When browsing to that polymarket site, I get redirected to this webpage and I love that for us.
Sinkholed webpage that says: "This gambling site is illegal in Belgium. It has therefore been blocked. Illegal gambling is dangerous and can even be punishable."
000
Pieter Hiele @honoki.net · 02/01/2026
I set myself a couple of bug bounty goals in '25: - Earn X€ / month; - Submit 5 reports (incl. 1 critical) / month; - Earn X€ in 2025 - Retain a H1 streak all year Here's how I did! My monthly € goal was missed by <10% in 3 months, but I hit my yearly € goal in November (which explains December?)
Table with headers Month, $, reports, crit, streak, showing check marks where goals were hit. December is the only month with no completed goals. I hit all 4 goals in March, August and November.
180
Pieter Hiele @honoki.net · 12/12/2025
Forgive me for being skeptical if "chatgpt said so" is your only argument. It seems your conclusion is right, but the data is shaky. Here's a table with numbers according to www.rit.edu/liberalarts/...
Table 1 - 24 U.S. Cities' Homicide Number, Rate, & Percent Change for 2023 - 2024, listing St. Louis, New Orleans and Detroit as the top 3, for example.
200
Pieter Hiele @honoki.net · 20/10/2025
This is what it looks like.
A screenshot of the context menu in Burp, showing Extensions > Copy unique domains > domains, URLs, paths, filenames or directories.
100
Pieter Hiele @honoki.net · 29/08/2025
Welcome to your nightmare future.
111
Pieter Hiele @honoki.net · 29/08/2025
Ik kan op geen van mijn accounts nog inloggen; paswoord wordt geaccepteerd (ook met passwordless via email code zelfde probleem), maar de OIDC login faalt.
000
Pieter Hiele @honoki.net · 22/08/2025
Is dat hoe je “er is sprake van” schrijft?
210
Pieter Hiele @honoki.net · 17/08/2025
Suddenly nostalgic for ThinkGeek. I bought so many fun gadgets there. And looking through my email receipts, one of them I've been carrying with me every day for more than 12 years!
A Utili-Key 6-in-1 Tool that looks like a simple key when strapped to a keychain.
010
Pieter Hiele @honoki.net · 13/08/2025
A page from Le Petit Prince which shows what looks like a hat, but turns out to be a snake having eaten an elephant:

"Mon dessin ne représentait pas un chapeau. Il représentait un serpent boa qui digérait un éléphant. J'ai alors dessiné l'intérieur du serpent boa, afin que les grandes personnes puissent comprendre. Elles ont toujours besoin d'explications."
000
Pieter Hiele @honoki.net · 13/08/2025
Accidental Petit Prince in my bookkeeping software.
120
Pieter Hiele @honoki.net · 23/07/2025
Too often I see people pushing with the middle of their feet and I wonder how they came to make such bad decisions in life.
120
Pieter Hiele @honoki.net · 22/07/2025
Now live on tools.honoki.net/smuggler.html Let me know what you think! ✨
02711
Pieter Hiele @honoki.net · 21/07/2025
Working on some way to visualize HTTP parser discrepancies when working on request smuggling vulnerabilities. Inspired by this blog post: w4ke.info/2025/06/18/f...
An HTML page with a raw request input field and side-by-side comparison of two ways differently-configured http parsers might interpret the same raw request, which could lead to request smuggling vulnerabilities. On the left, the parser sees a "normal" chunked request which parses a sneaky newline character (\n) as part of the chunked request header data; on the right, the same raw request is parsed differently because of the newline character being parsed as a terminator, prematurely ending the chunk header.
010
Pieter Hiele @honoki.net · 18/07/2025
000
Pieter Hiele @honoki.net · 11/07/2025
Also added a nifty new program filter to bbrf.me to filter your program list based on your own program tags.
Next to "select program" dropdown is a filter button that opens up a panel of fllter checkboxes, in this case: "platform", with options hackerone, intigriti, yeswehack. With the first checkbox selected, a message says "Showing 681 of 1037 programs".
010
Pieter Hiele @honoki.net · 08/07/2025
Got these storage bags slash window blinds from #VanEssa MobilCamping for our ID Buzz and they’re a perfect fit. Making me excited for our next trip. 🤩
010
Pieter Hiele @honoki.net · 06/06/2025
My office this afternoon is this wonderful garden from Kawon bookstore in Madaba, Jordan ☀️
A garden in Madaba, Jordan featuring a sandstone bar-slash-table, a large fig tree and a couple of sunbathing cats
030
Pieter Hiele @honoki.net · 28/05/2025
Finally reached the 10k reputation milestone on @hacker0x01.bsky.social 🤩
130
Pieter Hiele @honoki.net · 24/04/2025
How I preserve my sanity
230
Pieter Hiele @honoki.net · 15/04/2025
If all this is right, there seem to be 2 Boeing 747s that might be it: RYR85WD, headed NW for Manchester, or RYR7QF, headed slightly more N for London, just before 11PM
100
Pieter Hiele @honoki.net · 15/04/2025
That would put the plane in the shaded area on this map. That's very specific and seems kind of far/unlikely?
100
Pieter Hiele @honoki.net · 15/04/2025
The plane seems to span around 63px of the moon's 667-677px, which would put a Boeing 747 roughly 175 to 180km away I don't know if any of these calculations are correct
100
Pieter Hiele @honoki.net · 15/04/2025
Using the distance according to that mooncalc, and the example calculation on www.nasa.gov/wp-content/u..., it seems the apparent size of the moon was 0.49 arcminutes in the sky
100
Pieter Hiele @honoki.net · 01/04/2025
This webapp was built in the Middle Ages 🤯
150
Pieter Hiele @honoki.net · 18/02/2025
LinkedIn starting to push puzzles on its users has to signal the end is nigh, surely?
000
Pieter Hiele @honoki.net · 03/02/2025
Drove to the seaside this weekend and got stuck in a matrix glitch. #idbuzz
Two seemingly identical Volkswagen ID Buzz in green and white parked next to each other.
150
Pieter Hiele @honoki.net · 10/01/2025
👀
screenshot saying "the domain Attacker.com is now for sale"
110
Pieter Hiele @honoki.net · 10/01/2025
Ik heb hier tickets 338 tot 352 gedownload. Ik mag hopen dat dat geen 337 echte geïnteresseerden zijn. 🙄
350
Pieter Hiele @honoki.net · 17/12/2024
Here's a cute little config if you use Espanso (and I recommend it), which will automatically pretty-print any JSON you have copied to your clipboard by typing :jq espanso.org
130
Pieter Hiele @honoki.net · 12/12/2024
Very cool - but Hai is not great with respecting character limits it seems. ;)
000
Pieter Hiele @honoki.net · 29/11/2024
To help wrap my mind around overlong encoding of characters, I decided to put together a recipe in CyberChef following the excellent explanation on herolab.usd.de/en/the-secur... Here's the 2-byte version: gchq.github.io/CyberChef/#r...
Screenshot of the CyberChef recipe that converts the character A to the 2-byte overlong encoding 'C1 81'
2102
Pieter Hiele @honoki.net · 21/11/2024
Oops.
An email from Keybase saying “Uh-oh, honoki, your previously-proven twitter identity @honoki just broke. We've been checking it repeatedly, and it's not working from our perspective.”
030
Pieter Hiele @honoki.net · 20/11/2024
I'm celebrating my first CVE with a writeup! Hope you enjoy it. 🤓 "CVE-2020-11518: how I bruteforced my way into your Active Directory" honoki.net/2020/08/10/c...
A screenshot of a console with turbo intruder having successfully bruteforced a secret timestamp.
040
Pieter Hiele @honoki.net · 20/11/2024
"XXE-scape through the front door: circumventing the firewall with HTTP request smuggling" - read my write-up about a pretty cool way in which I bypassed a firewall stopping me from exploiting an XXE vulnerability. honoki.net/2020/03/18/x... #bugbounty #writeup #xxe
A typical New York fire escape. Because this write-up is about escaping a firewall. It’s a little joke.
1141
Pieter Hiele @honoki.net · 20/11/2024
Reposting my evergreens.🎄 Instead of using SSRF to peer inside a local network, I used an internal vulnerable server to proxy out traffic to the internet to turn my blind XXE into root-level file read access. Read my write-up on honoki.net/2018/12/12/f... #bugbounty #writeup #xxe #ssrf
Polyphemus, by Johann Heinrich Wilhelm Tischbein, 1802 (Landesmuseum Oldenburg), depicting the one-eyed giant son of Poseidon and Thoosa in Greek mythology.
4132
Pieter Hiele @honoki.net · 19/11/2024
010
Pieter Hiele @honoki.net · 18/11/2024
Phew, it's done.
350
Pieter Hiele @honoki.net · 29/08/2024
Updated the #BBRF dashboard to include: - URL routing (e.g. bbrf.me/#/program_name/domains) - clickable IPs/domains to fetch and display documents - JSON syntax highlighting - some JS cleanup github.com/honoki/bbrf-... Changes are live on bbrf.me
030
Pieter Hiele @honoki.net · 28/02/2024
I wrote a Burp extension to spin up a DigitalOcean droplet based on an OpenVPN configuration file and route traffic through it via a SOCKS proxy. Would be nice to hear some feedback about this! github.com/honoki/burp-... #bugbounty #burp
111