Sign in

Soroush Dalili 🍏🍐

@irsdl.bsky.social
1.8K followers 245 following 27 posts

Hacker (ethical), web appsec specialist, trainer, tools builder & apps breaker, X: @irsdl secproject.com soroush.me burpsuite.ninja

PostsRepliesMedia
Reposted by Soroush Dalili 🍏🍐
James Kettle @jameskettle.com · 05/02/2026
The voting has concluded, and we're thrilled to announce the top ten web hacking techniques of 2025! Massive thanks to everyone in the community for sharing their hard-earned discoveries, plus the panel and everyone who nominated or voted! portswigger.net/research/top...
portswigger.net
Top 10 web hacking techniques of 2025
Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
1107
Soroush Dalili 🍏🍐 @irsdl.bsky.social · 18/11/2025
Some sites may use direct IP address today if their domain name servers were not with Cloudflare too! There is this opportunity for WAF bypass... please share it , sharing is caring... 🤗
020
Reposted by Soroush Dalili 🍏🍐
David Buchanan @retr0.id · 18/11/2025
happy cloudflare outage day to all who celebrate
231504380
Soroush Dalili 🍏🍐 @irsdl.bsky.social · 18/11/2025
With cloudflare being down, and as a result, most things I use being down, I came here to say hi 🤭 I guess I will use other AIs than chatgpt today!
051
Soroush Dalili 🍏🍐 @irsdl.bsky.social · 08/04/2025
These days, I’m off work, busy taking care of a family member, so this really brightened my day and brought a big smile to my face. 😌 thanks @portswigger.net
2100
Reposted by Soroush Dalili 🍏🍐
gabe is not a ghost @infoseccrow.social · 07/04/2025
Did you know? DC4420, the London monthly that graced central London for all of the 10s and before, has a new home and a new date! Greene Man, 383 Euston Road, London, NW1 3AU April 29 Be there. www.eventbrite.co.uk/e/dc4420-apr... has details. you don't have to register. #infosec #security
eventbrite.co.uk
DC4420 - April 2025
A beta relaunch of the calendar classic DC4420.
034
Reposted by Soroush Dalili 🍏🍐
Nicolas Grégoire @agarri.fr · 28/03/2025
If you like hacking XML, this article is a gold mine! 😱 It includes parser discrepancies, round-trip attacks and my favorite, namespace confusion 🤩
0267
Soroush Dalili 🍏🍐 @irsdl.bsky.social · 04/02/2025
Congrats to all the winners (especially @orange.tw) and all researchers who made the 2024 long list! 🥂 Thanks for sharing your work with us! 🫡 To readers: Don’t just read the top 10—start there and then explore the rest. There are many great works beyond the top 10, so don’t limit yourself! 🦾
170
Reposted by Soroush Dalili 🍏🍐
James Kettle @jameskettle.com · 23/01/2025
This year two new security legends have joined the top-ten expert panel - @liveoverflow.bsky.social and @stokfredrik.bsky.social! Excited to see what analysis & insights they bring to the top ten alongside long-time contributors @agarri.fr and @irsdl.bsky.social
1405
Reposted by Soroush Dalili 🍏🍐
James Kettle @jameskettle.com · 15/01/2025
Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: portswigger.net/polls/top-10...
portswigger.net
Top 10 web hacking techniques of 2024
Welcome to the community vote for the Top 10 Web Hacking Techniques of 2024.
0248
Soroush Dalili 🍏🍐 @irsdl.bsky.social · 09/01/2025
Please submit any interesting and especially new web/http related topic published in 2024
021
Soroush Dalili 🍏🍐 @irsdl.bsky.social · 24/12/2024
If you are using YSoSerial .Net, we have accepted a few PRs and patched several bugs & improved the ViewState plugin! Merry Christmas 🎅 github.com/pwntester/ys...
1165
Reposted by Soroush Dalili 🍏🍐
tmp0ut @tmpout.sh · 16/12/2024
We are extending our call for papers to January 1, 2025! We are now targeting an end of January release. If you have any Linux/ELF related research, projects, or papers, we would love to publish them! Huge thank you to everyone who has already submitted! tmpout.sh/blog/vol4-cf...
03519
Soroush Dalili 🍏🍐 @irsdl.bsky.social · 14/12/2024
It seems Bsides Birmingham is now happening: www.bsidesbrum.com CFP is also open! 😎
bsidesbrum.com
Bsides Birmingham
040
Soroush Dalili 🍏🍐 @irsdl.bsky.social · 14/12/2024
Currently at #BSidesLDN2024 @n1ckdunn.bsky.social
020
Reposted by Soroush Dalili 🍏🍐
Cooper @ministraitor.bsky.social · 12/12/2024
🔥 Get ready for the biggest #SecuriTay yet! 🔥 🦄 500 attendees 🎮 2-day CTF 🤝 Multiple sponsors 📅 Happening 28 | 02 | 2025 - First ticket drop coming soon! 👀 More details at securi-tay.co.uk
securi-tay.co.uk
Securi-Tay 2024
The thirteenth annual occurrence of the Securi-Tay conference! Brought to you by @AbertayHackers.
174
Reposted by Soroush Dalili 🍏🍐
terjanq @terjanq.me · 10/12/2024
Extended the starter with shy writers! 😀 If you're not on the list but write about web security, then feel free to reply with the article you're most proud of, and I will add you to the pack! Make sure to resubscribe to not not miss on the amazing 🌐research! go.bsky.app/9JXnB17
92910
Reposted by Soroush Dalili 🍏🍐
harisec @harisec.bsky.social · 26/11/2024
I've released 'brainstorm': an alternative way to do web fuzzing combining my fav fuzzing tool 'ffuf' (from @joohoi.bsky.social )with local LLMs (via Ollama API) to generate smarter filename tests. It usually finds more endpoints with fewer requests. Added a IIS shortname support @irsdl.bsky.social
5389
Reposted by Soroush Dalili 🍏🍐
James Kettle @jameskettle.com · 23/11/2024
The "bug bounty hunters and content creators" starter pack is now up to 60 users! Follow this to get instantly connected to the bug bounty community & let me know if I've missed you off! go.bsky.app/GD7hKPX
go.bsky.app
Bug bounty hunters & content creators
Join the conversation
198722
Reposted by Soroush Dalili 🍏🍐
James Kettle @jameskettle.com · 21/11/2024
Any bug bounty people around? I'm creating a starter pack of people to follow but it's pretty brief currently! Let me know if you'd like to be added: go.bsky.app/GD7hKPX
459530
Reposted by Soroush Dalili 🍏🍐
TomNomNom @tomnomnom.com · 20/11/2024
If you ever find yourself investigating random docker images, dive (github.com/wagoodman/dive) is amazingly useful. It lets you see which files changed in each filesystem layer. I've used it to spot config files accidentally left in images :)
github.com
GitHub - wagoodman/dive: A tool for exploring each layer in a docker image
A tool for exploring each layer in a docker image. Contribute to wagoodman/dive development by creating an account on GitHub.
0265
Reposted by Soroush Dalili 🍏🍐
Nicolas Grégoire @agarri.fr · 19/11/2024
That’s what App Passwords are made for 🔒 Go to "Settings > Advanced > App Passwords" to create one for each 3rd-party app You can login with your handle and this specific password ✅
142
Reposted by Soroush Dalili 🍏🍐
Nicolas Grégoire @agarri.fr · 18/11/2024
The best we have right now in the "My pins" feed You reply with a pin emoji to the post you want to bookmark And the feed shows all your messages containing a pin bsky.app/profile/josh...
343
Soroush Dalili 🍏🍐 @irsdl.bsky.social · 17/11/2024
I wish I had the bookmark ability here as well. Any pointers?
360
Reposted by Soroush Dalili 🍏🍐
Rory McCune @mccune.org.uk · 15/11/2024
As there's more people showing up here who are into Web Application Security and I couldn't find an existing starter pack for it, I decided to create one :) If you do webappsec stuff and want added ping me :) go.bsky.app/NB1hgC
145522
Reposted by Soroush Dalili 🍏🍐
Mastering Burp Suite @mastering-burp.agarri.fr · 04/09/2023
Sharpener was forked in June. It's sill maintained by irsdl, but it isn't a MDSec project anymore. The BappStore switched to the fork and currently hosts v3.6, but you can get the latest version (v3.9) directly from Github.
github.com
Releases · irsdl/BurpSuiteSharpenerEx
Contribute to irsdl/BurpSuiteSharpenerEx development by creating an account on GitHub.
022