Sign in

Lauritz

@lauritz-holtmann.de
343 followers 299 following 35 posts

IT-Security Researcher, Pentester and Bug Hunter. Passionate about 💻, 🤽‍♂️, ⚜️, 🎸 and ⚽ #meinVfL #Kaeferjaeger + H1 Ambassador 🏠 security.lauritz-holtmann.de

PostsRepliesMedia
Lauritz @lauritz-holtmann.de · 29/06/2026
leHACK 2026, c’était une vraie fête.🇫🇷 I had an awesome time in #Paris for this year's edition of @le-hack.bsky.social, "Brave New World". It was a great conference - my first time attending - with great talks, a mini LHE hosted by @yeswehack.bsky.social with Puma as the target, and meeting friends.
110
Lauritz @lauritz-holtmann.de · 25/06/2026
I'll be around in #Paris at @le-hack.bsky.social over the next few days. Do not hesitate to say "hi" if you bump into me or ping me if you want to have a chat about #BugBounty -related things! :)
010
Lauritz @lauritz-holtmann.de · 06/05/2026
Limited slots (≤20 per team), mixed skill levels, and an emphasis on meaningful findings. If you’re as excited as we are regarding the upcoming AWC and are situated in🇳🇱 or 🇩🇪 - sign up before May 27 and join us for this special event! RSVP and Details: h1.community/e/mrd2c9/ (3/3)
h1.community
Hacking Meetup "Friendly-Edition": Netherlands vs. Germany 🇳🇱🇩🇪 | HackerOne Community
Hybrid Event - Join this special hacking meetup hosted in collaboration by the HackerOne Clubs of Germany and the Netherlands! We will be hacking on a live target, connecting, collaborating, and compe...
010
Lauritz @lauritz-holtmann.de · 06/05/2026
Expect a week of focused hacking on a real target, collaboration, and a competitive edge via a shared leaderboard. Timeline: • May 30 → June 7 (remote phase) • June 7 (hybrid finale, near NL–DE border) (2/3)
110
Lauritz @lauritz-holtmann.de · 06/05/2026
Hacking Meetup "Friendly Edition" 🇳🇱 vs 🇩🇪 The @hacker0x01.bsky.social Club Netherlands and HackerOne Club Germany are teaming up for a cross-club bug bounty competition - inspired by the HackerOne Ambassador World Cup. #BugBounty #Meetup (1/3)
130
Lauritz @lauritz-holtmann.de · 07/01/2026
Bug Bounty Meetup vol. 5 of the German @hacker0x01.bsky.social club will be held Feb 14th to Feb 22nd (remote). 👨‍💻 20 seats, swag, remote space for networking, a bug bounty target and lots of collaboration. RSVP now: h1.community/e/mbcd6v/
Screenshot taken from https://valdotr.github.io/medium-webinar/map.json by Vlado Romao.
010
Lauritz @lauritz-holtmann.de · 23/12/2025
[Blog Post] Turning the List-Unsubscribe SMTP Header into an SSRF/XSS Gadget security.lauritz-holtmann.de/post/xss-ssr... Once again, ancient RFCs and overlooked security hot spots in specifications turned out to be worthwhile for security research. Read the spec!
security.lauritz-holtmann.de
Turning List-Unsubscribe into an SSRF/XSS Gadget
The List-Unsubscribe SMTP header is standardized but often overlooked during security assessments. It allows email clients to provide an easy way for end-users to unsubscribe from mailing lists. This ...
022
Lauritz @lauritz-holtmann.de · 06/10/2025
Recap of our @hacker0x01.bsky.social Hacking Meetup in September 👀 Leaderboard (still in progress): leaderboards.hackerone.live/germany-meet... 👉 h1.community/e/mbkdm3/ #BugBounty #Meetup #HackerOne
030
Reposted by Lauritz
Oli (C..1..P.H.Y) @munz4u.de · 26/06/2025
I reported a single, highly critical vulnerability that earned the top payout of the event. 💥🐞 Big thanks to @exness6.bsky.social for putting together such a great virtual meetup, and a special shoutout to @lauritz-holtmann.de! Everything was incredibly well organized! 🙌
161
Lauritz @lauritz-holtmann.de · 26/06/2025
Leaderboard: leaderboards.hackerone.live/germany-meet...
000
Lauritz @lauritz-holtmann.de · 26/06/2025
Thank you very much to everyone who made the event possible! ❤️ Congrats to c1phy (hackerone.com/c1phy) for securing the well-deserved 1st place. 🥇 Join your local h1.community chapter to not miss opportunities like this! h1.community/chapters/ #BugBounty #Meetup #HackerOne
110
Lauritz @lauritz-holtmann.de · 26/06/2025
Hacking Meetup vol. 3 of the German @hacker0x01.bsky.social Club - supported by @exnessofficial.bsky.social - was a blast! 💥 We x6 the overall bounties of our previous meetup and scored over 94,000$ overall bounties. 🤯 Additionally, H1 swag is on the way to all attendees and will arrive soon. 🤞
150
Lauritz @lauritz-holtmann.de · 27/03/2025
Join our (or your local) club on h1.community to not miss future events in your region: h1.community/germany-hack... The leaderboard of the event can be found here: leaderboards.hackerone.live/germany-meet... Event wrap-up: h1.community/e/mgswsg/
h1.community
H1 | HackerOne Community
At HackerOne, we're making the internet a safer place. Thousands of talented people – hackers, employees, and community members – have dedicated ourselves to making the internet safer by helping organ...
000
Lauritz @lauritz-holtmann.de · 27/03/2025
Overall, we submitted 21 vulns and scored (by now) over 13k$ in bounties. And there are still some reports in triage or pending bounty state 🤞 Thanks to @hacker0x01.bsky.social and Grab for supporting the event and everyone who attended and collaborated!
110
Lauritz @lauritz-holtmann.de · 27/03/2025
Our @hacker0x01.bsky.social meetup (vol.2) last month was a blast! 🔥 Almost 40 signups, ~25 active remote attendees and 12 attendees from all over Germany who travelled to #Bochum and hacked together in person on Grab's assets. 🤯 #BugBounty #Meetup
130
Lauritz @lauritz-holtmann.de · 04/02/2025
bsky.app/profile/laur...
000
Lauritz @lauritz-holtmann.de · 04/02/2025
🧑‍💻 #BugBounty Meetup Vol. 2 of the German @hacker0x01.bsky.social Club x Grab The event is organised like a Mini-LHE: 📅 15.02. - 21.02.25 Remote Hacking 📅 22.02.25 In-Person Day 📍#Bochum (Work Inn Bochum-FiftyOne) ‼️ Signup Deadline: Wednesday, Feb 12th. 👉 h1.community/e/mgswsg/
250
Lauritz @lauritz-holtmann.de · 28/01/2025
True, it does. Whoops 🙈
eval is overwritten using eval=console.log resulting in alert(1) being logged. This indicates jsfuck uses eval.
020
Lauritz @lauritz-holtmann.de · 27/01/2025
In case space is no problem, you could also use good old jsfuck.com
jsfuck.com
JSFuck - Write any JavaScript with 6 Characters: []()!+
JSFuck is an esoteric and educational programming style based on the atomic parts of JavaScript. It uses only six different characters to execute code.
100
Lauritz @lauritz-holtmann.de · 27/01/2025
window['aler'+'t']() Does this 👆 count?
260
Lauritz @lauritz-holtmann.de · 06/01/2025
👉Signup here: h1.community/events/detai... This is a community event that is organized by volunteers and supported by H1, e.g. by sponsoring the venue. Thanks to @hacker0x01.bsky.social for their support! ❤️ (3/3)
h1.community
German HackerOne Club: Hacking Meetup vol. 2 | HackerOne Community
Hybrid Event - Join the second Hacking Meetup of the HackerOne Club Germany! We are going to hack on a live target, connect, collaborate, and learn. This Meetup is open for all skill levels. Sign up...
000
Lauritz @lauritz-holtmann.de · 06/01/2025
The event will consist of a remote part and the final in-person day in Bochum. 15.02. - 21.02.25 Remote hacking and knowledge exchange on Discord 22.02.25 In-Person event in Bochum, Germany Please sign up ASAP as we only have limited space available. (2/3)
100
Lauritz @lauritz-holtmann.de · 06/01/2025
The new year starts with a bang: #BugBounty Meetup Vol. 2 of the German @hacker0x01.bsky.social Club will take place on February 22nd in #Bochum, Germany! 🧑‍💻 We will organize the event like a Mini-LHE: Like last year, there will be again a collaborating H1 program and a leaderboard. (1/3)
LHE Leaderboard of the last H1 Meetup in Bochum
100
Lauritz @lauritz-holtmann.de · 30/12/2024
#38c3 was 🚀
030
Lauritz @lauritz-holtmann.de · 27/12/2024
Just landed at #38c3 🤩 Ping me here or via ☎️5876 if you want have a chat, talk about things like #BugBounty or just want to have a Tschunk together. :) I also have a handful of #H1 stickers with me to spread. 😏
030
Lauritz @lauritz-holtmann.de · 27/12/2024
🔜🚀 #38c3
0100
Lauritz @lauritz-holtmann.de · 18/12/2024
Blog: #Android App Links Allowed Hijacking Arbitrary #SSO Flows 👉 security.lauritz-holtmann.de/post/sso-and... Discover how twitter.com/_kun_19 and I uncovered a severe issue allowing hijack of SSO flows on Android… only to find we were years late to the party. #BugBounty #Security #FuckUp
security.lauritz-holtmann.de
Android App Links autoVerify=false Allowed Hijacking Authentication Flows
Research is a constant process of failure and iteration. However, in most cases, you only see the one-in-a-thousand (successful) attempt. To normalize f*ck ups, and because I believe the behavior we i...
020
Lauritz @lauritz-holtmann.de · 17/12/2024
Oof. The comments here are baffling - I did not get to drive in the US, yet. 🤯 Fortunately, you do not see as many cars running red here in Germany. Maybe because getting caught running a red light that is red for >1sec means loosing your drivers license for at least a month (?) or so.
100
Lauritz @lauritz-holtmann.de · 02/12/2024
I blog about web and SSO things from time to time. :) Most referenced post about an AWS Cognito ATO in Flickr: security.lauritz-holtmann.de/advisories/f... Most recent post about POST-based SSO Flows leading to XSS issues: security.lauritz-holtmann.de/post/sso-sec...
security.lauritz-holtmann.de
POST to XSS: Leveraging Pseudo Protocols to Gain JavaScript Evaluation in SSO Flows
In 2020, a blog post was published here about the real-world security implications of a vague specification of the Redirect URI within the OAuth 2.0 RFC1. At that time, I focussed on redirect-based fl...
010
Lauritz @lauritz-holtmann.de · 29/11/2024
I mean, with something like this, one could even evaluate to Auto-Triage selected reports/vuln categories, and directly forward reports to engineering that fulfil certain criteria. Of course hackers will hack, but could be worth it. 🤷‍♂️
010
Lauritz @lauritz-holtmann.de · 29/11/2024
Have not looked much into it, but I like the approach of www.facebook.com/whitehat/fbdl At least for (most of the times) easy reproducible things like XSS. I suppose in these cases you also do not give much IP out of hand that would enable anyone to automize your manual methodology. 😅
facebook.com
110
Lauritz @lauritz-holtmann.de · 23/11/2024
Got my #38c3 ticket, see you in Hamburg 🚀
050
Lauritz @lauritz-holtmann.de · 21/11/2024
The "Dead Domain Discovery" Extension is now available from Chrome Web Store: 👉 chromewebstore.google.com/detail/opfeo... Keep in mind that the extension needs broad permissions to work. I'd recommend to only install it to your "research browser". Github: github.com/lauritzh/dea...
chromewebstore.google.com
Dead Domain Discovery - Chrome Web Store
Scans the page for external iFrames, Scripts, and Styles, logs them to the console, and checks if their domains are resolvable.
020
Lauritz @lauritz-holtmann.de · 15/11/2024
The Flickr ATO using AWS Cognito recently turned "3" and it is still my favorite bug bounty story 😅 Check out the blog post in case you missed it: security.lauritz-holtmann.de/advisories/f... H1 disclosure: hackerone.com/reports/1342...
062
Lauritz @lauritz-holtmann.de · 30/11/2023
#BurpSuite #Bambda to detect Blind SSRF via OpenID Connect "request_uri" using out-of-bound detection (e.g. Collaborator). The vulnerable URL is b64-encoded and included within the canary URL. 👉 gist.github.com/lauritzh/7b3... 📚 security.lauritz-holtmann.de/post/sso-sec...
020
Lauritz @lauritz-holtmann.de · 29/11/2023
Got my ticket for #37c3 - see you there! 🚀
060