Sign in

Louis Dion-Marcil

@ldionmarcil.bsky.social
145 followers 278 following 6 posts

vegan btw. appsec @ mandiant/google cloud. opinions my own etc

PostsRepliesMedia
Reposted by Louis Dion-Marcil
Kévin Gervot (Mizu) @mizu.re · 24/07/2025
I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥 The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇 gmsgadget.com 1/4
12313
Louis Dion-Marcil @ldionmarcil.bsky.social · 23/06/2025
wrote some words about vulnerabilities i found in Aviatrix during a red team cloud.google.com/blog/topics/...
cloud.google.com
Trix Shots: Remote Code Execution on Aviatrix Controller | Google Cloud Blog
Red team case study detailing the discovery of two critical vulnerabilities in the Aviatrix Controller software.
041
Reposted by Louis Dion-Marcil
Micah Lee @micahflee.com · 04/05/2025
TeleMessage, the Israeli company that makes the modified Signal app used by Trump officials, was hacked. “I would say the whole process took about 15-20 minutes,” the hacker said micahflee.com/the-signal-c...
micahflee.com
The Signal Clone the Trump Admin Uses Was Hacked
TeleMessage, a company that makes a modified version of Signal that archives messages for government agencies, was hacked.
8269108
Reposted by Louis Dion-Marcil
CaidoIO @caido.io · 24/04/2025
🚀 Another plugin in the Caido Store! Introducing "Data Grep" by @bebiksior. Extract data from requests and responses. Great for building wordlists, finding secrets, or powering your recon. Check it out: github.com/caido-commun...
061
Reposted by Louis Dion-Marcil
terjanq @terjanq.me · 14/12/2024
Got sniped into the challenge and ended up doing some cool XSS research :D 11 char XSS with mind-boggling race-conditions. TL;DR the final payload is location=x (10 chars) and the longest is top.Z.x=x.d (11 char) It's shorter than location=name !! terjanq.me/solutions/jo...
terjanq.me
11 char XSS (slow race-condition)
13011
Louis Dion-Marcil @ldionmarcil.bsky.social · 06/12/2024
I wrote a thing with my colleague Ilyass El Hadi (0xc0ffee_) & Charles Prevost, about how we've been leveraging offensive webapp testing during Red Teams. 4 use cases of external breaches using webapps inside, enjoy! #appsec cloud.google.com/blog/topics/...
cloud.google.com
Bridging the Gap: Elevating Red Team Assessments with Application Security Testing | Google Cloud Blog
Red team and targeted external assessments should incorporate application security expertise to better simulate modern adversaries.
0187
Reposted by Louis Dion-Marcil
Corb3nik @atvh.dev · 30/11/2024
Environments are something I've wanted for a while now.
0123
Reposted by Louis Dion-Marcil
Luke Jahnke @nastystereo.com · 27/11/2024
My latest blog post is live! nastystereo.com/security/cro... Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
37829
Louis Dion-Marcil @ldionmarcil.bsky.social · 21/11/2024
Been having a ton of fun solving these, only 2/3 done and i'm quite humbled so far challenge-xss.quiz.flatt.training
challenge-xss.quiz.flatt.training
Flatt Security XSS Challenge
Execute alert(origin) on each challenge origins.
062
Reposted by Louis Dion-Marcil
becojo @becojo.com · 21/11/2024
add that to the reasons to stop using bash in production pipelines yossarian.net/til/post/som... #security #cicd #appsec
yossarian.net
TIL: Some surprising code execution sources in bash
051