Sign in

Maltemo

@maltemo.bsky.social
35 followers 61 following 7 posts

🇫🇷 - Security auditor. In my free time, interested in development, OSINT & Forensic. Eclectic hobbies and interests. Blog : maltemo.github.io

PostsRepliesMedia
Reposted by Maltemo
Freddy @freddyb.bsky.social · 07/03/2026
New blog post: Perfect types with `setHTML()` - frederikbraun.de/perfect-types-with… - TLDR: Use require-trusted-types-for 'script'; trusted-types 'none'; in your CSP and nothing besides setHTML() works, essentially removing all DOM-XSS risks....
1113
Maltemo @maltemo.bsky.social · 04/12/2025
Would you read your fuzzing wordlist before using it? What if there is a destructive query or an attacker payload inside? github.com/danielmiessl...
github.com
[Bug report]: Potential dangerous line in file `wso2-enterprise-integrator.txt` · Issue #1267 · danielmiessler/SecLists
I discovered while using the wordlist wso2-enterprise-integrator.txt that one of its entry tries to exploit what seems to be a SSRF to a (external or local ?) server : carbon/wsdl2code/index.jsp?ge...
000
Reposted by Maltemo
Pieter Hiele @honoki.net · 22/07/2025
Now live on tools.honoki.net/smuggler.html Let me know what you think! ✨
02711
Reposted by Maltemo
Kévin Gervot (Mizu) @mizu.re · 24/07/2025
I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥 The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇 gmsgadget.com 1/4
12313
Reposted by Maltemo
Geluchat @gelu.chat · 04/07/2025
Today was my last day as a pentester at Bsecure. After a three-year journey of hunting on the side, I’m ready to go all-in as a full-time bug bounty hunter. You can read about my journey from pentester to full-time hunter here: gelu.chat/posts/from-p...
gelu.chat
Finding Freedom, One Bug at a Time: My Journey from Pentester to Full-Time Hunter
After seven years in pentesting, I transitioned full-time into bug bounty hunting, leveraging deep experience and continuous learning. This article shares key moments and insights from that journey.
3247
Reposted by Maltemo
Laluka @laluka.bsky.social · 02/05/2025
Documenté, Sourcé, Miniaturé, Plus qu'à... Siroter ! 🎁 Cc @maltemo.bsky.social 🤝 @KharaTheOne (X) www.youtube.com/live/we_T4x6...
011
Maltemo @maltemo.bsky.social · 29/04/2025
Intéressant, attribution officielle par l'état Français de l'attaque TV5 Monde à l'APT28 appartenant au GRU. bsky.app/profile/gabr...
000
Reposted by Maltemo
Gareth Heyes @garethheyes.co.uk · 25/04/2025
Firefox treats multipart/x-mixed-replace like HTML. Chrome doesn’t. That tiny difference? It can turn a "non-exploitable" XSS into a real one. Abuse boundary handling, bypass filters, and make your payload land. thespanner.co.uk/making-the-u...
thespanner.co.uk
Making the Unexploitable Exploitable with X-Mixed-Replace on Firefox - The Spanner
In this post, we’ll look at an interesting difference in how Firefox and Chrome handle the multipart/x-mixed-replace content type. While Chrome treats it as an image, Firefox renders it as HTML - some...
0188
Reposted by Maltemo
Laluka @laluka.bsky.social · 28/04/2025
Blip @maltemo.bsky.social Bloup @KharaTheOne (X) Boum 💣️ www.twitch.tv/thelaluka
021
Reposted by Maltemo
Include Security @includesecurity.bsky.social · 17/04/2025
Do you use WebSockets? Read our latest blog post to find out how modern browsers may (or may not) be protecting you from Cross-Site WebSocket Hijacking. blog.includesecurity.com/2025/04/cros...
blog.includesecurity.com
Cross-Site WebSocket Hijacking Exploitation in 2025 - Include Security Research Blog
Include Security's latest blog post covers Cross-Site WebSocket Hijacking and how modern browser security features do (or don't) protect users. We discuss Total Cookie Protection in Firefox, Private N...
111
Maltemo @maltemo.bsky.social · 28/03/2025
I was reading Chromium source code from a website that doesn’t have search bar or any indexing and searched my way with google dorks: chromium.googlesource.com/chromium/src... I just discovered there is an index version featuring function hovering and linking 🤦‍♂️: source.chromium.org/chromium/chr...
chromium.googlesource.com
/ - chromium/src - Git at Google
000
Reposted by Maltemo
Gareth Heyes @garethheyes.co.uk · 20/03/2025
🔥 My Black Hat talk is now live! 🎥 Watch how email parsing quirks turned into RCE in Joomla and critical access control bypasses across major platforms. See how these subtle flaws led to serious exploits! www.youtube.com/watch?v=Uky4...
youtube.com
Splitting the Email Atom: Exploiting Parsers to Bypass Access Controls
YouTube video by Black Hat
0236
Reposted by Maltemo
Gareth Heyes @garethheyes.co.uk · 18/03/2025
You might have noticed that the recent SAML writeups omit some crucial details. In "SAML roulette: the hacker always wins", we share everything you need to know for a complete unauthenticated exploit on ruby-saml, using GitLab as a case-study. portswigger.net/research/sam...
portswigger.net
SAML roulette: the hacker always wins
Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library
05323
Reposted by Maltemo
Aethlios @aethlios.bsky.social · 12/03/2025
Great resource on secret leakage, I invite you to read it.
gitguardian.com
The State of Secrets Sprawl Report | GitGuardian
021
Reposted by Maltemo
Myko Nordy @n0rdy.foo · 22/01/2025
A few weeks ago, I've learned about the Okta Bcrypt incident from the @gergely.pragmaticengineer.com newsletter, and it made me wonder about the API choices by crypto libraries that allowed this incident to be unnoticed for years. My new post explores the topic. Enjoy! =) n0rdy.foo/posts/202501...
n0rdy.foo
n0rdy - What Okta Bcrypt incident can teach us about designing better APIs
133
Reposted by Maltemo
Laluka @laluka.bsky.social · 04/02/2025
Health insurance OK??? COOL! Part 2/3 then! www.youtube.com/watch?v=CKqr...
youtube.com
EP 178 | Techno Watch January Ft. @Drypaints @Maltemo @pentest_swissky
YouTube video by Laluka
021
Reposted by Maltemo
Laluka @laluka.bsky.social · 03/02/2025
Hi it's me again, I've been calling for a while now, you need to pay your health insurance Sir... Or have some replays? 😏 La dernière Techno Watch avec @Drypaints @Maltemo et @pentest_swissky !🌿 www.youtube.com/watch?v=ysen... 1/2
youtube.com
EP 177 | Techno Watch January Ft. @Drypaints @Maltemo @pentest_swissky
YouTube video by Laluka
131
Reposted by Maltemo
Laluka @laluka.bsky.social · 28/01/2025
Yop ! 🌿 Reprise des veilles technos ce soir 21h ! 🌖 En compagnie de @drypaint.bsky.social @maltemo.bsky.social @swissky.bsky.social 😎 ~ See you there ~ www.twitch.tv/thelaluka
twitch.tv
Twitch
Twitch is the world
022
Maltemo @maltemo.bsky.social · 28/01/2025
Question about Trusted Types : What blocks an attacker from creating it’s own Trusted TypePolicy from the TrustedTypePolicyFactory with a function that doesn’t sanitize input data ? Am I missing something ?
100
Reposted by Maltemo
d4d @zakfedotkin.bsky.social · 22/01/2025
Hot out of the oven! The Cookie Sandwich – a technique that lets you bypass the HttpOnly protection! This isn't your average dessert; it’s a recipe for disaster if your app isn’t prepared: portswigger.net/research/ste...
portswigger.net
Stealing HttpOnly cookies with the cookie sandwich technique
In this post, I will introduce the "cookie sandwich" technique which lets you bypass the HttpOnly flag on certain servers. This research follows on from Bypassing WAFs with the phantom $Version cookie
03413
Maltemo @maltemo.bsky.social · 08/01/2025
@fox0x01.bsky.social just reported an account trying to impersonate you : [@]foxox01.bsky.social
010
Reposted by Maltemo
Nicolas Grégoire @agarri.fr · 23/12/2024
Somebody uploaded to SlideShare the slides of my talk at @northsec.bsky.social 2023 🌐 It’s the sequel of the first @burpsuite.bsky.social talk I ever gave, exactly 10 years before 🛠️ Enjoy these 50 slides of Burp tips 🎁🎅
slideshare.net
Burp suite pro tips and tricks for hacking
Burp suite pro tips and tricks for hacking - Download as a PDF or view online for free
03818
Reposted by Maltemo
mpgn @mpgn.bsky.social · 31/12/2024
hear me out, pass the certificate auth on nxc 🔥
073
Reposted by Maltemo
Dirk-jan @dirkjanm.io · 12/12/2024
Want to run roadrecon, but a device compliance policy is getting in your way? You can use the Intune Company Portal client ID, which is a hardcoded and undocumented exclusion in CA for device compliance. It has user_impersonation rights on the AAD Graph 😃
34520
Maltemo @maltemo.bsky.social · 26/11/2024
Just discovered this nice resource about DOM Clobbering attacks : domclob.xyz Thank you Soheil for this amazing work
domclob.xyz
DOM Clobbering
DOM Clobbering Wiki
011