Sign in

renniepak

@renniepak.nl
2.2K followers 208 following 176 posts

Self-XSS connoisseur. Elite Hacker. MVH H11337UPBash. One-Percent Man. Creator of CSPBypass.com. (he/him)

PostsRepliesMedia
renniepak @renniepak.nl · 11/09/2026
Found the best vulnerability of my life today. Responsibly disclosed ofcourse. Hopefully I can share a CVE anytime soon :)
010
Reposted by renniepak
0xacb @0xacb.com · 22/06/2026
We've all been there: found an XSS, blocked by CSP. There's a bunch of CSP bypasses that you can try by @renniepak.nl: cspbypass.com It has a compilation of bypasses, based on the exact CSP you're up against.  Here’s a quick tutorial on how to use it 👇
052
Reposted by renniepak
Jorian @jorianwoltjer.com · 28/05/2026
I won't keep you in mystery any longer, here's how I found an XSS vulnerability *in* Shazzer! The chain involved some interesting browser techniques no sane developer could foresee. Check out the details below: jorianwoltjer.com/blog/p/stori... (and thanks @garethheyes.co.uk for making Shazzer!)
jorianwoltjer.com
Finding XSS on Shazzer (literally) | Jorian Woltjer
How I found an XSS in Shazzer, a tool for discovering and sharing browser quirks through fuzzing. Not *using*, but *in* Shazzer. We'll explore some useful techniques with Blob URLs to unsandbox malici...
096
renniepak @renniepak.nl · 25/05/2026
None of this happens without the people who make it happen. A massive thank you to our sponsor @intigriti.com , to my incredible co-organiser @g0053.me, and above all, to the 22 of you who travelled from near and far to be part of our HackerHideout community. See you next time!
040
renniepak @renniepak.nl · 25/05/2026
Looking back on #hh0526 with a big smile. 😊 We brought together 22 hackers from 9 different nationalities in the wonderful city of Utrecht for a day of pure bug bounty fun, hacking on @intigriti.com programs with special event bonuses included.
141
renniepak @renniepak.nl · 16/05/2026
shazzer.co.uk/renniepak/st...
010
renniepak @renniepak.nl · 08/04/2026
򫑰򚁲򚐩򯑽򬡥򬑵򩑳Ꝋ򫡩򫑡򭁩򫱮򡡲򨑭򩐨򬰩򯐻򬰨򚑽򚀩`.replace(/u\D*/g,``)))
121
renniepak @renniepak.nl · 08/04/2026
򬀨򚐻򩠮򪡵򫑰򪑮򩱼򯀨򫰽򪐽򜀬򫠽򫡵򫁬򚑽򪑦򚀡򩠮򪡵򫑰򪑮򩰦򙠡򩠮򩁵򨱫򪑮򩰦򙡣򛡬򩑮򩱴򪀩򮱬򩑴򘁥򞱦򫱲򚁬򩑴򘁪򘁯򩠠򨰩򪑦򚀡򪠮򬡥򫑯򭡥򙠦򪠮򮁐򫱳򟠽򮀩򮱥򟑪򞱢򬡥򨑫򯑩򩠨򩐦򙡥򘐽򟑮򚑻򫁥򭀠򩀽򩐮򮁐򫱳򛑸򛁓򟑤򛱲򛁔򟑥򛡴򮑰Ꙝ򫱮򩡩򩰬򬀽򥀮򭁹򬁥򟐽򤀦򙡥򛡹򤁯򬰼ꏗ򝐬򮐽򩐮򮑐򫱳򛁡ꏐ򛁨ꏙ򜰬򭠽򭐻򩡯򬠨򫁥򭀠򪰽򜐻򪰼㈀򞱫򚰫򚑻򪀫򟑶򛁶򚰽ꋦ򞱩򩠨򪀼򮐩򮱡򟑫򞱢򬡥򨑫򯑩򩠨򪀾ꏙ򜰦򙡫ꏡ򚑢򬡥򨑫򯑡򯁼򚁡ꏔ򚐻򫁥򭀠򫐽򨐫򝀻򩡯򬠨򫁥򭀠򪠠򫱦򘁣򚑩򩠨򪠡򟐽򩐦򙠡򪠮򬡥򫑯򭡥򙠦򪠮򮁐򫱳򟡸򚑻򫁥򭀠򬐽򚁪򛡸򤁯򬰭򮀩򛱲򛁢ꏐ򞱨㶓򛁶򟑵򞱦򫱲򚁬򩑴򘁫ꏑ򞱫㰠򜀻򪰫򚰩򪑦򚁨򚰽򭠬򭠫򟐮򝠬򪀾ꏙ򜰦򙡫ꏡ򚑻򨠽򪰻򨡲򩑡򪱽򬐼򨠫򨐫򝠦򙠨򫐽򨐫򜠩򞱢򬡥򨑫򯑰򟱓㰐򙠦򚁮򟑥򛁦򛡳򩑴򡁵򨱫ꊁ򚐬򬱥򭁔򪑭򩑯򭑴򚀨򚐽򟡦򛡤򭑣򪱩򫡧򙠦򩠮򬱥ꝍ򭑣򪰨򜀩򛁍򨑴򪀮򨱥򪑬⠖⹧򚠨򩀫򥀮򭱩򩁴򪀪򩐮򬱩򮡥򚱗򚐯򬠩ꊸ򜀩򚐺򤰼򟑭򙠦򚁮򟑥򛁯ꏑ򛁩ꏐ򛁦򛡳򭁡򬡴򢡵
110
renniepak @renniepak.nl · 08/04/2026
eval(unescape(escape`!򩡵򫡣򭁩򫱮ꈊ򚀩򮱬򩑴򘁧򟑒򭑮򫡥򬠮򩱥򭁉򫡳򭁡򫡣򩐨򚐻򪑦򚀡򩱼򯀡򩰮򬁬򨑹򪑮򩰩򬡥򭁵򬡮򘁤򫱣򭑭򩑮򭀮򩁩򬱰򨑴򨱨򡑶򩑮򭀨򫡥򭰠򢱥򮑢򫱡򬡤򡑶򩑮򭀨򘡫򩑹򩁯򭱮򘠬򮱫򩑹򠱯򩁥ꎣ򜡽򚐩򛁶򫱩򩀠򬱥򭁔򪑭򩑯򭑴ꊊⱐ򜀩򞱬򩑴򘁴ꏑ򛁮򛁯ꏐ򛁩ꏐ򛁐򟐢򬁴򩑲򫱤򨑣򭁹򫀢򛁳򟐨򚐽򟡻򪑦򚀡򭀩򬡥򭁵򬡮򞱬򩑴򘁧򟑒򭑮򫡥򬠮򩱥򭁉򫡳򭁡򫡣򩐨򚐻򪑦򚀡򩱼򯁧򛡣򬡡򬱨򩑤򚑲򩑴򭑲򫠠򭀽򜀻򫁥򭀠򩠽򩰮򭁒򩑸򛁣򟑧򛡨򫱲򪑺򫱮򛡯򨡳򭁡򨱬򩑳򛁲򟑧򛡣򭑲򬡥򫡴򤱰򩑥򩀬򭐽ⴐ򛑲ꋱ򜀬򭰽򩠮򮁐򫱳򛁗򟑦򛡣򫱮򩡩򩰮򭱩򩁴򪀬򮀽򭰫򥰻򪑦򚁯򚑻򪐫򚰻򫁥򭀠򩐽򜐻򩡯򬠨򫁥򭀠򪠠򫱦򘁣򚑻򫁥򭀠򥀽򪠮򭁹򬁥򠱯򫡦򪑧򞱩򩠨򥀮򭁹򬁥򟐽򤀦򙡪򛡹򤁯򬰼ꏗ򝐩򨱯򫡴򪑮򭑥򞱩򩠨򪠮򮁐򫱳򟁸ꊳ򜀦򙡪򛡸򤁯򬰫򥀮򭱩򩁴򪀪򪠮򬱩򮡥򟡷ꋑ򜀦򙡦򛡹򤁯򬰫򩠮򨱯򫡦򪑧򛡨򩑩򩱨򭀾򪠮򮑐򫱳򚑻򩐽򜀻򨡲򩑡򪱽򯑥򙠦򩠮򪡵򫑰򪑮򩰦򙡩ꏥ򙠦򩠮򩑮򩁊򭑭
120
renniepak @renniepak.nl · 22/03/2026
For anyone curious, I just pushed the complete set to our repo: github.com/renniepak/CS...
github.com
Added csp_domains.json and updated README.md · renniepak/CSPBypass@10434a9
040
renniepak @renniepak.nl · 19/03/2026
The results are quite interesting and can be found here: cspbypass.com/csp-domains.... To keep the list manageable, it only includes hostnames with 10 or more occurrences. I will push the full dataset to GitHub shortly.
cspbypass.com
CSP Domain Rankings
150
renniepak @renniepak.nl · 19/03/2026
To answer that question, I processed the latest Common Crawl dataset, totalling 14.54 TB, to compile a full list of the most commonly whitelisted domains found in CSP script-src directives (falling back to default-src where script-src was absent).
110
renniepak @renniepak.nl · 19/03/2026
When reviewing pull requests with new additions for CSPBypass.com, I often find myself questioning how useful a given entry actually is. If no websites whitelist a specific host, there is little point in adding it.
155
renniepak @renniepak.nl · 06/03/2026
What windows or MacOs files reliably contain the username of the currently logged in user WITHOUT that username being part of the file path?
000
renniepak @renniepak.nl · 12/02/2026
The best time to quit bug bounty was 20 months ago. The second best time is now.
160
renniepak @renniepak.nl · 07/02/2026
Added a small feature to cspbypass.com to warn the user if unsafe-inline is detected, in which case you typically don’t need to waste time hunting for 3rd-party whitelisted CSP bypasses and go straight to inline scripts / event handlers.
075
Reposted by renniepak
Gareth Heyes @garethheyes.co.uk · 16/12/2025
Bypass CSP in a single click using my new Custom Action, powered by @renniepak.nl's excellent CSP bypass project.
1137
renniepak @renniepak.nl · 05/12/2025
It depends. Might want to checkout @intigriti.com latest blog.
010
renniepak @renniepak.nl · 01/12/2025
Thanks for mentioning our site cspbypass.com
cspbypass.com
CSP Bypass Search
A tool designed to help ethical hackers bypass restrictive Content Security Policies
240
renniepak @renniepak.nl · 29/11/2025
we at cspbypass.com recommend cspbypass.com
040
renniepak @renniepak.nl · 27/10/2025
I was naive and deleted it myself. Someone else claimed it.
100
Reposted by renniepak
0xacb @0xacb.com · 21/10/2025
Found an XSS but got blocked by the CSP? cspbypass.com has a compiled list of ways to bypass the Content-Security Policy. Check out the video below 👇
286
Reposted by renniepak
Gareth Heyes @garethheyes.co.uk · 26/09/2025
In a shameless effort to promote my book. I've crafted some very special vectors for you. If you like them please purchase my book to read more. www.amazon.com/dp/B0BRD9B3GS
https://www.amazon.com/dp/B0BRD9B3GS
0133
renniepak @renniepak.nl · 06/09/2025
I was unaware of coding music to begin with. So I guess I'll check out sonicpi as well. :)
010
renniepak @renniepak.nl · 06/09/2025
Been playing around with strudel.cc recently. It is pretty awesome! strudel.cc#Ly9Td2VldCBE...
strudel.cc
Strudel REPL
Strudel is a music live coding environment for the browser, porting the TidalCycles pattern language to JavaScript.
100
Reposted by renniepak
Marko Bevc @marko.social · 02/09/2025
Great interview with @racheltobac.bsky.social shining a light in a lot of important topics, like what are likely attack vectors, impact of #AI on #security, #ethics, affecting social interactions and #privacy . "Be politely paranoid." 👏 www.youtube.com/watch?v=xEdZ...
youtube.com
Social Engineer: YOU are Easier to Hack than your Computer
YouTube video by Scammer Payback
3126
renniepak @renniepak.nl · 27/08/2025
Coded some PHP today without using ChatGPT, like a mad man.
060
Reposted by renniepak
0xacb @0xacb.com · 26/08/2025
Time to reveal what I was doing with @teknogeek.io back in '19. All the hard work and sleepless nights have paid off!
0133
renniepak @renniepak.nl · 25/08/2025
Just finished a major UI overhaul of CSPBypass.com and would love your feedback. Excited to welcome ProjectDiscovery as our first sponsor. Huge thanks to their team for supporting the project and recognizing its value to the community.
cspbypass.com
CSP Bypass Search
A tool designed to help ethical hackers bypass restrictive Content Security Policies
030
renniepak @renniepak.nl · 24/08/2025
I enabled sponsorships on Github for cspbypass.com. The main goal is to cover hosting fees etc. So if you want to support my work, I would highly appreciate it if you could become a sponsor. github.com/sponsors/ren... Thanks!
cspbypass.com
CSP Bypass Search
A tool designed to help ethical hackers bypass restrictive Content Security Policies
021
renniepak @renniepak.nl · 21/08/2025
Forgot how to bug bounty.
121
renniepak @renniepak.nl · 17/07/2025
LOL. almost 3 years after reporting it and it being fixed, I got assigned a CVE for a vuln I found 🙃 nvd.nist.gov/vuln/detail/...
nvd.nist.gov
NVD - CVE-2025-53836
160
renniepak @renniepak.nl · 26/06/2025
That's awesome! Congrats!
020
Reposted by renniepak
Gareth Heyes @garethheyes.co.uk · 20/06/2025
Made hacking rooms work in real time. This demo connects three browsers with real time editing on. From Chrome I edit some HTML. This gets sent over websockets to the other browsers which call postMessage to a blob with a sandboxed iframe.
053
renniepak @renniepak.nl · 19/06/2025
😍
080
renniepak @renniepak.nl · 14/06/2025
I have no clue any more. I have stored XSS on a specific subdomain, I have another subdomain that reflects all cookies (also http only), I can register my own OAuth clients somewhere else. But uh, I dunno. Stuff.
000
renniepak @renniepak.nl · 12/06/2025
I feel like I have all the pieces to a ATO chain. I just have no idea what the chain would be...
140
renniepak @renniepak.nl · 11/06/2025
I thought he would. That dude is awesome.
100
renniepak @renniepak.nl · 10/06/2025
I think @mrtuxracer.bsky.social already does this kind of stuff as part of his bug bounty. Not cloud though.
110
renniepak @renniepak.nl · 10/06/2025
No, the conference took place quite a while ago. This is my website, and the slides will remain available here.
010
Reposted by renniepak
Gareth Heyes @garethheyes.co.uk · 09/06/2025
Epic Firefox XSS vectors by Masato Kinugawa. Now available on our XSS cheat sheet including variants found by me. Link to vectors👇 portswigger.net/web-security...
<object data=# codebase=javascript:alert(document.domain)//>
<embed src=# codebase=javascript:alert(document.domain)//>
<object data="#
alert(1)" codebase=javascript://>
<embed src="#!
alert(1)" codebase=javascript:>
0114
renniepak @renniepak.nl · 07/06/2025
🏳️‍🌈
040
renniepak @renniepak.nl · 06/06/2025
What are the benefits?
100
renniepak @renniepak.nl · 06/06/2025
You can checkout all the slides/examples here: 0-a.nl/nahamcon/ I don't have a blog (about WAF bypasses).
0-a.nl
Widgets Gone Wild - Title Slide
110
renniepak @renniepak.nl · 05/06/2025
K-9 = Canine. 🤯
030
renniepak @renniepak.nl · 04/06/2025
100%!
020
Reposted by renniepak
Gareth Heyes @garethheyes.co.uk · 04/06/2025
Abuse EvalError, onpageswap, and setTimeout to get JS execution without parens. @0x999.net redirects the page to trigger onpageswap, hijacks the thrown error, and turns it into code. Inspired by @terjanq.me. Now available on the XSS cheat sheet. Link to vector👇 portswigger.net/web-security...
<script>
onpageswap=setTimeout;
location='x';
Event.prototype.toString=EvalError.prototype.toString;
Event.prototype.name='alert\x281\x29'
</script>
0134
renniepak @renniepak.nl · 26/05/2025
Such a DOM XSS tease: var s=document.createElement('style');s.innerHTML=decodeURIComponent(location.hash.slice(1));document.head.appendChild(s)
120
renniepak @renniepak.nl · 25/05/2025
In this type of XSS I mostly find arbitrary redirects (to javascript URI) or including a user supplied url for script src.
010
renniepak @renniepak.nl · 25/05/2025
Sorry, to comment on your blog you linked: That's like 80% of my bug bounty income still these days. I guess nothing changed over the past 6 years :)
110