Sign in

smaury

@smaury.bsky.social
963 followers 323 following 54 posts

Co-Founder @shielder.com CTF Player jbz.team Cliff Jumping Lover (23mt max so far)

PostsRepliesMedia
Reposted by smaury
Shielder @shielder.com · 01/07/2026
With @ostifofficial.bsky.social and @sovereign.tech we audited @symfony.com YAML, the library bundled in that PHP framework that all your friends probably run somewhere in their stack. If that's true, please update and read the attached blogpost to find out if you're affected! Links ⏬
144
Reposted by smaury
BobDaHacker 🏳️‍⚧️ (she/her) @bobdahacker.com · 16/06/2026
⚽ I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID. Registered on FIFA's public Agent Platform, accessed RTMP stream keys for every live World Cup 2026 camera feed. An attacker could've replaced live TV worldwide. bobdahacker.com/blog/fifa-hack #InfoSec #FIFA #WorldCup
bobdahacker.com
I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
How I found that anyone could register on FIFA's public Agent Platform, gain access to the Football Data Platform's Streaming Management panel, and get RTMP ingest URLs and stream keys for every live ...
126528
smaury @smaury.bsky.social · 27/05/2026
Slides for my WarCon talk ✅ See y'all in Warsaw 👀 Spoiler ⏬ youtu.be/LWGJA9i18Co?...
youtu.be
OK Go - Upside Down & Inside Out
YouTube video by OKGoVEVO
010
Reposted by smaury
Shielder @shielder.com · 30/04/2026
Can a hostile container sneak past your eBPF tracing? Sometimes, yes. With @ostifofficial.bsky.social & @cncf.io we audited Inspektor Gadget - 3 vulns (fixed), 6 hardenings, 6 bypasses (io_uring, openat2, jumbo frames…). Work by ndaprela & @suidpit.sh👏 🔗 www.shielder.com/blog/2026/04...
shielder.com
Shielder - Inspektor Gadget Security Audit
Security audit of Inspektor Gadget, an eBPF-based observability framework for Linux and Kubernetes. Sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Imp...
097
smaury @smaury.bsky.social · 05/04/2026
The guys on IRC told me I needed special hardware for a smurf attack. Am I doing this right?
020
smaury @smaury.bsky.social · 24/03/2026
Worst response you can get in 2026: Your are right, ...
000
smaury @smaury.bsky.social · 24/03/2026
Can't wait to see the final report going public!
000
smaury @smaury.bsky.social · 11/03/2026
Claude skill issue
000
Reposted by smaury
Shielder @shielder.com · 31/01/2026
Love breaking things just to see how they work? 🐛🔨 ​A @shielder.com delegation is on the ground at @fosdem.org, and we're looking for fellow hackers and security researchers. ​If you are passionate about securing the Open Source world, we definitely need to talk!
033
Reposted by smaury
Shielder @shielder.com · 31/12/2025
Happy New Year, Hackers! 🎆 We’re looking forward to a 2026 full of crazy exploits, instant patches, and - most importantly - YOU, the amazing human beings behind the screens.
021
smaury @smaury.bsky.social · 09/12/2025
What's the Bobby Tables equivalent in #AI era?
120
smaury @smaury.bsky.social · 01/12/2025
Join us tomorrow to learn more about this cool audit!
000
Reposted by smaury
Shielder @shielder.com · 25/11/2025
Want to learn more about our approach into auditing complex libraries and writing cool exploits? 🗓️: Dec 02 🕗: 20:00 CET RSVP: luma.com/ostif-meetup...
luma.com
OSTIF Meetups · Events Calendar
View and subscribe to events from OSTIF Meetups on Luma.
023
smaury @smaury.bsky.social · 07/08/2025
👋🏿 Hackers! Are you a Red Teaming Wizard 🧙🏿 looking for a new challenge? @shielder.com is hiring a Red Teaming Lead to join our crew! More info ⬇️ (share appreciated) #hiring #redteaming romhack.io/job-opportun...
romhack.io
RomHack - Job opportunities
Check for RomHack sponsor's job opportunities
023
smaury @smaury.bsky.social · 31/07/2025
Working with folks from @lucasfilm.bsky.social, @ilmvfx.bsky.social, and Apple to secure some of the OSS foundations the movie and entertainment industries rely on was so cool! Big shout-out 📣 to the @ostifofficial.bsky.social and ASWF for making this possible.
041
Reposted by smaury
TumpiCon @tumpicon.org · 25/06/2025
The TumpiCon experience will start tomorrow! Can't wait to meet y'all in Pinerolo 🏞️ Schedule is out: tumpicon.org
172
smaury @smaury.bsky.social · 23/05/2025
Woah - thanks Nestlè and @intigriti.com!
060
smaury @smaury.bsky.social · 20/05/2025
It's so cool working with the GoogleVRP team - folks over there are amazing. I love the concept of "you report something, then we work together with you to escalate it as much as possible". High bounties are also a nice addendum :) #BugBounty #bugbountytips
270
smaury @smaury.bsky.social · 27/04/2025
Romhack is coming up and the CfP is still open! Got novel research you’d love to present in front of an eager audience, with the stunning Roman landscape as your backdrop, and on the same stage where @jameskettle.com will deliver the keynote? Submit now! cfp.romhack.io/romhack-2025/
cfp.romhack.io
RomHack Conference 2025
Schedule, talks and talk submissions for RomHack Conference 2025
021
Reposted by smaury
ostifofficial.bsky.social @ostifofficial.bsky.social · 10/04/2025
We are so excited to announce the publication of our audit of PHP core! This work was made possible through a collaboration between OSTIF, @thephpf.bsky.social, and @quarkslab.bsky.social with funding provided by @sovereign.tech. For the report and further links, check out ostif.org/php-audit-co...
053
smaury @smaury.bsky.social · 10/04/2025
Is there a way I can wipe this from my brain? Jim Carrey any recommendations? mobapc.it/prodotto/sha...
020
Reposted by smaury
TumpiCon @tumpicon.org · 09/04/2025
Just published some talks on tumpicon.org Wanna join us? Follow the trail 🥾
063
Reposted by smaury
Shielder @shielder.com · 07/04/2025
Last week Apple released MacOS 13.4 which contains a fix for a vulnerability @suidpit.bsky.social exploited to escape the Sandbox. Update now and stay tuned for the technical details! Ref: support.apple.com/en-us/122373
095
smaury @smaury.bsky.social · 03/04/2025
Woah -- more Google Chrome VRP swag in my mailbox today! Wondering how to get some yourself? Find vulnerabilities in Chrome! More info here: bughunters.google.com/about/rules/...
031
smaury @smaury.bsky.social · 18/03/2025
One of my old Google VRP reports just went public -- check it out if you want to see an example of CEF exploitation. bughunters.google.com/reports/vrp/...
bughunters.google.com
CEF Debugger Enabled in Google Web Designer | Google Bug Hunters
Found a security vulnerability? Discover our forms for reporting security issues to Google: for the standard VRP, Google Play, and Play Data Abuse.
081
Reposted by smaury
ostifofficial.bsky.social @ostifofficial.bsky.social · 17/03/2025
Our next meetup is a presentation from our friends at X41 D-Sec GmbH. Join us next Wednesday, March 26th, at 14:00 CDT for a presentation and discussion with Markus Vervier and Eric Sesterhenn on their audit of @mullvad.bsky.social. We can't wait for this one! RSVP at lu.ma/wreregye
lu.ma
Security Code Audit of Mullvad VPN · Zoom · Luma
Join us for a presentation and meetup with Markus Vervier and Eric Sesterhenn of X41 D-Sec GmbH around their company's audit of Mullvad VPN. Markus Vervier is…
033
Reposted by smaury
Osservatorio Nessuno OdV @osservatorionessuno.org · 17/03/2025
We recently analyzed the latest Cellebrite device support matrix published in February 2025. The reality is worrisome. It can be used to unlock most of the mobile devices we use every day. Read our report: (ENG) osservatorionessuno.org/blog/2025/03... (ITA) osservatorionessuno.org/it/blog/2025...
osservatorionessuno.org
A deep dive into Cellebrite: Android support as of February 2025
A deep dive into Cellebrite: Android support as of February 2025
067
smaury @smaury.bsky.social · 13/03/2025
Swag day -- thanks ChromeVRP and @amyre.bsky.social
170
Reposted by smaury
Shielder @shielder.com · 13/03/2025
In Lausanne for @1ns0mn1h4ck.bsky.social? Don’t miss the chance to meet our very own @not4nhacker.bsky.social! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while!
075
Reposted by smaury
TumpiCon @tumpicon.org · 06/02/2025
Hey hackers! We’ve started sending out the first invites — check your inbox! 👀 Didn’t get one? Take the fast track and submit a talk!
1117
smaury @smaury.bsky.social · 07/03/2025
tmux and chill
120
smaury @smaury.bsky.social · 06/02/2025
🗣️
020
smaury @smaury.bsky.social · 01/02/2025
On my way to @fosdem.bsky.social! If you are into securing open source code then we should definitely have a chat -- looking forward to meeting y'all!
000
Reposted by smaury
Gareth Heyes @garethheyes.co.uk · 28/01/2025
Discover blocklist bypasses via unicode overflows using the latest updates to ActiveScan++, Hackvertor & Shazzer! Thanks to Ryan Barnett and Neh Patel for sharing this technique. portswigger.net/research/byp...
GET /%0D%0ASet-Cookie: foo=bar
403 Forbidden

GET /%E4%BC%8D%E4%BC%8ASet-Cookie: foo=bar
200 OK
Set-Cookie: foo=bar
03822
Reposted by smaury
Shielder @shielder.com · 16/01/2025
🚨 New Open Source Audit Alert! 🚨 Shielder, with @ostifofficial.bsky.social & @cncf.io, audited karmada-io: 🔍 6 issues found (1 high, 1 medium, 2 low, 2 info) ✔️ Most fixed, others planned. 🗣️ to @suidpit.bsky.social and @thezero.org Full details in the blog post! www.shielder.com/blog/2025/01...
shielder.com
Shielder - Karmada Security Audit
Karmada Security Audit, sponsored by the CNCF (Cloud Native Computing Foundation), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
065
smaury @smaury.bsky.social · 16/01/2025
Love when we can publish the results of our effort!
020
Reposted by smaury
TumpiCon @tumpicon.org · 12/01/2025
The second edition of TumpiCon is here! 📅 June 27-28, 2025 📍 Somewhere near Turin, Italy 🔒 Invite-only No flashy stages. No fluff. Just raw, technical, and unfiltered hacking. More details? If you know, you know. Follow the trail: tumpicon.org
165
smaury @smaury.bsky.social · 12/01/2025
Looking for a chill, invite-only, and uncensored conference? Then you are in the right place :)
030
Reposted by smaury
Mastering Burp Suite @mastering-burp.agarri.fr · 20/12/2024
Ever wondered why you NEVER see chunked responses in Burp? 🤔 The answer is simple, default settings hide them! 🫣 Go to "Settings > Network > HTTP > Streaming responses" to make them appear 🔍
Screenshot of Burp's HTTP settings, where streaming URLs must be definedChunked response as seen in Repeater, with chunk metadata (their size) not stripped
0206
Reposted by smaury
Freddy @freddyb.bsky.social · 20/12/2024
I have discount codes for *annuals plans* of Mozilla VPN, Firefox Relay Premium Email Masking and Monitor Plus (US only). Message me in private. Happy to hook you up, if we know each other :) #ad
011
Reposted by smaury
Jorian @jorianwoltjer.com · 19/12/2024
Have you tried my december XSS challenge? The solution's public now in this writeup! It includes two vulnerabilities in CodeIgniter that abuse the cache storage format and bypass its builtin XSS filter. Merry Christmas! 🎄
051
Reposted by smaury
Johan Carlsson @joaxcar.bsky.social · 18/12/2024
⚠️Challenge time again⚠️ It is based on a real-world situation. Use the HTML injection to leak the flag to an external domain ☃️ This time, send solutions in DM; we don't want to spoil the fun. I also might want to patch any obvious blunder I made creating it joaxcar.com/xss/outer.ht...
2185
Reposted by smaury
Gareth Heyes @garethheyes.co.uk · 19/12/2024
TIL: Array.fromAsync([1],alert)
0125
Reposted by smaury
renniepak @renniepak.nl · 16/12/2024
Some cool new additions on cspbypass.com for skype.[com] and x.[com]/ twitter.[com]
cspbypass.com
CSP Bypass Search
A tool designed to help ethical hackers bypass restrictive Content Security Policies
0142
Reposted by smaury
s1r1us | Mohan Sri Rama Krishna Pedhapati @mohansrk.bsky.social · 14/12/2024
Imagine opening a Discord message and suddenly your computer is hacked. We discovered a bug that made this possible and earned a $5,000 bounty for it. Here's the story and a beginner-friendly deep dive into V8 exploit development. watch: youtu.be/R3SE4VKj678?...
youtu.be
Hacking Discord for $5000 Bounty
YouTube video by Mrgavyadha
1188
Reposted by smaury
Matthew Green @matthewdgreen.bsky.social · 13/12/2024
You wake up. It’s 2013. Some language platform has chosen to use an insecure algorithm for its random() function, and HN is blaming the numerous security flaws that resulted from this decision on individual software developers. www.zellic.io/blog/proton-...
zellic.io
Far From Random: Three Mistakes From Dart/Flutter's Weak PRNG | Zellic — Research
A look into how an unexpectedly weak PRNG in Dart led to Zellic's discovery of multiple vulnerabilities
2387
Reposted by smaury
ostifofficial.bsky.social @ostifofficial.bsky.social · 13/12/2024
Our 2024 collaboration report with the @cncf.io is available to read at ostif.org/2024-cncf-os...! Learn about our ongoing work managing security audits for CNCF projects, dive into specifics about Notary's second OSTIF audit, and see how funding is spent to improve security.
ostif.org
2024 CNCF/OSTIF Independent Security Audit Impact Report – OSTIF.org
011
Reposted by smaury
daniel:// stenberg:// @daniel.haxx.se · 11/12/2024
Welcome to #curl 8.11.1 daniel.haxx.se/blog/2024/12...
daniel.haxx.se
curl 8.11.1
Welcome to another curl release. This time we do a bugfix only release, five weeks since the previous version shipped. Release Presentation https://www.youtube.com/watch?v=9SgOsDr4KDE Numbers the 263r...
0131
Reposted by smaury
shubs @shubs.io · 07/12/2024
This is really great research by @ryotak.net - I appreciated that he covered some of his experiments along the way, and how he landed on a finely tuned way of finding a 12-char hash collision with a command injection payload at the end. flatt.tech/research/pos...
flatt.tech
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt Security Inc. A few days ago, I was upgrading my home lab network, and I decided to upgrade the OpenWrt on my router.1 After ac...
1185