Reposted by sshellnetspooky @vacci.ne · 11/10/2025The Sixth Annual Binary Golf Grand Prix #BGGP6 will start Friday 10/17!!! @binary.golf Fall/Winter 2025media.tenor.coma group of cartoon characters are dancing together in a park .ALT: a group of cartoon characters are dancing together in a park . 11711
Reposted by sshellremy 🐀 @remyhax.bsky.social · 07/08/2025Every year there’s some discourse around how safe/unsafe it is to scan QR codes at BlackHat and DefCon. Last year, I set out to enumerate the scope, and did! And then promptly forgot for a year. QR codes you shouldn’t have scanned last year; this year. remyhax.xyz/posts/no-sca...remyhax.xyzQR Codes You Shouldn't ScanNumber 3 may surprise you! I’m kidding of course, blatant web-based phishing attacks are boring. This blog isn’t about those. Most of these examples will probably surprise you in some way. This blog i... 0248
sshell @sshell.co · 27/07/2025New blog post about all the fun I had red teaming at @NationalCCDC this year! Covers some of the fun we had this year specifically relating to the web side of things, as well as some tips and resources for competitors & those interested in participating www.sshell.co/red-teaming-...sshell.coRed Teaming at National CCDC 2025There's nothing quite like the feeling of playing Doom on someone's hypervisor and watching as they frantically try to figure out how to eject you from the system. 141
Reposted by sshellyung intranet @bane.at.haunted.computer · 01/07/2025As of this morning I am unemployed. I am looking for work! I have a range of experience that can be valuable to the right team. A short list of relevant skills that I'd call out: reverse engineering & vuln research, DFIR, project management, infrastructure architecting, system administration. 26130
sshell @sshell.co · 01/06/2025what do you mean “stuck at 50% done saving a bookmark?” you completed one half of one api call? i hate it here. 240
Reposted by sshellPhrack Zine @phrack.org · 17/03/2025We heard you needed some more time, so we wanted to let you cook. We decided to push the Phrack 72 CFP deadline back until June 15th. Stay tuned for upcoming Phrack events. Print this flyer out and give it to someone IRL!! 110950
sshell @sshell.co · 18/02/2025Report government waste to DOGE: - Every Electron app wastes hundreds of MB of disk space (and RAM) by bundling it's own Chrome browser. Make native UI great again! - Every Go binary is too large. What are they hiding in there? - Windows installs 500+ language packs. In the US we only use en-US! 020
sshell @sshell.co · 09/02/2025i wish there was a very serious medical drama where everything was normal EXCEPT every patient was played by the same actor, and it was never brought up or addressed in any way. 030
Reposted by sshelld0nut @d0nut.dev · 07/02/2025Got an MRI recently and @sshell.co immediately turned it into a banger 0525
sshell @sshell.co · 24/01/2025i tried openai operator and got jumpscared because i forgot how terrible it was to rawdog the internet without an ad-blocker. 040
Reposted by sshellcts @gf256.bsky.social · 11/01/2025Many YouTube videos lately are clickbait and stretch out a Wikipedia page into 30 minutes. Many videos are just questions with simple answers. So I built tldw.tube: put in the URL and save your time! (No hate on Veritasium, it just happened to work well for the screenshot) 96017
sshell @sshell.co · 10/01/2025i am attendee at the local shmoo conference today. i can’t wait to talk about the latest developments in shmoo technology. 240
sshell @sshell.co · 19/12/2024Took an existing open-source tool that 105 seconds to run on default settings out of the box. Had Cursor rewrite it in a more performant language with only functionality I needed, and tuned for performance on my specific setup. Kept prompting it to further optimize and... 140
Reposted by sshellPhrack Zine @phrack.org · 16/12/2024We updated our CFP for Phrack 72! The deadline is now April 1st 2025. Check the site for specifics on how to contribute, as well as some inspiration! We also posted a link to purchase physical copies of Phrack 71, and a donation link too. Enjoy! phrack.org 411658
sshell @sshell.co · 14/12/2024the best part about december is watching “jingle all the way” at least 7 timesmedia.tenor.coma man talking on a phone with the words put that cookie down on the bottomAlt: a man talking on a phone with the words put that cookie down on the bottom 010
Reposted by sshellJustin Gardner @rhynorater.bsky.social · 06/12/2024Yo, new big thing: Shift. AI seamlessly integrated into your HTTP proxy. Use cases: "Take this JS and build the JSON request body" "Fill in these IDs from my notes - UserA" "Create a match and replace rule to turn on this feature flag" "Generate a wordlist with all HTTP Verbs" 1115
Reposted by sshellnetspooky @vacci.ne · 03/12/2024Me reverse engineering: Haha fuck yeah!!! Yes!! Me engineering: Well this fucking sucks. What the fuck. 448197
sshell @sshell.co · 30/11/2024who are some of your favorite hackers and companies working with AI for offensive security right now? 210
Reposted by sshellharisec @harisec.bsky.social · 26/11/2024I've released 'brainstorm': an alternative way to do web fuzzing combining my fav fuzzing tool 'ffuf' (from @joohoi.bsky.social )with local LLMs (via Ollama API) to generate smarter filename tests. It usually finds more endpoints with fewer requests. Added a IIS shortname support @irsdl.bsky.social 5389
sshell @sshell.co · 26/11/2024bro, i’m sitting down to watch jonbenet docuseries and the music was done by THE SYSTEM OF A DOWN GUY?! 160
Reposted by sshellNicolas Grégoire @agarri.fr · 24/11/2024I’ve to say that I’m impressed by how @xbow.com managed to identify this SSRF vulnerability (and bypass a MIME filter on its way) 🤖xbow.comXBOW – SSRF & URI validation bypass in 2FAuthXBOW discovered a Server-Side Request Forgery (SSRF) vulnerability in the OTP preview feature of the open-source project, 2FAuth. 21713
Reposted by sshelljstnkndy @jstnkndy.bsky.social · 25/11/2024I took this training last year, after using burp for as many years as I can remember, and I still learned a lot. I still use some of the tips I learned daily and it's made me faster. Highly recommend. 093
Reposted by sshellJames Kettle @jameskettle.com · 25/11/2024Custom lists are super cool! I enjoy reading social posts, but want to make sure I never miss a quality writeup or technique. To achieve this, I'm building a 'high signal web security' list of topic-focused accounts, which you can pin next to 'Following' if you want :) bsky.app/profile/jame... 25416
sshell @sshell.co · 24/11/2024sometimes i use gemini pro and then immediately remember why i wasn't using gemini pro 140
Reposted by sshelleve6 @eve6.bsky.social · 24/11/2024Get back to your roots. Remember why you started posting in the first place: because you have a disease 311468220
Reposted by sshellHexadecim8 @hexadecim8.com · 19/11/2024Wow, it’s real! 2 and a half years later, I’m officially a published author with Wiley. If you want to learn how world governments have (and haven’t) cooperated with hackers over the past 40 years, go to my bio and get your copy! 1714426
sshell @sshell.co · 19/11/2024really loving the ability to use API to find content I’m looking for on bluesky. has anyone gone through the process of creating their own feed yet? (from scratch) 110
sshell @sshell.co · 19/11/2024i opened it tw*tter, saw a normal post of someone unsure about bluesky, and half the responses were just super aggressively attacking anyone who DARE use another website. definitely glad to be spending more time here. life’s too short for for that toxic garbage. 490
sshell @sshell.co · 18/11/2024this is one of my favorite videos. tom does a great job at demonstrating how powerful it is to have a deep knowledge of your tools and how you can create super efficient workflows with a number of relatively simple concepts 020
Reposted by sshellJames Kettle @jameskettle.com · 15/11/2024This is so true, it's one of the reasons I love running the annual "Top 10 web hacking techniques" even though I'm allergic to clickbait. Being featured means so much to people. 292
Reposted by sshellTomNomNom @tomnomnom.com · 14/11/2024Just added a whole bunch more people to my Hackers starter pack 🥰 go.bsky.app/NRP3ecE 2012646
sshell @sshell.co · 13/11/2024watching “fear street: 1994” and getting unreasonably upset that the in the AOL chatroom they were using “calibri regular” font which wasn’t out yet. 020
sshell @sshell.co · 12/11/2024ivanti and citrix critical CVEs dropped today, plus rumors of random PAN-OS RCE floating around 120
sshell @sshell.co · 12/11/2024hello pinned post viewers, i am a person who occasionally does security research, ccdc red teaming, lots and lots of recon, tool development, and other random computer shenanigans. thanks for coming to my ted talk 050
sshell @sshell.co · 11/11/2024someone on my floor bought a trumpet and has proceeded to make it everybody else’s problem 110
sshell @sshell.co · 10/11/2024had to make a hard choice today between a) trying to fix a printer or b) throwing myself out the window of a 7 story building 000
sshell @sshell.co · 10/11/2024you can always tell how interested i am in something by how much math i’m willing to endure learning because of it 000
sshell @sshell.co · 09/11/2024after a thorough investigation, i am releasing a list of people who i believe are using/have used a computer go.bsky.app/S9yXrn7 140