Sign in

sshell

@sshell.co
1.5K followers 224 following 61 posts

propane and propane accessories ai + security research ccdc red team

PostsRepliesMedia
sshell @sshell.co · 04/03/2026
checking in to let everyone know that i am still using a computer
160
Reposted by sshell
netspooky @vacci.ne · 11/10/2025
The Sixth Annual Binary Golf Grand Prix #BGGP6 will start Friday 10/17!!! @binary.golf Fall/Winter 2025
media.tenor.com
a group of cartoon characters are dancing together in a park .
ALT: a group of cartoon characters are dancing together in a park .
11711
Reposted by sshell
remy 🐀 @remyhax.bsky.social · 07/08/2025
Every year there’s some discourse around how safe/unsafe it is to scan QR codes at BlackHat and DefCon. Last year, I set out to enumerate the scope, and did! And then promptly forgot for a year. QR codes you shouldn’t have scanned last year; this year. remyhax.xyz/posts/no-sca...
remyhax.xyz
QR Codes You Shouldn't Scan
Number 3 may surprise you! I’m kidding of course, blatant web-based phishing attacks are boring. This blog isn’t about those. Most of these examples will probably surprise you in some way. This blog i...
0248
sshell @sshell.co · 03/08/2025
i am very excited to see all of my friends in las vegas, nevada
040
sshell @sshell.co · 27/07/2025
New blog post about all the fun I had red teaming at @NationalCCDC this year! Covers some of the fun we had this year specifically relating to the web side of things, as well as some tips and resources for competitors & those interested in participating www.sshell.co/red-teaming-...
sshell.co
Red Teaming at National CCDC 2025
There's nothing quite like the feeling of playing Doom on someone's hypervisor and watching as they frantically try to figure out how to eject you from the system.
141
Reposted by sshell
yung intranet @bane.at.haunted.computer · 01/07/2025
As of this morning I am unemployed. I am looking for work! I have a range of experience that can be valuable to the right team. A short list of relevant skills that I'd call out: reverse engineering & vuln research, DFIR, project management, infrastructure architecting, system administration.
26130
sshell @sshell.co · 01/06/2025
what do you mean “stuck at 50% done saving a bookmark?” you completed one half of one api call? i hate it here.
screenshot of an app saving a bookmark, but being stuck at 50%
240
Reposted by sshell
Phrack Zine @phrack.org · 17/03/2025
We heard you needed some more time, so we wanted to let you cook. We decided to push the Phrack 72 CFP deadline back until June 15th. Stay tuned for upcoming Phrack events. Print this flyer out and give it to someone IRL!!
Flyer for the Phrack 40th anniversary edition CFP. It contains the text of the CFP at phrack.org, with additional text "CFP EXTEND!! Papers due June 15 2025" and "Phrack Since 1985"
110950
sshell @sshell.co · 18/02/2025
Report government waste to DOGE: - Every Electron app wastes hundreds of MB of disk space (and RAM) by bundling it's own Chrome browser. Make native UI great again! - Every Go binary is too large. What are they hiding in there? - Windows installs 500+ language packs. In the US we only use en-US!
020
sshell @sshell.co · 09/02/2025
i wish there was a very serious medical drama where everything was normal EXCEPT every patient was played by the same actor, and it was never brought up or addressed in any way.
030
Reposted by sshell
d0nut @d0nut.dev · 07/02/2025
Got an MRI recently and @sshell.co immediately turned it into a banger
0525
sshell @sshell.co · 24/01/2025
i tried openai operator and got jumpscared because i forgot how terrible it was to rawdog the internet without an ad-blocker.
040
Reposted by sshell
cts @gf256.bsky.social · 11/01/2025
Many YouTube videos lately are clickbait and stretch out a Wikipedia page into 30 minutes. Many videos are just questions with simple answers. So I built tldw.tube: put in the URL and save your time! (No hate on Veritasium, it just happened to work well for the screenshot)
96017
sshell @sshell.co · 10/01/2025
i am attendee at the local shmoo conference today. i can’t wait to talk about the latest developments in shmoo technology.
240
sshell @sshell.co · 19/12/2024
Took an existing open-source tool that 105 seconds to run on default settings out of the box. Had Cursor rewrite it in a more performant language with only functionality I needed, and tuned for performance on my specific setup. Kept prompting it to further optimize and...
run times starting at 12 seconds, decreasing down to 2.2 seconds over 5 runs
140
Reposted by sshell
Phrack Zine @phrack.org · 16/12/2024
We updated our CFP for Phrack 72! The deadline is now April 1st 2025. Check the site for specifics on how to contribute, as well as some inspiration! We also posted a link to purchase physical copies of Phrack 71, and a donation link too. Enjoy! phrack.org
screenshot of the CFP on phrack.org
411658
sshell @sshell.co · 14/12/2024
the best part about december is watching “jingle all the way” at least 7 times
media.tenor.com
a man talking on a phone with the words put that cookie down on the bottom
Alt: a man talking on a phone with the words put that cookie down on the bottom
010
Reposted by sshell
Justin Gardner @rhynorater.bsky.social · 06/12/2024
Yo, new big thing: Shift. AI seamlessly integrated into your HTTP proxy. Use cases: "Take this JS and build the JSON request body" "Fill in these IDs from my notes - UserA" "Create a match and replace rule to turn on this feature flag" "Generate a wordlist with all HTTP Verbs"
1115
Reposted by sshell
netspooky @vacci.ne · 03/12/2024
Me reverse engineering: Haha fuck yeah!!! Yes!! Me engineering: Well this fucking sucks. What the fuck.
448197
sshell @sshell.co · 30/11/2024
who are some of your favorite hackers and companies working with AI for offensive security right now?
210
Reposted by sshell
harisec @harisec.bsky.social · 26/11/2024
I've released 'brainstorm': an alternative way to do web fuzzing combining my fav fuzzing tool 'ffuf' (from @joohoi.bsky.social )with local LLMs (via Ollama API) to generate smarter filename tests. It usually finds more endpoints with fewer requests. Added a IIS shortname support @irsdl.bsky.social
5389
sshell @sshell.co · 26/11/2024
bro, i’m sitting down to watch jonbenet docuseries and the music was done by THE SYSTEM OF A DOWN GUY?!
music by system of a down guy creditmeme of the System of a Down guy burnt into a tv
160
sshell @sshell.co · 26/11/2024
went outside today and we’re off to a bad start already
one of my stupid fucking airpods is dead and the other one is fully charged
070
Reposted by sshell
Nicolas Grégoire @agarri.fr · 24/11/2024
I’ve to say that I’m impressed by how @xbow.com managed to identify this SSRF vulnerability (and bypass a MIME filter on its way) 🤖
xbow.com
XBOW – SSRF & URI validation bypass in 2FAuth
XBOW discovered a Server-Side Request Forgery (SSRF) vulnerability in the OTP preview feature of the open-source project, 2FAuth.
21713
Reposted by sshell
jstnkndy @jstnkndy.bsky.social · 25/11/2024
I took this training last year, after using burp for as many years as I can remember, and I still learned a lot. I still use some of the tips I learned daily and it's made me faster. Highly recommend.
093
Reposted by sshell
James Kettle @jameskettle.com · 25/11/2024
Custom lists are super cool! I enjoy reading social posts, but want to make sure I never miss a quality writeup or technique. To achieve this, I'm building a 'high signal web security' list of topic-focused accounts, which you can pin next to 'Following' if you want :) bsky.app/profile/jame...
25416
sshell @sshell.co · 24/11/2024
sometimes i use gemini pro and then immediately remember why i wasn't using gemini pro
140
Reposted by sshell
eve6 @eve6.bsky.social · 24/11/2024
Get back to your roots. Remember why you started posting in the first place: because you have a disease
311468220
Reposted by sshell
netspooky @vacci.ne · 19/11/2024
I'm not an attacker, I'm a packet craftsman
61049
sshell @sshell.co · 20/11/2024
going through and saving some old posts that I liked
3380
Reposted by sshell
Hexadecim8 @hexadecim8.com · 19/11/2024
Wow, it’s real! 2 and a half years later, I’m officially a published author with Wiley. If you want to learn how world governments have (and haven’t) cooperated with hackers over the past 40 years, go to my bio and get your copy!
1714426
sshell @sshell.co · 19/11/2024
really loving the ability to use API to find content I’m looking for on bluesky. has anyone gone through the process of creating their own feed yet? (from scratch)
110
sshell @sshell.co · 19/11/2024
i opened it tw*tter, saw a normal post of someone unsure about bluesky, and half the responses were just super aggressively attacking anyone who DARE use another website. definitely glad to be spending more time here. life’s too short for for that toxic garbage.
490
sshell @sshell.co · 18/11/2024
this is one of my favorite videos. tom does a great job at demonstrating how powerful it is to have a deep knowledge of your tools and how you can create super efficient workflows with a number of relatively simple concepts
020
Reposted by sshell
James Kettle @jameskettle.com · 15/11/2024
This is so true, it's one of the reasons I love running the annual "Top 10 web hacking techniques" even though I'm allergic to clickbait. Being featured means so much to people.
292
Reposted by sshell
TomNomNom @tomnomnom.com · 14/11/2024
Just added a whole bunch more people to my Hackers starter pack 🥰 go.bsky.app/NRP3ecE
2012646
sshell @sshell.co · 13/11/2024
watching “fear street: 1994” and getting unreasonably upset that the in the AOL chatroom they were using “calibri regular” font which wasn’t out yet.
screenshot from the movie “fear street part 1: 1994” showing an aol instant messenger conversationscreenshot from wikipedia showing the calibri font was only released in 2007
020
sshell @sshell.co · 12/11/2024
ivanti and citrix critical CVEs dropped today, plus rumors of random PAN-OS RCE floating around
mr bones wild ride, the ride never endspatrick starr, mom come pick me up i’m scared
120
sshell @sshell.co · 12/11/2024
hello pinned post viewers, i am a person who occasionally does security research, ccdc red teaming, lots and lots of recon, tool development, and other random computer shenanigans. thanks for coming to my ted talk
050
sshell @sshell.co · 11/11/2024
someone on my floor bought a trumpet and has proceeded to make it everybody else’s problem
110
sshell @sshell.co · 10/11/2024
had to make a hard choice today between a) trying to fix a printer or b) throwing myself out the window of a 7 story building
000
sshell @sshell.co · 10/11/2024
you can always tell how interested i am in something by how much math i’m willing to endure learning because of it
000
sshell @sshell.co · 09/11/2024
after a thorough investigation, i am releasing a list of people who i believe are using/have used a computer go.bsky.app/S9yXrn7
140
sshell @sshell.co · 09/11/2024
still still gaming
010
sshell @sshell.co · 02/07/2023
still gaming
210
sshell @sshell.co · 01/05/2023
gaming
020