Sign in

STÖK

@stokfredrik.bsky.social
3.3K followers 61 following 94 posts

Hacker / Creative Mischief & GOOD VIBES ONLY

PostsRepliesMedia
Reposted by STÖK
Joo N/A @joohoi.bsky.social · 03/08/2025
Hyped! Our caravan is heading out to #why2025 in just a two short days!
031
STÖK @stokfredrik.bsky.social · 30/07/2025
Pure Scandinavian Darkness presents : - SOUL CAPTURE - Shoot, steal, store offline. @joohoi.bsky.social | @stokfredrik.bsky.social Iconic photosessions coming to @why2025.bsky.social
162
STÖK @stokfredrik.bsky.social · 13/02/2025
echo stok | D i s o b e y
090
STÖK @stokfredrik.bsky.social · 13/02/2025
Got curious bout astrology since its space/planetsstuff, so did my chart, realized I had sun, moon, venus & uranus is Scorpio, googled it and realized I’m actually a loyal creative manipulative magnetic sexual mysterious beast of a psychopath sparkled with drive,anxiety & destruction, who knew..
180
Reposted by STÖK
PortSwigger Research @portswiggerres.bsky.social · 04/02/2025
The results are in! We're proud to announce the Top 10 Web Hacking Techniques of 2024! portswigger.net/research/top...
portswigger.net
Top 10 web hacking techniques of 2024
Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year
26636
Reposted by STÖK
James Kettle @jameskettle.com · 04/02/2025
Congratulations to all the winners! Also massive thanks to the panelists for their help selecting the final ten, it's a time consuming process: @agarri.fr @irsdl.bsky.social @liveoverflow.bsky.social @stokfredrik.bsky.social
091
Reposted by STÖK
James Kettle @jameskettle.com · 23/01/2025
This year two new security legends have joined the top-ten expert panel - @liveoverflow.bsky.social and @stokfredrik.bsky.social! Excited to see what analysis & insights they bring to the top ten alongside long-time contributors @agarri.fr and @irsdl.bsky.social
1405
Reposted by STÖK
James Kettle @jameskettle.com · 21/01/2025
24 hours remaining until voting closes on the Top 10 (new) Web Hacking Techniques of 2024! If you haven't already voted now's the time to do it. portswigger.net/polls/top-10...
portswigger.net
Top 10 web hacking techniques of 2024
Welcome to the community vote for the Top 10 Web Hacking Techniques of 2024.
1116
Reposted by STÖK
Phillip Wylie @phillipwylie.bsky.social · 10/01/2025
My new episode of The Phillip Wylie featuring the fantastic @stokfredrik.bsky.social has dropped early! YouTube: youtu.be/GvevgFED2xM Spotify: open.spotify.com/epi... Apple: podcasts.apple.com/u...
0145
STÖK @stokfredrik.bsky.social · 05/01/2025
What’s the current best cli based tech/stack identification / fingerprinting tooling out there today? Used to love github.com/urbanadventure… are there any newer and better tools?
github.com
170
STÖK @stokfredrik.bsky.social · 03/01/2025
This season I made a promise to myself to level up my game and maximize the amount of ride days.
3110
STÖK @stokfredrik.bsky.social · 01/01/2025
Lost my voice on the second day of ccc, still can’t speak 😂, but I make cute growl sounds. That didn’t stop me from getting my hair braided and all dolled up for new years, and still manage fall asleep before midnight 🤣. But hey woke up fresh to some fresh pow so here’s to a fresh new year! 🏂❄️
0110
Reposted by STÖK
BlockTjej'n crocheting @erlern.bsky.social · 27/12/2024
In a little less than 24hrs i will be talking about counter surveillance for women's shelters and how surveillance state is gonna surveill. Prepare for emotional whiplash :))) #38C3 events.ccc.de/congress/202...
0134
STÖK @stokfredrik.bsky.social · 27/12/2024
Oh! It’s apparently tschunk a’ clock ft @bitquark.io and @joohoi.bsky.social #38c3
1131
STÖK @stokfredrik.bsky.social · 26/12/2024
Pizzas + craft beer * STÖK & JOOHOI . what could go wrong?! #38c3
0100
STÖK @stokfredrik.bsky.social · 26/12/2024
Oof, Im nervous.. Sure Iv traveled to security conferences & present talks on main stages around the world before. But today im doing something different. Im heading to #38c3 as a tourist and since its my first time at congress, if you find me all lost / lurking, say hi ❤️✌️ and show me what’s up!
5312
Reposted by STÖK
Disobey_Fi @disobeyfi.bsky.social · 20/12/2024
Something new in the air? Feels like ...Disobey's programme has been published? Indeed! We are proud to point you towards our pages (which now have practical stuff too) to check on the awesome programme we have for you next Feb! disobey.fi/2025/
disobey.fi
Disobey
Disobey - The Nordic Security Event
0136
Reposted by STÖK
Nicolas Grégoire @agarri.fr · 21/12/2024
The program for @disobeyfi.bsky.social 2025 looks quite good 👍 Too bad, I didn't manage to grab a ticket 😢 Maybe next year... 🍀
151
Reposted by STÖK
Bee 🐝 @securibee.bsky.social · 16/12/2024
🐝 Hive Five 202 - A Bias to Action New terminal on the block: Ghostty, Neovim tutorial series, Docker fundamentals for hackers, and the Four Quarters productivity method. Let's take this week by swarm! Here are this week's Bee's Knees:
111
STÖK @stokfredrik.bsky.social · 15/12/2024
Heavy snowfall outside, watching Beyond Medals - Casino and dreaming about the upcoming snowboard season. ❄️
2190
STÖK @stokfredrik.bsky.social · 12/12/2024
Yes deer, thank you very munch deer,
1170
STÖK @stokfredrik.bsky.social · 10/12/2024
Going to ccc for the first time this year and skipping Blackhat & DEF CON for WHY2025 this summer. Fun times!
2100
STÖK @stokfredrik.bsky.social · 07/12/2024
Saturday vibes, hanging out on the studio building some ikea “lego” while Sara and tårtan plays ps5 and chews on raindeer horn
0110
Reposted by STÖK
Advanced Fuzzing League @aflplusplus.bsky.social · 03/12/2024
We've released #LibAFL 0.14.1 with some important fixes. github.com/AFLplusplus/...
github.com
Release 0.14.1 · AFLplusplus/LibAFL
Highlights LibAFL docs on docs.rs are working again Cmplog regression from 0.14.0 fixed Builds again on latest nightly What's Changed StdMOptMutator::new: remove unused type parameter by @Mrmaxm...
0125
Reposted by STÖK
James Kettle @jameskettle.com · 03/12/2024
I've just rewritten ActiveScan++ in Java to lay the foundation for some major enhancements. It's not in the BApp store yet but if you'd like to take it for a spin you can grab it here: github.com/albinowax/Ac...
github.com
GitHub - albinowax/ActiveScanPlusPlus: ActiveScan++ Burp Suite Plugin
ActiveScan++ Burp Suite Plugin. Contribute to albinowax/ActiveScanPlusPlus development by creating an account on GitHub.
24616
STÖK @stokfredrik.bsky.social · 02/12/2024
Rather spend my day catching bugs than crab, still mad respect to the fishermen of the ”deadliest catch” 👾🦀
090
STÖK @stokfredrik.bsky.social · 01/12/2024
Need some advice. Been planning to buy a tv and a ps5 for my new workspace, i rarely watch tv nor game but I think I want too, but im not sure what to get, is ps5 pro the way to go and what ”sceeen” would be appropriate as the most bang for the buck? I’m Lost in all that oled,qled,uhd,4k,120hz stuff
450
Reposted by STÖK
Gareth Heyes @garethheyes.co.uk · 29/11/2024
Hackvertor BApp edition has been updated to fix two issues 🥳 Removed maximum length limit for custom tags 🐛 Fix JS custom tags when using a newer JRE Grab it while it's 🔥 portswigger.net/bappstore/65...
0244
STÖK @stokfredrik.bsky.social · 29/11/2024
Present the man a CLI in a hotel reception and he will slay it. Let the same man borrow @dmnk.bsky.social Ukulele and the results will be the same. Hats of you talented maddafakka @tomnomnom.com
3263
STÖK @stokfredrik.bsky.social · 28/11/2024
When it’s -10c outside and crispy air, it feels good to be able to get some focused work done in the studio. then commute the 15m from ”work” to ”home” and unwind in front of a warming fire.
5281
Reposted by STÖK
Justin Gardner @rhynorater.bsky.social · 27/11/2024
Alright, new platform so I'm going to start sharing some things that I'm excited about to keep the momentum flowing! Rn, I think the 403 Bypasser Caido plugin from Bebiks is freaking amazing. This is a tool to automate the bypassing of walled-off endpoints. This plugin does 3 things right:
3378
Reposted by STÖK
parzel @parzel.bsky.social · 27/11/2024
I can highly recommend Shazzer from @garethheyes.co.uk, such a great tool for XSS research!
youtube.com
Digging for XSS Gold: Unearthing Browser Quirks with Shazzer
YouTube video by PortSwigger
0224
Reposted by STÖK
TomNomNom @tomnomnom.com · 26/11/2024
Another fun vim thing: if you omit the 'search' part of a search and replace (e.g :%s/search/replace/), it uses the last thing you searched for. Coupled with being able to use * to search for the thing under your cursor can make for quicker replacements :)
3335
Reposted by STÖK
James Kettle @jameskettle.com · 23/11/2024
The "bug bounty hunters and content creators" starter pack is now up to 60 users! Follow this to get instantly connected to the bug bounty community & let me know if I've missed you off! go.bsky.app/GD7hKPX
go.bsky.app
Bug bounty hunters & content creators
Join the conversation
198722
STÖK @stokfredrik.bsky.social · 26/11/2024
Needed a couch. So ”Borrowed” four pallets from a local business, had two unused beds and some angle iron, smashed em together, good enough. Stashed some pillows in a linen bedsheet, tried it out, sweet, then fell asleep on said couch. 🛋️💤
2140
Reposted by STÖK
Bitquark @bitquark.io · 25/11/2024
I've just updated Shortscan to support reading a list of URLs to scan from a file (and included a minor bugfix). Feedback welcome! The latest version is v0.9.2 and can be found on Github: github.com/bitquark/sho...
github.com
GitHub - bitquark/shortscan: An IIS short filename enumeration tool
An IIS short filename enumeration tool. Contribute to bitquark/shortscan development by creating an account on GitHub.
4368
Reposted by STÖK
0xacb @0xacb.com · 23/11/2024
Bug bounties helped us break free from the 9-to-5 monotony, and some of us decided to start our own companies. If you're considering this path, I recommend reading "Calling all hackers" by pwn.cat phrack.org/issues/71/17...
phrack.org
.:: Phrack Magazine ::.
Phrack staff website.
1373
STÖK @stokfredrik.bsky.social · 23/11/2024
Not sure what to make of this plattform, loving it’s rawness, lack of dms and that people I used to know are here, but as a ”semi public person” I struggle with what to share and curate. I just wish I could share things that excite me in my life, rather than hacking content.
28580
STÖK @stokfredrik.bsky.social · 23/11/2024
Back on the open road again, -12c this crispy morning. Spent the night at Ekshärad ski slope. It’s closed for the season but seems to have a few decent big jumps, would be fun to get back here and ride when the snow hits and the park opens. ❄️🏂
0170
Reposted by STÖK
Bee 🐝 @securibee.bsky.social · 21/11/2024
Buzz & Boost ft. @shenet.works Each issue features an innovator living life on their own terms, sharing: 🐝 Buzz: 5 game-changing recommendations 🚀 Boost: Their most exciting current project
1105
Reposted by STÖK
shubs @shubs.io · 22/11/2024
Earlier this year, Assetnote's Security Research team discovered a vulnerability in Sitecore XP (CVE-2024-46938) that can lead to pre-authentication RCE. Order of operations bugs are one of my favorite types of bugs :) Write up and exploit script here: assetnote.io/resources/re...
15023
Reposted by STÖK
Gareth Heyes @garethheyes.co.uk · 22/11/2024
In case you missed it...the DEF CON video of my talk 'Splitting the Email Atom' is finally here! 🚀 Watch me demonstrate how to turn an email address into RCE on Joomla, bypass Zero Trust defences, and exploit parser discrepancies for misrouted emails. Don’t miss it: youtu.be/JERBqoTllaE?...
youtu.be
DEF CON 32 - Splitting the email atom exploiting parsers to bypass access controls - Gareth Heyes
YouTube video by DEFCONConference
29329
Reposted by STÖK
Oli (C..1..P.H.Y) @munz4u.de · 21/11/2024
This is still one of my favorite vids for understanding and finding IDOR vulnerabilities by @stokfredrik.bsky.social. It was the video that inspired me to dive in and get the basics of the idea! www.youtube.com/watch?v=3K1-...
youtube.com
Burp Suite tutorial: IDOR vulnerability automation using Autorize and AutoRepeater (bug bounty)
YouTube video by STÖK
1172
Reposted by STÖK
James Kettle @jameskettle.com · 21/11/2024
Any bug bounty people around? I'm creating a starter pack of people to follow but it's pretty brief currently! Let me know if you'd like to be added: go.bsky.app/GD7hKPX
459530
STÖK @stokfredrik.bsky.social · 21/11/2024
Must resist the urge to simply destroy all them logs….
0111
Reposted by STÖK
Brandon @blaron.bsky.social · 15/11/2024
If you are in cybersecurity repost this so we can all follow each other 😬
1181113
STÖK @stokfredrik.bsky.social · 20/11/2024
After being shutdown for 3 years the skiresort 5 mins from my house is starting backup up again and I can hear the snow cannons roar! Im so hard Gonna get myself a new snowboard kit as a belated birthday gift.
1140
Reposted by STÖK
Pieter Hiele @honoki.net · 20/11/2024
Reposting my evergreens.🎄 Instead of using SSRF to peer inside a local network, I used an internal vulnerable server to proxy out traffic to the internet to turn my blind XXE into root-level file read access. Read my write-up on honoki.net/2018/12/12/f... #bugbounty #writeup #xxe #ssrf
Polyphemus, by Johann Heinrich Wilhelm Tischbein, 1802 (Landesmuseum Oldenburg), depicting the one-eyed giant son of Poseidon and Thoosa in Greek mythology.
4132
Reposted by STÖK
Pieter Hiele @honoki.net · 20/11/2024
"XXE-scape through the front door: circumventing the firewall with HTTP request smuggling" - read my write-up about a pretty cool way in which I bypassed a firewall stopping me from exploiting an XXE vulnerability. honoki.net/2020/03/18/x... #bugbounty #writeup #xxe
A typical New York fire escape. Because this write-up is about escaping a firewall. It’s a little joke.
1141
Reposted by STÖK
TomNomNom @tomnomnom.com · 20/11/2024
miss these guys
A group of 9 hackers stood in a colourful alleyway in VancouverA group of 9 women from a K-Pop band in the same colourful alleyway in Vancouver.
3233