J0_mart Profile Banner
Jomar Profile
Jomar

@J0_mart

Followers
2K
Following
114
Media
62
Statuses
790

Sharing is knowledge

Joined August 2012
Don't wanna be here? Send us removal request.
@ArchAngelDDay
Douglas Day
7 months
Big news: @rez0__ and I just launched a new LLM evaluation designed to test for one of the most dangerous model failure modes—sycophancy. We call it: The Glazing Score 👇
3
7
71
@snyff
Louis Nyffenegger
7 months
One of the hardest parts of a security code review? Figuring out how the project is structured. https://t.co/TxPtEGUyuM just changed the game: 🧠 Repo overview 🧩 Component relationships 🧭 Architecture map 💬 Ask: “Any secrets?” “SQLi here?” Try it. It's 🔥 for AppSec.
Tweet card summary image
deepwiki.com
DeepWiki provides up-to-date documentation you can talk to, for every repo in the world. Think Deep Research for GitHub - powered by Devin.
4
19
110
@R_Marot
Rémy Marot
7 months
I just started a blog to share my experiences in Web2 and Web3! My first post is live: https://t.co/l3AkSEjKCB I hope it will be helpful, especially for those getting started!
blog.rmsec.io
How a simple OAuth client-credentials leak led to a full PII exposure—and what every bug hunter must learn from it.
1
28
103
@nav1n0x
N$
8 months
Recently found unauthenticated fileupload on a public bugbounty programs' SOAP service!, managed to upload a PHP webshell via SOAP documentRequest feature and almost gained code execution. Full #writeup coming soon! #BugBounty
6
24
277
@J0_mart
Jomar
8 months
Just published a new blog post on the collaborative environment we use with @R_Marot for smart contract auditing https://t.co/pOwNCsLmU9 This can easily be replicated for web2 code audits and it makes teamwork much easier
blog.jomar.fr
In cybersecurity, collaboration is essential, this ensures that multiple perspectives and expertise converge to uncover vulnerabilities more effectively, where overlooking even small issues can lead...
2
3
10
@J0_mart
Jomar
8 months
Bad timing, a few hours after my tweet, bugcrowd announces that MFA is mandatory and pushes a change that breaks the authentication system in ScopesExtractor I've just pushed the fix !
@J0_mart
Jomar
8 months
it's been a long time since I posted a blog post ! Today I posted "Extract and monitor bugbounty scopes" https://t.co/vitfIMFbwe With new projects in the pipeline, I've already lined up a number of upcoming articles 😁
1
0
8
@J0_mart
Jomar
8 months
it's been a long time since I posted a blog post ! Today I posted "Extract and monitor bugbounty scopes" https://t.co/vitfIMFbwe With new projects in the pipeline, I've already lined up a number of upcoming articles 😁
blog.jomar.fr
Extract and monitor bugbounty scopes
2
15
69
@R_Marot
Rémy Marot
9 months
🚀 We wrapped up our first First Flight event on @CodeHawks with my teammate @J0_mart! 🔥 An amazing first experience with quite good results: 5 high / 1 medium / 1 low vulnerabilities reported. Time to keep sharpening our skills and leveling up our audits!
1
1
4
@Rhynorater
Justin Gardner
9 months
This is how you take responsibility for a breach.
7
16
177
@assetnote
Assetnote
1 year
Last month, our Security Research team discovered and disclosed a critical pre-authentication RCE in CraftCMS (CVE-2024-56145). You can read our blog post on the issue here: https://t.co/5XKTpW5SNq
3
28
106
@J0_mart
Jomar
1 year
Thank you @PentesterLab !
1
2
32
@DoomerOutrun
doomerhunter (Victor Poucheret)
1 year
After H1-0131 and H1-702, we wanted to share our experience as LHE hackers for aspiring hackers and newcomers.
10
25
140
@dreyand_
DreyAnd
1 year
#CyberPanel (n)day pre-auth root RCE drop 🎁 I also intended to note down my mental process while auditing code since the bug is relatively easy, definitely recommended for upcomers Left a challenge at the end if you want to find your own n-day bug :) https://t.co/jAtQG9zQFV
7
43
226
@J0_mart
Jomar
1 year
Thanks @yeswehack, the poster is sublime !
1
0
15
@leonjza
_leon_jacobs(💥)
1 year
gowitness v3 is out! A huge task, but I refactored basically _everything_ for version 3 in just over a week, followed by also writing the longest release notes of my life! Hopefully it's the best version yet. A lot has changed, so feel free to dig in. 🤖 🧵👇
9
68
198
@adrien_jeanneau
Hisxo
1 year
🔥 White-Box Penetration Testing: Debugging For Python Vulnerabilities 🔗 https://t.co/cS3vAfgs3c #BugBounty
0
3
8
@iangcarroll
Ian Carroll
1 year
In April, @samwcyo and I discovered a way to bypass airport security via SQL injection in a database of crewmembers. Unfortunately, DHS ghosted us after we disclosed the issue, and the TSA attempted to cover up what we found. Here is our writeup: https://t.co/g9orwwgoxt
51
643
2K
@smiegles
Olivier Beg
1 year
🚀 Introducing SanicDNS 🚀 Looking for lightning-fast domain resolutions? SanicDNS resolves up to 5M domains per second! 🏎️💨 https://t.co/aE01QGeAq8
Tweet card summary image
github.com
Gotta go fast. Contribute to hadriansecurity/sanicdns development by creating an account on GitHub.
1
14
60