Jomar
@J0_mart
Followers
2K
Following
114
Media
62
Statuses
790
Sharing is knowledge
Joined August 2012
Big news: @rez0__ and I just launched a new LLM evaluation designed to test for one of the most dangerous model failure modes—sycophancy. We call it: The Glazing Score 👇
3
7
71
One of the hardest parts of a security code review? Figuring out how the project is structured. https://t.co/TxPtEGUyuM just changed the game: 🧠 Repo overview 🧩 Component relationships 🧭 Architecture map 💬 Ask: “Any secrets?” “SQLi here?” Try it. It's 🔥 for AppSec.
deepwiki.com
DeepWiki provides up-to-date documentation you can talk to, for every repo in the world. Think Deep Research for GitHub - powered by Devin.
4
19
110
I just started a blog to share my experiences in Web2 and Web3! My first post is live: https://t.co/l3AkSEjKCB I hope it will be helpful, especially for those getting started!
blog.rmsec.io
How a simple OAuth client-credentials leak led to a full PII exposure—and what every bug hunter must learn from it.
1
28
103
Recently found unauthenticated fileupload on a public bugbounty programs' SOAP service!, managed to upload a PHP webshell via SOAP documentRequest feature and almost gained code execution. Full #writeup coming soon! #BugBounty
6
24
277
Just published a new blog post on the collaborative environment we use with @R_Marot for smart contract auditing https://t.co/pOwNCsLmU9 This can easily be replicated for web2 code audits and it makes teamwork much easier
blog.jomar.fr
In cybersecurity, collaboration is essential, this ensures that multiple perspectives and expertise converge to uncover vulnerabilities more effectively, where overlooking even small issues can lead...
2
3
10
Bad timing, a few hours after my tweet, bugcrowd announces that MFA is mandatory and pushes a change that breaks the authentication system in ScopesExtractor I've just pushed the fix !
it's been a long time since I posted a blog post ! Today I posted "Extract and monitor bugbounty scopes" https://t.co/vitfIMFbwe With new projects in the pipeline, I've already lined up a number of upcoming articles 😁
1
0
8
it's been a long time since I posted a blog post ! Today I posted "Extract and monitor bugbounty scopes" https://t.co/vitfIMFbwe With new projects in the pipeline, I've already lined up a number of upcoming articles 😁
blog.jomar.fr
Extract and monitor bugbounty scopes
2
15
69
🚀 We wrapped up our first First Flight event on @CodeHawks with my teammate @J0_mart! 🔥 An amazing first experience with quite good results: 5 high / 1 medium / 1 low vulnerabilities reported. Time to keep sharpening our skills and leveling up our audits!
1
1
4
Last month, our Security Research team discovered and disclosed a critical pre-authentication RCE in CraftCMS (CVE-2024-56145). You can read our blog post on the issue here: https://t.co/5XKTpW5SNq
3
28
106
After H1-0131 and H1-702, we wanted to share our experience as LHE hackers for aspiring hackers and newcomers.
10
25
140
#CyberPanel (n)day pre-auth root RCE drop 🎁 I also intended to note down my mental process while auditing code since the bug is relatively easy, definitely recommended for upcomers Left a challenge at the end if you want to find your own n-day bug :) https://t.co/jAtQG9zQFV
7
43
226
1 Bug, $50K+ in bounties: how Zendesk left a backdoor in hundreds of companies #bugbountytips
https://t.co/8pkfFsXRWR
gist.github.com
1 bug, $50,000+ in bounties, how Zendesk intentionally left a backdoor in hundreds of Fortune 500 companies - zendesk.md
76
342
1K
gowitness v3 is out! A huge task, but I refactored basically _everything_ for version 3 in just over a week, followed by also writing the longest release notes of my life! Hopefully it's the best version yet. A lot has changed, so feel free to dig in. 🤖 🧵👇
9
68
198
🔥 White-Box Penetration Testing: Debugging For Python Vulnerabilities 🔗 https://t.co/cS3vAfgs3c
#BugBounty
0
3
8
Someone just exploited https://t.co/hSm8iKVvZs with a Pwn Request and added their payloads to the main branch… @stripe
github.com
Learn how to accept a payment from customers around the world with a variety of payment methods. - stripe-samples/accept-a-payment
15
86
494
In April, @samwcyo and I discovered a way to bypass airport security via SQL injection in a database of crewmembers. Unfortunately, DHS ghosted us after we disclosed the issue, and the TSA attempted to cover up what we found. Here is our writeup: https://t.co/g9orwwgoxt
51
643
2K
🚀 Introducing SanicDNS 🚀 Looking for lightning-fast domain resolutions? SanicDNS resolves up to 5M domains per second! 🏎️💨 https://t.co/aE01QGeAq8
github.com
Gotta go fast. Contribute to hadriansecurity/sanicdns development by creating an account on GitHub.
1
14
60