Lauritz
@_lauritz_
Followers
2K
Following
3K
Media
159
Statuses
2K
IT-Security Researcher, Pentester and Bug Hunter. Passionate about π», π€½ββοΈ, βοΈ, πΈ and β½ (@VfLBochum1848eV ) #Kaeferjaeger + H1 Ambassador
Germany
Joined April 2012
[Blog Post] Flickr: Zero User-Interaction Account Takeover π https://t.co/sv9GGuCgfm π https://t.co/fxj3griIHB
#appsec #sso #aws #cognito #flickr #bugbounty
21
150
480
Just figured out @CaidoIO is eating up almost 400G of my storage π
Any tips how to deal with it? For Burp, I zip project files and move them to an external drive from time to time... I know that there is a manual backup feature in Caido, but I feel there has to be a nicer way.
1
0
4
Hello! Just published a new research with ( @sml555_ , @codecancare) π» Who Needs A Blind XSS? https://t.co/bUpFj1p0Mh
#CyberSecurity #BugBounty
hx01.me
How spreadsheet formulas quietly ran inside internal systems.
6
42
201
Made a small and fun research about a technique to leak iframe contents, check this out:
blog.bugport.net
In this small and fun research, I will show how I developed a Clickjacking technique that leaks iframe contents by prompting the user to perform a click and drag + middle mouse button (wheel) click....
0
11
70
ShareHound (@podalirius_), Conquest C2 (@virtualloc), Docker Compose path traversal (@RonMasas), dead domain discovery (@_lauritz_), Narrator persistence/lat movement (@Oddvarmoe ), and more!
blog.badsectorlabs.com
ShareHound (@podalirius_), Conquest C2 (@virtualloc), Docker Compose path traversal (@RonMasas), dead domain discovery (@_lauritz_), Narrator persistence/lat movement (@Oddvarmoe ), Windows 11 LPE...
0
10
21
Recap of our @Hacker0x01 Hacking Meetup in September π Leaderboard (still in progress): https://t.co/3PMHJraAZn π https://t.co/oBFxHyNb3r
#BugBounty #Meetup #HackerOne
1
1
13
4th place in the German Club LHE π (Even tho not all bugs have been rewarded yet) I had 0 expectations joining the event, just exited to hack with some insanely talented folks, and learn as much as i can. And then out of nowhere i started finding some pretty nice bugs.
12
2
103
If you are using Nextcloud Mail... you may want to make sure to update to the most recent version of the extension. https://t.co/CXN5BIpgVt Just stumbled over a trivial XSS issue by accident, just to find out, it was apparently addressed yesterday: https://t.co/DwWTjIXezf
0
0
2
Secured my First Hacker Award at the 3rd H1 Club Event Germany, as Most Helpful Hackerπ«‘It's been a pleasure as always, huge thanks to @_lauritz_ and @Hacker0x01 for the Event!! Leaderboard results coming soon
3
1
44
@nullcon Berlin was a blast π₯ Thanks for the amazing time, great talks, impactful collaboration with @Krevetk0Valeriy in @yeswehack's Mini-LHE and all the networking! See you all again next year at NullCon Berlin 2026.π€ Thanks @antriksh_s for organizing this awesome event. β€οΈ
I had a great time at @nullcon. Many thanks to the organizers of the event! And I was very happy to meet @_lauritz_ , @Ch0pin and other great people in person!
2
1
16
Unser @Hacker0x01 Bug Bounty Meetup geht in die nΓ€chste Runde π€© π₯ 30 PlΓ€tze ππ 10. - 20.09.25 (Remote-Hacking) ππ§βπ» 20.09.25 (In-Person in Essen) β° 12 - 18 Uhr π Rivvers Essen-Lindenallee https://t.co/lM5bi4iNkq ππΆ 10min FuΓweg vom HbF Essen π https://t.co/oBFxHyMDdT
2
1
7
I just got the confirmation that I was selected for this year's @nullcon Berlin Bug Bounty Scholarship π This will actually be my fourth @nullcon, I am looking forward to meeting friends and doing some bug bounty hunting in September. See you there! :) https://t.co/kPeqTkZ7d8
1
2
32
I reported a single, highly critical vulnerability that earned the top payout of the event. π₯π Big thanks to @EXNESS for putting together such a great virtual meetup, and a special shoutout to @_lauritz_! Everything was incredibly well organized! π
Hacking Meetup vol. 3 of the German @Hacker0x01 Club - supported by @EXNESS - was a blast! π₯ We x6 the overall bounties of our previous meetup and scored over 94,000$ overall bounties. π€― Additionally, H1 swag is on the way to all attendees and will hopefully arrive soon .π€
1
1
35
Thank you very much to everyone who made the event possible! β€οΈ Congrats to @marcolivermunz for securing the well-deserved 1st place. π₯ Join your local https://t.co/Nt9FqpF0f4 chapter to not miss opportunities like this! https://t.co/FxvlJyFkdb
#BugBounty #Meetup #HackerOne
h1.community
At HackerOne, we're making the internet a safer place. Thousands of talented people β hackers, employees, and community members β have dedicated ourselves to making the internet safer by helping...
1
0
7
Hacking Meetup vol. 3 of the German @Hacker0x01 Club - supported by @EXNESS - was a blast! π₯ We x6 the overall bounties of our previous meetup and scored over 94,000$ overall bounties. π€― Additionally, H1 swag is on the way to all attendees and will hopefully arrive soon .π€
3
2
59
I just found the coolest csp bypass ever! did you know that a valid pdf can ALSO be valid javascript? (details below)
11
122
788
I am getting a lot of spam recently via DM, even though I have the filter for low-quality messages enabled. Sad, but I feel like I have to restrict message requests for now, even though I think open DMs are generally a good thing. If you want to contact me, use Discord or email
1
0
3
It was an honor to participate with a German team for the first time - thanks a lot @Arl_rose and everyone who made the event possible. :) Looking forward to the next AWC π Make sure to join your regional H1 chapter at https://t.co/FxvlJyFkdb to not miss events like this!
h1.community
At HackerOne, we're making the internet a safer place. Thousands of talented people β hackers, employees, and community members β have dedicated ourselves to making the internet safer by helping...
The @hacker0x01 ambassador World Cup comes to an end. After 1 year, 42 teams, 766 hackers, and 6 rounds (including two in person), we conclude what to me is a passion project I always envisioned and I'm very happy to make a reality. Thanks to everyone who made it possible.
1
0
6
Join our (or your local) club on https://t.co/Nt9FqpF0f4 to not miss future events in your region: https://t.co/AmAJ2azWs1 The leaderboard of the event can be found here: https://t.co/4yOuJWEsZ7 Event wrap-up:
h1.community
At HackerOne, we're making the internet a safer place. Thousands of talented people β hackers, employees, and community members β have dedicated ourselves to making the internet safer by helping...
0
0
2
Overall, we submitted 21 vulns and scored (by now) over 13k$ in bounties. And there are still some reports in triage or pending bounty state π€ Thanks to @Hacker0x01 and @GrabSG for supporting the event and everyone who attended and collaborated!
1
0
1