_sy1vi3 Profile Banner
Sylvie Profile
Sylvie

@_sy1vi3

Followers
836
Following
2K
Media
52
Statuses
993

AhRZbVYwWVM1emVXeDJhV1V1Wm5scAoccUtabXB6NXVvSkg2TElPMXAzTWFuMU4ycGo9PQ==

she/her 20
Joined May 2021
Don't wanna be here? Send us removal request.
@_sy1vi3
Sylvie
3 hours
staying over at a friend's place and i see this, this is good right?
1
0
4
@_sy1vi3
Sylvie
2 days
this is almost a relief i can't lie, i've lost so much sleep this past week going for these
2
2
49
@_sy1vi3
Sylvie
6 days
my teammates gonna make me take a break from playing vercelctf this weekend to play seccon instead and i think thats kinda messed up honestly
1
0
17
@_sy1vi3
Sylvie
7 days
ok turns out a girl can in fact :3 four days spent on that lmfao
@_sy1vi3
Sylvie
8 days
can a girl get one teensy little prototype pollution gadget as a treat or is that too much to ask for
1
0
33
@_sy1vi3
Sylvie
8 days
can a girl get one teensy little prototype pollution gadget as a treat or is that too much to ask for
2
1
32
@_sy1vi3
Sylvie
10 days
in trying to break vercel's firewall ive discovered a whole bunch of things that seem like Problems™ in their own right that make me somewhat hesitant to trust the security anything else going on here
1
0
40
@_sy1vi3
Sylvie
10 days
y'all're gonna be disappointed when next week rolls around and i go back to never saying anything other than the occasional reply to a friend's tweet
0
0
16
@_sy1vi3
Sylvie
11 days
@rauchg
Guillermo Rauch
11 days
1
2
32
@_sy1vi3
Sylvie
11 days
another silly takeaway i got from all of this is that despite not being a frontend dev and generally being a proponent of just coping with raw html/js, ive learned that NextJS is actually pretty fun and easy to work with all things considered
2
1
37
@_sy1vi3
Sylvie
11 days
my 39c3 trip is gonna be so silly now
1
0
10
@_sy1vi3
Sylvie
12 days
vercel's WAF seems very effective at one thing at least, and that's keeping me up until 6am
5
0
72
@_sy1vi3
Sylvie
12 days
i think one of the funniest outcomes of this whole thing is that ive developed something of a sixth sense for knowing if something is a NextJS/Vercel app before even checking devtools
0
0
29
@_sy1vi3
Sylvie
12 days
do u guys think he knows about the cve
2
2
49
@_sy1vi3
Sylvie
13 days
i interacted with too many security slop posters and now my timeline is full of bug bounty skids instead of silly gay people this is so heartbreaking đź’”
5
1
63
@_sy1vi3
Sylvie
13 days
you can see the 02-meow-rce-poc file here matches the hash i posted last week
@_sy1vi3
Sylvie
18 days
18571097aedaec16f729c4227e1e508fe161d5d6b4256eec7d0525535ebb3fa0 9678cd237c17d74ff125532ba75fba5da682a75d6711ef7a2d32cfb18931bb2c
0
1
17
@_sy1vi3
Sylvie
13 days
to be clear, this bug belongs to Lachlan, and for the time being the level of credit currently given to me on https://t.co/AgbXeD3ujX is roughly accurate. we both plan to make detailed blog posts about this at some point in the future.
1
0
22
@_sy1vi3
Sylvie
13 days
while Lachlan began working with Meta and Vercel to get it patched, i began doing reconnaissance to identify vulnerable websites so that we could alert everyone who needed to be alerted immediately after the initial advisory went out.
1
1
12
@_sy1vi3
Sylvie
13 days
i feel i should mention that the initial full RCE PoC had 20+ gadgets, while the one Lachlan submitted to Meta and the ones floating around the internet right now only have like 3.
1
0
10
@_sy1vi3
Sylvie
13 days
we realized the significance of this immediately, and after discussing it we agreed that the bug was his and the PoC was his. Lachlan spent well over 100 hours working on this, to my ~36.
1
0
11