bl4sty Profile Banner
blasty Profile
blasty

@bl4sty

Followers
17K
Following
2K
Media
283
Statuses
4K

irresponsible disclosure aficionado

The Netherlands
Joined April 2009
Don't wanna be here? Send us removal request.
@bl4sty
blasty
24 hours
vibecoding devicetrees
1
0
8
@bl4sty
blasty
14 days
fuck. you will be missed @steaIth
@hackerschoice
The Hacker's Choice (@[email protected])
14 days
Stealth died 😢 A member of Team-Teso, Phrack staff, and many other groups. A true hacker—perhaps as true as a hacker can ever be. WE MISS YOU. 🩷 More: https://t.co/Jx0JYfrjnG <stealth> we had joy we had fun we had a rootshell on a sun.
1
0
24
@bl4sty
blasty
28 days
okay very funny @eastdakota now plug it back in pls
0
0
17
@bl4sty
blasty
1 month
TIL the Task Manager Guy™ once dabbled in scareware?
@c0ner0ne
h4x
1 month
Did i upset the “task manager” guy for pointing out his malicious career after Microsoft? https://t.co/V23100AUYD
6
7
145
@bl4sty
blasty
1 month
question to people who have dealt with receiving bug bounty payments (or any kind of payout for an accomplishment; think everything in the 1k-50k USD range): are regular wire transfers your preferred payment method? would you be opposed to taking stable coin (USDT/USDC/..)
8
1
9
@monsterhunter
Monster Hunter
5 days
Celebrate gaming’s biggest night with epic deals on award‑winning titles!
0
32
2K
@bl4sty
blasty
1 month
Jia Tan right now: "hold my beer, I'm pretty sure I can hide my shellcode in MOOV atoms and ADTS frame headers"
0
1
39
@bl4sty
blasty
1 month
500+ dusty codecs, 400+ dusty formats, one innocent looking bug report and one curious core dev. EVERYONE GET ON THE FLOOR RIGHT NOW. NOBODY MOVE THIS IS A ROB^H^H^H SUPPLY CHAIN ATTACK.
2
2
40
@bl4sty
blasty
1 month
I feel as an infosec shitposter, I should clarify tavis' lingo a bit. "popped" in this context means popping calc.exe, or possibly a more nefarious payload 🙃. it doesn't mean people get so angry over security bugs in 1990s game codecs (or at least I hope so) they strap up and
@FFmpeg
FFmpeg
1 month
>Let's hope a bug in some 1990s game codec doesn't get some ffmpeg core developer popped.
12
6
206
@bl4sty
blasty
1 month
KASLR on Pixel 😭
@natashenka
Natalie Silvanovich
1 month
@__sethJenkins broke kASLR by doing … nothing 😩 https://t.co/hxPzVTC1RN
1
3
53
@LecenaSt
Lecena
1 month
These cozy knitted stockings are perfect for keeping your feet warm on chilly winter nights. Whether you’re lounging around the house, watching TV, or wearing slippers or shoes, they add comfort and style to your everyday moments.
0
135
1K
@bl4sty
blasty
2 months
i guess you can still contact a CNA directly etc. but it adds to the hassle that is a disclosure process
2
0
8
@bl4sty
blasty
2 months
kind of funny that bugs that are communicated to vendors in a way they don't appreciate can result in no CVE being allocated for the vuln(s). while i guess it is bureaucratically legit (or is it?) it makes the CVE system an unreliable source of truth (more news at 11)
@0xmadvise
no_r0llback
2 months
Sucks, yesterday i've discovered a path traversal in docker compose, but unfortunately it will not be assigned as a CVE. Because i was supposed to send an email instead of opening a public issue in GH😅 anyhow the poc can be found here: https://t.co/BDt5nnrTYA
9
11
69
@bl4sty
blasty
2 months
looking at the history for the hashtag it appears @thegrugq milked his own meme for six years straight wth
1
0
13
@bl4sty
blasty
2 months
the most important question I have about this HackingTeam revival that was exposed by @oct0xor and co is if #YourBoySerge is still saving the day when the live demos fail during a sales pitch. or did they find a new Serge? (anyone remember #YourBoySerge? or am I just really
6
1
30
@DanielGenkin
Daniel Genkin
2 months
More interposer fun, this time with DDR5 memory. Breaking TDX, SGX, SEV and even Nvidia TEEs. Checkout our work at https://t.co/Jl1dpGnM6J, and get a personally-signed Intel attestation report at @TEEdotFail.
45
84
346
@TheSAScon
TheSAS2025
2 months
Every #TheSAS2025 participant already knows who the best speakers were this year. However, the world deserves to know too. 🥇 The best cocktail of deep research and lively presentation this year was delivered by none other than Peter Geissler (@bl4sty) himself. His talk on
0
4
23
@oct0xor
Boris Larin
2 months
TrueType is the gift that keeps on giving (do you remember Triangulation?) and Peter @bl4sty keeps on winning pwn2own thanks to it #TheSAS2025
0
3
37
@bl4sty
blasty
2 months
thanks to everyone who attended my #TheSAS2025 talk "Typographic hit job: when fonts pull the trigger". 🙏 I've written an accompanying blogpost that goes over all the details:
Tweet card summary image
haxx.in
Last year we (PHP HOOLIGANS) competed in Pwn2Own (ireland, 2024) once again. One of our (succesful) entries was against a little pet peeve target of mine, the CANON ImageCLASS printer. In this post...
4
42
137