Piotr Bazydło Profile
Piotr Bazydło

@chudyPB

Followers
4K
Following
3K
Media
43
Statuses
922

Principal Vulnerability Researcher at watchTowr | Previously: Zero Day Initiative | @[email protected]

Joined October 2017
Don't wanna be here? Send us removal request.
@chudyPB
Piotr Bazydło
1 year
My OffensiveCon 2024 talk about Exchange PowerShell Remoting is available. Includes a chain of 3 vulns to RCE (file write + file read + DLL load).
3
103
295
@chudyPB
Piotr Bazydło
3 days
My 2nd Sitecore blog is live. This time, it's a Pre-Auth HTML Cache Poisoning (fun reflection) + Post-Auth RCE 🫡.
@watchtowrcyber
watchTowr
3 days
It’s Friday, and we’re back - completing our 2 part series detailing the vulnerabilities we discovered in the Sitecore Experience Platform CMS 🫡.
1
10
72
@grok
Grok
18 days
Blazing-fast image creation – using just your voice. Try Grok Imagine.
278
547
3K
@chudyPB
Piotr Bazydło
10 days
RT @chompie1337: I've been asked countless times how to learn VR & xdev. The answer is always: "do something you think is cool". It's hard….
Tweet card summary image
github.com
Binary Exploitation Phrack CTF Challenge. Contribute to xforcered/PhrackCTF development by creating an account on GitHub.
0
143
0
@chudyPB
Piotr Bazydło
12 days
I joined Sonny and added quite nice pre-auth RCE chain, which contains argument injection -> auth bypass vuln 🫡.
@watchtowrcyber
watchTowr
12 days
We're back - returning to the scene of the "crime" - to demonstrate 2 pre-auth RCE chains against Commvault (CVE-2025-57788, CVE-2025-57789, CVE-2025-57790, CVE-2025-57791) . Enjoy, and speak soon 😉.
1
9
51
@chudyPB
Piotr Bazydło
13 days
RT @steventseeley: As it turns out, @orange_8361 and I have more in common than I had thought! If you love old school PHP quirks and CTF tr….
0
61
0
@chudyPB
Piotr Bazydło
14 days
BTW - 2 long blog posts incoming 😅.
@chudyPB
Piotr Bazydło
17 days
Small survey. Should my blogs be:.a) Long as usual, with a deep dive and the code flow analysis. b) Shorter, straight to the root-cause analysis. Any feedback appreciated :).
1
1
21
@chudyPB
Piotr Bazydło
15 days
RT @watchtowrcyber: We’re expanding the phorce globally - and within watchTowr Labs, we’re always hiring. We’re looking for hands on skills….
0
18
0
@chudyPB
Piotr Bazydło
15 days
Tweet media one
Tweet media two
0
5
0
@chudyPB
Piotr Bazydło
17 days
Small survey. Should my blogs be:.a) Long as usual, with a deep dive and the code flow analysis. b) Shorter, straight to the root-cause analysis. Any feedback appreciated :).
0
0
2
@chudyPB
Piotr Bazydło
25 days
RT @albinowax: The whitepaper is live! Learn how to win the HTTP desync endgame. and why HTTP/1.1 needs to die:
Tweet card summary image
http1mustdie.com
Upstream HTTP/1.1 is inherently insecure, and routinely exposes millions of websites to hostile takeover. Join the mission to kill HTTP/1.1 now
0
250
0
@chudyPB
Piotr Bazydło
25 days
RT @TheZDIBugs: [ZDI-25-809] (0Day) Microsoft Exchange PowerShell Exposed Dangerous Method NTLM Relay Vulnerability (CVSS 8.8; Credit: Piot….
Tweet card summary image
zerodayinitiative.com
(0Day) Microsoft Exchange PowerShell Exposed Dangerous Method NTLM Relay Vulnerability
0
3
0
@chudyPB
Piotr Bazydło
25 days
RT @TheZDIBugs: [ZDI-25-820] (0Day) Microsoft SharePoint IsAuthorizedType Deserialization of Untrusted Data Information Disclosure and Deni….
Tweet card summary image
zerodayinitiative.com
(0Day) Microsoft SharePoint IsAuthorizedType Deserialization of Untrusted Data Information Disclosure and Denial-of-Service Vulnerability
0
3
0
@chudyPB
Piotr Bazydło
25 days
RT @TheZDIBugs: [ZDI-25-822] (0Day) Microsoft SharePoint GetTransformer Unsafe Reflection Denial-of-Service Vulnerability (CVSS 6.5; Credit….
Tweet card summary image
zerodayinitiative.com
(0Day) Microsoft SharePoint GetTransformer Unsafe Reflection Denial-of-Service Vulnerability
0
1
0
@chudyPB
Piotr Bazydło
25 days
RT @TheZDIBugs: [ZDI-25-813] (0Day) Microsoft PowerShell TryModuleAutoLoading Directory Traversal Remote Code Execution Vulnerability (CVSS….
Tweet card summary image
zerodayinitiative.com
(0Day) Microsoft PowerShell TryModuleAutoLoading Directory Traversal Remote Code Execution Vulnerability
0
1
0
@chudyPB
Piotr Bazydło
27 days
Research is fun. One month ago, I thought that I'll never again make a research as good as my .NET deserialization one. Here I am today, writing a new whitepaper. You never know the day 😅.
4
2
117
@chudyPB
Piotr Bazydło
28 days
Btw, I described my SharePoint CVE-2024-38018 at a PL conference last year, and they've recently uploaded it. I guess you don't know Polish, but slides are in English 😅 RCE part starts at 30:30 .
3
24
119