C:\hristian Mehlmauer
@firefart
Followers
3K
Following
5K
Media
236
Statuses
8K
I hacked the planet - opinions are my own - Mastodon: https://t.co/FTAelGh7DO
Vienna, Austria
Joined June 2009
Proud to release a new tool called STUNNER to test TURN servers (mostly used in WebRTC). It can open a local socks server and relay all traffic over vuln devices into the internal network https://t.co/xdNlS1gUl8 Also found some vulns in Cisco Expressway:
firefart.at
Some time ago I stumbled across a [HackerOne report](https://hackerone.com/reports/333419) about abusing Slacks TURN server for proxy functionality inside their internal network. I found this...
2
36
100
#BSidesVienna is now live on #HackerTracker ( https://t.co/EYg28kQ7yy). You can use the app to manage your own schedule for not only this event but for many more. https://t.co/veNVrC8KS7
0
1
2
Sponsor Spotlight: A big thanks goes out the the city of Vienna (@Stadt_Wien) for supporting #BSidesVienna. Check out their new public bug bounty over at https://t.co/F1mtau0XVY, they pay out bounties!
bugcrowd.com
Learn more about City of Vienna - Vienna Municipal Department 01’s Bug Bounty engagement powered by Bugcrowd, the leader in crowdsourced security solutions.
4
1
3
While you were all busy pressing F5 to get a ticket, we quietly released a surprise for you. The first #BSidesVienna schedule is released! Have a look:
0
2
3
Reminder, the next Ticket round will start on Sunday 26.10.2025 at 19:00 Vienna time UTC+2!
1
2
5
Sponsor Spotlight: Thanks to slashsec Red Teaming GmbH for sponsoring the afterparty for #BSidesVienna! They focus on Red Teaming and are always looking for talented offensive security professionals with a real hacker mindset. You can check them out at
slashsec.at
Exzellente Red Teaming & Cyber Security Services in Österreich
0
1
1
PRO TIP: REST is overengineering. Just expose one endpoint called /api that accepts SQL queries directly.
543
519
10K
Postgres 18 has been released, with Async I/O support. Previously, all read requests were blocking, but with this update, they are no longer, delivering massive performance gains for read-heavy applications! It's enabled by default on Postgres 18!
85
527
6K
If you want to be a better hacker, be a developer. Be an admin. Set up infra. Build coding projects. Make an app that writes to a db. Or stores cookies. Or performs auth. You will find it easier to spot the cracks and failure points in systems once you have set them up yourself.
22
70
590
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog:
dirkjanm.io
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise...
143
906
3K
🚨 Shai-Hulud: Major npm supply chain attack. 100+ packages weaponized with stolen GitHub tokens, stealing secrets, hijacking repos, and auto-propagating like a worm. Guidance + detections inside:
wiz.io
Learn how the Shai-Hulud npm worm compromised 100+ packages with data-stealing malware. See how it spreads, the risks, and steps to detect and mitigate.
0
14
29
Chat, did we do it? Is iPhone spyware cooked? The way I'm reading this, iPhone 17 just became the most secure mobile device ever.
40
61
929
“The largest supply chain compromise in npm, Inc. history just happened, packages with a total of 2 billion weekly downloads just got turned malicious” LinkedIn Post https://t.co/dJ0tlPrSBJ More info on hacker news https://t.co/uncwjtFgxT
21
338
1K
#BSidesVienna is free by design—but it runs on sponsor support. Your company can support us and get more than good karma: visibility on shirts, badges, website, big screen ads during breaks—plus event tickets, exhibition space, and more. https://t.co/f1OHSXJ57z
bsidesvienna.at
BSidesVienna
0
7
9
In security, when you do your job perfectly, nothing happens. And people don't see when nothing happens.
39
233
1K
mitmproxy is in the Microsoft Store, just in case you need it for some reason. #LivingOffMicrosoftStore
18
67
599
DOOM on the ANKER Prime Charging station😅 This internal SWM34S MCU is just way too nice! 8MB RAM + 16MB Flash directly mapped to memory allow goes brrrr Also on Youtube: https://t.co/QYbpjiOwYz
23
350
2K