hashkitten
@hash_kitten
Followers
2K
Following
754
Media
0
Statuses
20
vulnerability research @assetnote // hacking // codegolf // ctf with 🛹🐶
Joined September 2016
Two weeks ago, I did my first (in-person) @Hacker0x01 LHE in Singapore! I worked with @hash_kitten and @infosec_au, and I'm really happy with how it went and what we found :D (We won the Best Team and Best Bug awards! 🔥) It was an amazing event, thanks @Hacker0x01! 😁
Our #H165 live hacking event with @tiktok_us and @okx in Singapore was a big success! It's time to celebrate this year's winners. Here we go... 🥁 For TikTok: Eliminator: avishai Exterminator: kevin_mizu, shubs, hashkitten Vigilante: m4II0K For OKX: Eliminator:
7
5
124
LET'S GET THE BALL (BEARINGS) ROLLING ONLY 4 WEEKS LEFT UNTIL SKATEBOARDING DOG CTF @BSidesCbr 2025 WATCH THE COUNTDOWN ON OUR WEBSITE: https://t.co/Mbp0MzpT8E
0
9
17
This month's Christmas in July release from @SLCyberSec's Security Research team is a pre-authentication RCE vulnerability in Sawtooth Lighthouse Studio (CVE-2025-34300). This software is prevalent and hidden in plain sight. Read more on our blog: https://t.co/1IqFTTeA4i
1
28
131
Pre-auth bugs in enterprise software? Yes please. @hash_kitten takes us inside their research on Adobe Experience Manager—uncovering critical, pre-auth vulnerabilities in a platform powering 45,000+ sites. Live at BSides Canberra 2025: https://t.co/xTLfK6ZGKC
cfp.bsidescbr.com.au
Adobe Experience Manager (AEM) is one of the most popular content and digital asset management systems used by enterprises. It’s likely that the home pages of some of the biggest brands you know and...
0
28
127
To kick off our Christmas and July research posts, we explain how we achieved persistent XSS on every Adobe Experience Manager Cloud instance, not twice, but thrice! This is now patched across all of AEM cloud, but what an interesting attack surface! https://t.co/T8AwmmgmUn
3
39
201
We discovered a pre-authentication RCE vulnerability in Craft CMS caused by an obscure PHP foot gun (CVE-2024-56145), approx 150k sites created with Craft CMS. You can read @Assetnote's Security Research team's blog on the issue: https://t.co/UuzXePNVeT
#attacksurfacemanagement
7
91
384
Our security researcher @hash_kitten found one of the most critical exploit chains in the history of @assetnote. Affecting 40k+ instances of ServiceNow, we could execute arbitrary code, access all data without authentication. You can read our blog here: https://t.co/2yTgn1NzhY
15
220
793
At @assetnote, we published our research on Magento's pre-authentication XXE (CVE-2024-34102). @hash_kitten and I reproduced this issue together. It is a brilliant vulnerability originally found by Sergey Temnikov. You can read our research here: https://t.co/wENjzVSAYh
3
134
417
I've written another set of challenges this year and I'm really happy with how they turned out. Make sure you check out DUCTF this weekend :)
Attention ALL Hackers - We are now ONE WEEK AWAY from DUCTF 4.0! 🔥 Sign-ups are now OPEN! 🔥 https://t.co/tbttlCFE6H
2
3
19
Did you enjoy the latest blogpost on PHP filter chains? Well, our ninja @_remsio_ strikes again with a new article detailing how you can abuse them to leak files from the targeted system, as well as a freshly developed tool to exploit it!
synacktiv.com
PHP filter chains: file read from error-based oracle
2
66
142
Just learned you can exploit blind file-reads in PHP by combining the dechunk filter with the PHP memory limit. This crazy finding by @hash_kitten is a great reminder to pay attention to CTF writeups! https://t.co/gaB0aEQsQo
2
118
368
I've written some challenges this year. Make sure you check DUCTF out! =)
You all know the drill by now! What are you waiting for! Registration is open at https://t.co/KxW9N8f9gL and only 1 week till the madness starts 🔥🔥🔥
0
1
16
Finished Google CTF 2021 at #13 with 🛹🐻 GG to everyone involved! crypto writeups (all challenges): https://t.co/VdouC76z7D
2
13
80