
shubs
@infosec_au
Followers
55K
Following
10K
Media
249
Statuses
5K
Co-founder, security researcher. Building an attack surface management platform, @assetnote
halcyon
Joined August 2013
RT @n1nj4sec: I recently found a blind FreeMarker SSTI on a bbp. It was not possible to RCE but I found some nice gadgets to enumerate acce….
0
46
0
RT @spaceraccoonsec: When I asked @infosec_au to write a foreword for "From Day Zero to Zero Day," I didn't anticipate how perfectly he wou….
0
13
0
RT @ITSecurityguard: Honestly a bit surreal, but I’ll be joining @assetnote as a Security Researcher soon🦆. Excited to be part of such a br….
0
4
0
How do we turn bad SSRF (blind) into good SSRF (full response)? The @assetnote Security Research team at @SLCyberSec used a novel technique involving HTTP redirect loops and incremental status codes that leaked the full HTTP resp. It may work elsewhere!
6
179
605
RT @TantoSecurity: The post is at and we hope you enjoy reading it as much as we enjoyed putting it together! ❤️.
0
11
0
RT @spaceraccoonsec: Sadly, other than the security team, nobody cares about the security tools you build. Here’s how to avoid getting suck….
0
10
0
RT @0xLupin: 2 AM in a Tokyo hotel room: @assetnote x Depi find a Dependency Confusion vuln that lands RCE on Netflix !. 🚀 Shout-out to @i….
0
48
0
@ryotkak @Geluchat @kevin_mizu I forgot to mention. @ajxchapman made an impossible RCE chain possible. His work was inspiring.
1
0
67
I won the Most Valuable Hacker award for the Salesforce H1-6102 live hacking event in Sydney (my hometown)! I enjoyed working with some very talented hackers, including @ryotkak, @Geluchat, and @kevin_mizu. This is my third MVH award, and I'm grateful to be able to compete.
89
36
766
IP whitelisting is fundamentally broken. At @assetnote, we've successfully bypassed network controls by routing traffic through a specific location (cloud provider, geo-location). Today, we're releasing Newtowner, to help test for this issue:
14
235
865