j_domeracki Profile Banner
Jakub Domeracki Profile
Jakub Domeracki

@j_domeracki

Followers
353
Following
140
Media
6
Statuses
44

Security Engineer @ Coder Google Cloud VRP ๐ŸŒฉ๏ธ

Joined April 2023
Don't wanna be here? Send us removal request.
@j_domeracki
Jakub Domeracki
4 months
Another one of my reports got disclosed ๐ŸŽ‰. @GoogleVRP did a great job of nearly eliminating XSS-es from their core apps, but some are still to be found. A technical writeup, describing this and corresponding issues, should be published by end of month ๐Ÿคž.
Tweet card summary image
bughunters.google.com
Found a security vulnerability? Discover our forms for reporting security issues to Google: for the standard VRP, Google Play, and Play Data Abuse.
6
38
214
@j_domeracki
Jakub Domeracki
21 days
Still can't quite believe that one of my reports won the most creative category award at recent @GoogleVRP bugSWAT LHE! ๐ŸŽ‰. Can't disclose the details yet but I'll surely cover the entire attack scenario in a dedicated writeup.
Tweet media one
5
3
92
@j_domeracki
Jakub Domeracki
26 days
I'm honestly blown away by how much using tools like Gemini CLI & Claude Code, aids in vulnerability research. ๐Ÿคฏ. It feels like having a conversation with the more technical coworker who actually went through the code ๐Ÿ˜†.
0
0
0
@j_domeracki
Jakub Domeracki
1 month
RT @terminatorLM: ๐Ÿ‘ปThis is GerriScary: a vulnerability I discovered in Google's Gerrit that allowed to hack several projects and affected 1โ€ฆ.
0
26
0
@j_domeracki
Jakub Domeracki
3 months
Sharing a writeup on Bucket Traversals, which in my opinion is an under researched vulnerability class:. It's based on a case study which ended being rewarded by OSS @GoogleVRP:. I hope you'll find it interesting!
Tweet media one
1
24
79
@j_domeracki
Jakub Domeracki
4 months
@GoogleVRP PS. I don't really like XSS as an attack vector but this one was cool.
0
0
0
@j_domeracki
Jakub Domeracki
5 months
@GoogleVRP None of the current guesses are close - it's a cloud specific scenario which was reported and written about in the past. I intend to stick with the standard 90 days post disclosure / 30 days post fix practice, so no details until then.
0
0
1
@j_domeracki
Jakub Domeracki
5 months
Well-known attack technique, still relevant. Will publish an educational writeup in a few weeks/months๐Ÿคž. @GoogleVRP
Tweet media one
4
2
98
@j_domeracki
Jakub Domeracki
7 months
Rarely do I post but this is in my book a must watch by @snyff. Great insights and for me personally a much needed recalibration of expectations & approach.
1
6
14
@j_domeracki
Jakub Domeracki
7 months
RT @S1r1u5_: Imagine opening a Discord message and suddenly your computer is hacked. We discovered a bug that made this possible and earneโ€ฆ.
0
178
0
@j_domeracki
Jakub Domeracki
8 months
RT @gregxsunday: Story of a Cloud Architecture Diagramming Tool gone wrong by @j_domeracki.#BBRENewsletter84 https:โ€ฆ.
0
4
0
@j_domeracki
Jakub Domeracki
9 months
Sharing a technical writeup, which goes over an almost year long responsible disclosure process:. The severity of disclosed shortcomings, resulted in getting decommissioned ๐Ÿšง. Greatly appreciate the cooperation with @GoogleVRP! ๐ŸŽ‰.
jdomeracki.github.io
Table of Contents
0
30
126
@j_domeracki
Jakub Domeracki
1 year
Doomsday or blessing? ๐Ÿค”.
0
0
1
@j_domeracki
Jakub Domeracki
1 year
Tweet media one
0
37
0