k_firsov Profile Banner
Kirill Firsov Profile
Kirill Firsov

@k_firsov

Followers
2K
Following
297
Media
15
Statuses
133

Founder and CEO at @FearsOff | Protecting the World’s Top Crypto Exchanges & Financial Institutions | Cybersecurity Enthusiast

Dubai, United Arab Emirates
Joined April 2011
Don't wanna be here? Send us removal request.
@k_firsov
Kirill Firsov
1 month
My research on CVE-2025-49113 is out. Happy reading! #CVE #roundcube #poc @FearsOff
Tweet media one
5
94
323
@k_firsov
Kirill Firsov
15 days
7. And that's how you bypass Cloudflare WAF using. Cloudflare’s own rules 😎.No IP leaks, no magic tricks. Just read the docs and follow my tips 😉.
3
0
48
@k_firsov
Kirill Firsov
15 days
6. Send the request. No challenge, no CAPTCHA, no block. Just a clean 200 OK. Your payload goes straight to the origin 🎯
Tweet media one
2
5
58
@k_firsov
Kirill Firsov
15 days
5. That's your way in. Craft a POST request and prepend junk data to reach the limit. Put your SQLi payload after that. Cloudflare won't see it. The WAF gives up scanning after the limit is reached.
3
1
35
@k_firsov
Kirill Firsov
15 days
4. Just check Cloudflare's own docs 👀. Cloudflare only inspects the body of a request up to a certain size. Enterprise: 128 KB.Everyone else: much lower
Tweet media one
2
2
46
@k_firsov
Kirill Firsov
15 days
3. You start hunting for the real IP. Shodan, Censys, subdomains. Hours go by. Nothing works. Cloudflare is doing its job well. But what if I told you there's a way around it?.
1
0
20
@k_firsov
Kirill Firsov
15 days
2. You're testing a login form. There's SQLi in the password field. You try something like:.password' or 1='. 1. But instead of a response, Cloudflare hits you with:."Attention Required! | Cloudflare".Brutal.
Tweet media one
1
0
28
@k_firsov
Kirill Firsov
15 days
How to bypass Cloudflare WAF?.@FearsOff #bugbountytips #cloudflare #waf #bypass. 1. Found an SQL injection but getting blocked by Cloudflare?.Here's a pro tip 😏
Tweet media one
14
161
810
@k_firsov
Kirill Firsov
1 month
@FearsOff Since many other teams have already released their PoC, here’s mine: Also, the previously blurred parts of the article are now visible.
2
6
22
@k_firsov
Kirill Firsov
1 month
Files from the video on github but without PoC
0
0
1
@k_firsov
Kirill Firsov
1 month
The exploit for CVE-2025-49113 is already available for sale on the dark web. I feel sorry for anyone who hasn’t upgraded to the newest version yet. Doomsday is coming, believe me. #roundcube #CVE @FearsOff
Tweet media one
3
11
51
@k_firsov
Kirill Firsov
1 month
If you’re using cPanel, Plesk, ISPConfig, or DirectAdmin, you’re likely in the line of fire for CVE-2025-49113 – all of them bundle Roundcube by default. If your server/website exposes any of these ports: 2083, 2086, 2087, or 2096, you’re vulnerable. #CVE #roundcube @FearsOff.
3
9
43
@k_firsov
Kirill Firsov
1 month
The correct CVE ID now is CVE-2025-49113.
0
0
2
@k_firsov
Kirill Firsov
1 month
check PoC demo now
@k_firsov
Kirill Firsov
1 month
Here is a PoC demonstration for you guys! #roundcube #cve #fearsoff .
1
5
9
@k_firsov
Kirill Firsov
1 month
Here is a PoC demonstration for you guys! #roundcube #cve #fearsoff .
2
27
123
@k_firsov
Kirill Firsov
1 month
Excited to share that I reported CVE-2025-48745, Roundcube ≤ 1.6.10 Post-Auth RCE via PHP Object Deserialization. This bug has existed undetected for 10 years and affects over 53 Million hosts. Details and PoC will be published soon. We're giving time to all affected parties to.
9
40
218
@k_firsov
Kirill Firsov
2 months
RT @mar1hachem: 🚨 Coinbase Breach = Bug Bounty Reality Check 🚨. Yesterday, bribed support agents leaked about 1% of @coinbase users’ perso….
0
4
0
@k_firsov
Kirill Firsov
2 months
🥈 Scored the 2nd-highest bounty on @Hacker0x01 and broke into the Top 10 leaderboard three times in the past 30 days! Huge thanks to @cryptocom for trusting us with their security—now, back to hunting. 🐛🚀.#BugBounty #EthicalHacking #Cybersecurity
Tweet media one
21
35
398
@k_firsov
Kirill Firsov
3 months
RT @FearsOff: 🚨 Another Major Milestone Unlocked! 🚨. We’re proud to announce that FearsOff has officially claimed the #1 spot on @Official_….
0
12
0