leonjza Profile Banner
_leon_jacobs(💥) Profile
_leon_jacobs(💥)

@leonjza

Followers
5K
Following
6K
Media
645
Statuses
4K

⟦ 'cto @sensepost', '@orangecyberdef', 'caffeine fueled', '(╯°□°)╯︵ ┻━┻', 'security guy', 'metalhead', 'i saw your password', 'KOOBo+KXleKAv+KXlSnjgaM=' ⟧

https://leonjza.bsky.social
Joined June 2012
Don't wanna be here? Send us removal request.
@leonjza
_leon_jacobs(💥)
2 months
I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :)
17
142
1K
@BSidesCapeTown
BSides Cape Town
3 days
A browser that reboots your machine? That’s not a feature, that’s Leon Jacobs’ kind of fun. In 7 Vulns in 7 Days, he unpacks a week-long dive through bloatware and bad privilege boundaries. Join him at BSides Cape Town 2025 for bugs, exploits, and a few laughs at vendor expense.
0
2
6
@1ns0mn1h4ck
Insomni'hack
4 days
🚀 Insomni’hack 2026 is coming! 🗓️ March 16-20 @ SwissTech, Lausanne Mon-Wed: Workshops | Thu-Fri: Talks | Fri-Sat: CTF 👉 More details soon: https://t.co/nMZo0LDpS9 🔔 Save the dates & stay tuned! #INSO26 #cybersecurity #CTF #event #Lausanne
0
6
16
@disconnect3d_pl
Disconnect3d
9 days
Btw we released Pwndbg 2025.10.10 recently with improved kernel debugging, mach-O+Objective-C (LLDB) support, new commands for dumping mallocng (musl) allocator state and much more! See the changelog here! https://t.co/uPIOS3Bjuy
2
52
296
@Steph3nSims
Stephen Sims
9 days
Fantastic @offby1security session with @leonjza on finding bugs in Windows bloatware. It's available on YouTube here:
0
18
74
@leonjza
_leon_jacobs(💥)
9 days
Starting in just over an hour!
@Steph3nSims
Stephen Sims
10 days
Update!! Due to flight delays we will be running the @offby1security stream with @leonjza "Vulnerability Discovery in Windows Bloatware" on Saturday 18-Oct at 1AM PT / 08:00 UTC. https://t.co/dtvyAn1aic
0
2
13
@Steph3nSims
Stephen Sims
10 days
Update!! Due to flight delays we will be running the @offby1security stream with @leonjza "Vulnerability Discovery in Windows Bloatware" on Saturday 18-Oct at 1AM PT / 08:00 UTC. https://t.co/dtvyAn1aic
2
6
26
@1ns0mn1h4ck
Insomni'hack
12 days
📢Insomni'hack Call for Paper is now open! The CFP 2026 is now accepting submissions. Want to speak, lead a workshop, or present a case study? We want to hear from you! 🔗 Submit: https://t.co/2VDGS8TzxQ #InsomniHack #CFP #Cybersecurity #Infosec #TechTalks
0
12
23
@fridadotre
Frida
14 days
Frida 17.4 introduces Simmy, a new backend for Apple’s Simulators on macOS. Spawn, attach, and instrument apps — just like on a real device.
5
130
496
@pagedout_zine
PagedOut
23 days
https://t.co/o4CGqi5qR0  ← we've just released Paged Out! zine Issue #7 https://t.co/ZEuR7WtUAL ← direct link https://t.co/DFuGBWFb4D ← prints for zine collectors https://t.co/8VN5hGyEux ← issue wallpaper Enjoy! Please please please RT to spread the news - thank you!
Tweet card summary image
pagedout.institute
Deeply technical zine. And it's free.
6
134
280
@ZephrFish
@zephrfish.yxz.red
29 days
It would appear weekends are where I take pictures, procrastinate and kick out blog posts and tools. Here's my latest thing I bring to the table, OmniProx it's a semi dropin replacement for FireProx due to AWS's policy changes. https://t.co/uqCwaZjaSh https://t.co/0iBgpaTsST
Tweet card summary image
github.com
IP Rotation from different providers - Like FireProx but for GCP, Azure, Alibaba and CloudFlare - ZephrFish/OmniProx
1
22
78
@leonjza
_leon_jacobs(💥)
29 days
Romhack was absolute 🔥! The conference, the community, the vibe - all of it was just something else. Special mention to @merlos1977 and the @cybersaiyanIT team for making the speaking experience excellent too. 🙃
2
3
20
@codewhisperer84
codewhisperer84
1 month
Check out Titanis, my new C#-based protocol library! It features implementations of SMB and various Windows RPC protocols along with Kerberos and NTLM. https://t.co/GC5wA2y3EO
Tweet card summary image
github.com
Windows protocol library, including SMB and RPC implementations, among others. - trustedsec/Titanis
14
187
554
@_1mposter
1mposter
1 month
Consumed We are what we feed on
27
124
752
@leonjza
_leon_jacobs(💥)
1 month
🇮🇹👋
0
0
2
@leonjza
_leon_jacobs(💥)
1 month
Soon™ Private invites at Romhack (@cybersaiyanIT) next week, public release a while later.
@leonjza
_leon_jacobs(💥)
2 months
I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :)
1
3
5
@_dirkjan
Dirk-jan
1 month
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog:
dirkjanm.io
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise...
143
904
3K
@singe
Dominic White 👾
1 month
I had occasion to hack on some Wordpress’es and realised there’s a ton of surface area exposed over the "new" REST interfaces. Here's a small utility to convert it into a OpenAPI/Swagger file so you can explore it in your pentests/bug bounty work. Link below
1
5
21
@leonjza
_leon_jacobs(💥)
2 months
If you're at RomHack (@cybersaiyanIT) at the end of the month, come tell me your @github username and I'll give you early access to the @sensepost tool repo for PipeTap at the con! 🙃 Below is a demo of the proxy in action. https://t.co/6rOorMYPCL
2
1
25
@leonjza
_leon_jacobs(💥)
2 months
So far PipeTap can: - Proxy reads/writes (even some async ones). - Be a client, incl. the ability to have the *actual* connection in a remote process for those targets that do client pid validation. - Proxy TCP <-> Named pipe for arbitrary Python clients. - And more to come!
1
1
10
@leonjza
_leon_jacobs(💥)
2 months
Ofc, I'm aware alternatives exist (and that really, using just a @fridadotre hook you can get far), but I wanted something more versatile.
1
1
10