Francesco Enrietti Profile
Francesco Enrietti

@not4nhacker

Followers
56
Following
222
Media
3
Statuses
57

Chief "Have you ever heard about OAuth?" Officer @ShielderSec

Joined January 2022
Don't wanna be here? Send us removal request.
@mdisec
Mehmet INCE
5 days
1/6 What started as a routine 24-hour vulnerability research of PostHog turned into quite the rabbit hole... 🕳️🐇 I ended up finding a way to chain a simple SSRF, a ClickHouse Postgresql Table functions SQL Escape 0-day, and default DB credentials into a full RCE. It’s a fun
3
8
81
@ShielderSec
Shielder
28 days
Want to learn more about our approach into auditing complex libraries and writing cool exploits? Attend @OSTIFofficial's meetup where our very own @Th3Zer0 and @suidpit will talk about the "Security Audit of OpenEXR" 🗓️: Dec 02 🕗: 20:00 CET RSVP:
Tweet card summary image
luma.com
View and subscribe to events from OSTIF Meetups on Luma.
0
6
8
@bl4sty
blasty
2 months
can we please get the libxml2 and ffmpeg people some cold cash, lambo's and decent quality blow as a token of appreciation for all the ASAN splats we throw over the fence and want to have fixed pronto? I know one man's trash (CVE's) is another man's treasure, but we gotta respect
1
11
88
@TheSAScon
TheSAS2025
3 months
You’ve done everything right: least privilege, PAM solution deployed, users don’t even know passwords. What could go wrong? Paolo Cavaglià (@Paupu_95) from Shielder has the answer in his #TheSAS2025 talk, "Grand Theft Credential: Ransomware Gangs’ Wet Dream" 🏰 His team spent
0
4
11
@ShielderSec
Shielder
9 months
Last week @Apple released MacOS 13.4 which contains a fix for a vulnerability @suidpit exploited to escape the Sandbox. Update now and stay tuned for the technical details! Ref: https://t.co/fSRCbM8WbQ
0
8
18
@not4nhacker
Francesco Enrietti
9 months
Except @TumpiConIT of course
0
0
1
@not4nhacker
Francesco Enrietti
9 months
A bit late but who cares. This week I was lucky enough to attend @1ns0mn1h4ck, and it was a great event, probably my new favorite conf
1
0
0
@ShielderSec
Shielder
9 months
In Lausanne for @1ns0mn1h4ck? Don’t miss the chance to meet our very own @not4nhacker! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while!
5
3
5
@TumpiConIT
TumpiCon
11 months
Hey hackers! We’ve started sending out the first invites — check your inbox! 👀 Didn’t get one? Take the fast track and submit a talk!
0
8
14
@ShielderSec
Shielder
1 year
During a recent engagement @Mindlaess_ hacked his way through @vtigercrm which led to discover a privilege escalation and a SQL injection. Learn more in the dedicated advisories: - CVE-2024-42994 #sqli https://t.co/dRCKRNwFS0 - CVE-2024-42995 #privesc https://t.co/FyzBVR04xx
0
9
18
@ShielderSec
Shielder
2 years
Back in December 2023 our researchers @Th3Zer0 @suidpit and @Mindlaess_ performed an audit sponsored by @awscloud and facilitated by @OSTIFofficial on boost. It resulted in 7 findings and 15 new fuzzers. The report is now public, check the details here:
Tweet card summary image
shielder.com
Boost Security Audit, sponsored by Amazon Web Services (AWS), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
0
14
18
@ShielderSec
Shielder
2 years
We recently partnered with @OSTIFofficial to perform a security audit sponsored by @awscloud on @brefphp. The audit resulted in 5 findings promptly addresses by @matthieunapoli. The report is now public, check the details here:
Tweet card summary image
shielder.com
Bref Security Audit, sponsored by Amazon Web Services (AWS), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
0
13
24
@ShielderSec
Shielder
2 years
Hey hackers - attending @nullcon? Pop to say hi and talk about AppSec and VR! You can find @smaury92 @Th3Zer0 @suidpit @not4nhacker around 🖖🏿
0
2
13
@CNviolations
Community Notes & Violations
2 years
81
929
13K
@not4nhacker
Francesco Enrietti
2 years
PoV: You try to submit a solution to a @Ch0pin challenge:
1
0
8
@ShielderSec
Shielder
2 years
Ever wondered how to binary diff router firmwares to write n-day exploits? Learn how @Th3Zer0 and @suidpit combined unblob, binexport, ghidra, Qiling, and an Asus router to write an exploit for CVE-2023-39238. The outcome was unexpected ... 1/7
Tweet card summary image
shielder.com
Notes on patch diffing, reverse engineering and exploiting CVE-2023-39238, CVE-2023-39239, and CVE-2023-39240.
1
18
59
@itsandrewgao
andrew gao
2 years
A 🧵 of peer reviewed published scientific research where the authors left out a key coauthor 😉: “As an AI language model…” @MicrobiomDigest
113
1K
7K
@teej_dv
teej dv 🔭
2 years
"I use Linux as my operating system," I state proudly to the unkempt, bearded man. He swivels around in his desk chair with a devilish gleam in his eyes, ready to mansplain with extreme precision. "Actually," he says with a grin, "Linux is just the kernel. you use GNU+Linux." I
145
530
6K
@ZenOfDesign
Damion Schubert - @ZenOfDesign.com on bsky
2 years
The last week on Twitter has been really an amazing string of WTF, even by the impressive standards of Elon. It's really funny when you put all the pieces together. it's important to start at the beginning. Twitter's pretty broke. (amusing thread)
112
4K
20K
@RightWingCope
Right Wing Cope
2 years
Marco Rubio CANNOT read 💀
103
2K
39K