Francesco Enrietti
@not4nhacker
Followers
56
Following
222
Media
3
Statuses
57
Chief "Have you ever heard about OAuth?" Officer @ShielderSec
Joined January 2022
1/6 What started as a routine 24-hour vulnerability research of PostHog turned into quite the rabbit hole... 🕳️🐇 I ended up finding a way to chain a simple SSRF, a ClickHouse Postgresql Table functions SQL Escape 0-day, and default DB credentials into a full RCE. It’s a fun
3
8
81
Want to learn more about our approach into auditing complex libraries and writing cool exploits? Attend @OSTIFofficial's meetup where our very own @Th3Zer0 and @suidpit will talk about the "Security Audit of OpenEXR" 🗓️: Dec 02 🕗: 20:00 CET RSVP:
luma.com
View and subscribe to events from OSTIF Meetups on Luma.
0
6
8
can we please get the libxml2 and ffmpeg people some cold cash, lambo's and decent quality blow as a token of appreciation for all the ASAN splats we throw over the fence and want to have fixed pronto? I know one man's trash (CVE's) is another man's treasure, but we gotta respect
1
11
88
You’ve done everything right: least privilege, PAM solution deployed, users don’t even know passwords. What could go wrong? Paolo Cavaglià (@Paupu_95) from Shielder has the answer in his #TheSAS2025 talk, "Grand Theft Credential: Ransomware Gangs’ Wet Dream" 🏰 His team spent
0
4
11
Last week @Apple released MacOS 13.4 which contains a fix for a vulnerability @suidpit exploited to escape the Sandbox. Update now and stay tuned for the technical details! Ref: https://t.co/fSRCbM8WbQ
0
8
18
A bit late but who cares. This week I was lucky enough to attend @1ns0mn1h4ck, and it was a great event, probably my new favorite conf
1
0
0
In Lausanne for @1ns0mn1h4ck? Don’t miss the chance to meet our very own @not4nhacker! If you're into cursed OAuth hacking techniques or breaking mobile apps, find a comfy spot -- you might be there for a while!
5
3
5
Hey hackers! We’ve started sending out the first invites — check your inbox! 👀 Didn’t get one? Take the fast track and submit a talk!
0
8
14
During a recent engagement @Mindlaess_ hacked his way through @vtigercrm which led to discover a privilege escalation and a SQL injection. Learn more in the dedicated advisories: - CVE-2024-42994 #sqli
https://t.co/dRCKRNwFS0 - CVE-2024-42995 #privesc
https://t.co/FyzBVR04xx
0
9
18
Back in December 2023 our researchers @Th3Zer0 @suidpit and @Mindlaess_ performed an audit sponsored by @awscloud and facilitated by @OSTIFofficial on boost. It resulted in 7 findings and 15 new fuzzers. The report is now public, check the details here:
shielder.com
Boost Security Audit, sponsored by Amazon Web Services (AWS), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
0
14
18
We recently partnered with @OSTIFofficial to perform a security audit sponsored by @awscloud on @brefphp. The audit resulted in 5 findings promptly addresses by @matthieunapoli. The report is now public, check the details here:
shielder.com
Bref Security Audit, sponsored by Amazon Web Services (AWS), facilitated by Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
0
13
24
Hey hackers - attending @nullcon? Pop to say hi and talk about AppSec and VR! You can find @smaury92 @Th3Zer0 @suidpit @not4nhacker around 🖖🏿
0
2
13
Ever wondered how to binary diff router firmwares to write n-day exploits? Learn how @Th3Zer0 and @suidpit combined unblob, binexport, ghidra, Qiling, and an Asus router to write an exploit for CVE-2023-39238. The outcome was unexpected ... 1/7
shielder.com
Notes on patch diffing, reverse engineering and exploiting CVE-2023-39238, CVE-2023-39239, and CVE-2023-39240.
1
18
59
A 🧵 of peer reviewed published scientific research where the authors left out a key coauthor 😉: “As an AI language model…” @MicrobiomDigest
113
1K
7K
"I use Linux as my operating system," I state proudly to the unkempt, bearded man. He swivels around in his desk chair with a devilish gleam in his eyes, ready to mansplain with extreme precision. "Actually," he says with a grin, "Linux is just the kernel. you use GNU+Linux." I
145
530
6K
The last week on Twitter has been really an amazing string of WTF, even by the impressive standards of Elon. It's really funny when you put all the pieces together. it's important to start at the beginning. Twitter's pretty broke. (amusing thread)
112
4K
20K