
nytr0gen
@nytr0gen_
Followers
3K
Following
15K
Media
46
Statuses
781
Ambassador @Hacker0x01 | CTF Player @WreckTheLine
Romania
Joined May 2013
insane
Found an RCE in Google Web Designer :) Very similar to the CSS Injection to RCE found by Bálint Magyar. https://t.co/BpOJ4sfvNx
1
1
11
check out this fantastic work by @Zettergren0x00
Re-made Frans little PostMessage tracker for manifest V3 - (that actually works) - with a lot of quality of life improvements. Feel free to take it for a spin! #BugBounty
https://t.co/L8jNEOzkPi
0
0
1
34 years since Linus first announced Linux today! Probably the greatest open source project of all time. What an achievement for mankind.
gbhackers.com
August 25, 2025, marks the 34th anniversary of Linux, a project that began as a modest hobby and has grown into the bedrock of modern digital infrastructure.
40
159
2K
Just published my first blog post "Cache Deception + CSPT: Turning Non Impactful Findings into Account Takeover" You can read the full write-up here: https://t.co/pfLArv8zUu
zere.es
Recently, while auditing the main application of a private bug bounty program, I discovered a Client-Side Path Traversal (CSPT) and a Cache Deception vulnerability. Individually, these issues were...
26
130
540
Here’s the second half of our Friday lineup at @DEFCON – and it’s just as stacked. 🔥 @DaneSherrets, @Shlibness, @mgianarakis, Jordan Macey, @CryptoGangsta, @scriptingxss, @nytr0gen_, @erbbysam, and @BrunoModificato. See you there. 👀 #BugBounty
0
8
26
Last year I found a XSS bug in Google IDX here's a detail writeup about it. Hope you will enjoy it's kinda lengthy :p Shoutouts to @MtnBer for finding the original bug in Gitlab and @kl_sree @sivaneshashok for the required chains to complete the exploit. https://t.co/L3e5rCrUuy
sudistark.github.io
Technical breakdown of an XSS vulnerability in Google IDX Workstation.
12
85
361
I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥 The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇 https://t.co/SgsSyxoEMR 1/4
11
170
447
Most edgy talk this year at #DEFCON33 📐
Don't miss "Hacking the Edge: Real-World ESI Injection Exploits" by Robert Vulpe (@nytr0gen_) on Friday, August 8 at 04:30 PM inside the Village. Read more at https://t.co/e3glU8gWAU
#BugBounty #DEFCON33
3
1
21
hi
We're excited to announce that Robert Vulpe (@nytr0gen_) will be speaking at the Bug Bounty Village at DEF CON 33! Stay tuned for more details on their talk, you won’t want to miss it. #BugBounty #DEFCON #BBV #BugBountyVillage
3
3
47
🔥 A new (more difficult) era for mXSS will come soon! If nothing breaks, Chromium will start escaping "<" and ">" in attributes starting with M138. See https://t.co/lXfe86tpmd for details.
2
17
88
Today, we’re announcing the preview release of ty, an extremely fast type checker and language server for Python, written in Rust. In early testing, it's 10x, 50x, even 100x faster than existing type checkers. (We've seen >600x speed-ups over Mypy in some real-world projects.)
125
508
5K
I just finally watched @emil_lerner talk. It's a really good talk on image processing - definitely worth 20 minutes of your time! https://t.co/7Qu4TPy3Sn
5
14
109
I made a tool to help test archive (zip/tar) extraction bugs (synk working directory into archive, add path traversals, links, permissions, etc):
github.com
Archive Alchemist is a tool for creating specially crafted archives to test extraction vulnerabilities. - avlidienbrunn/archivealchemist
1
31
174
Check out our speakers and get your tickets! https://t.co/BPFrNoym2Y
#BSidesHBG #infosec #cybersecurity #BSides
0
1
1
We are 4 weeks out from BSides Harrisburg 2025! Be sure to buy your tickets before me sell out! 🗓️Friday April 25, 2025 🎟️ https://t.co/Lsid8QgsNq
#infosec #cybersecurity #BSides #BSidesHBG #Harrisburg
0
5
5
I thought I had good reason to code up a vectorized binary search, which was kind of fun to do, but then I checked, and the standard torch.searchsorted() works well enough. For all the emphasis given in computer science curriculums and job interviews, actually implementing
77
61
1K
📣We’re thrilled to welcome @nytr0gen_ to the Speaker lineup for BSides Harrisburg 2025! Robert will speak on “Exploiting CRLF Vulnerabilities for Account Takeovers: Lessons from Bug Bounty Programs” 🗓️Friday April 25, 2025 #BSidesHBG #infosec #cybersecurity #BSides
2
2
10