
truff
@truffzor
Followers
286
Following
2K
Media
4
Statuses
139
Joined June 2009
Some time ago while hunting with @Icare1337 and looking for bugs in Ghostscript I found a vulnerability that allows to local file read / write. This led to CVE-2025-46646. - #infosec #bugbounty.
4
6
35
Some time ago I found 2 vulns in Collabora Online that when chained allowed to arbitrary file write. When digging further with my colleague @Icare1337 we found out a pre auth RCE in a largely used open source software. We'll do a write up later. CVE below:.
1
1
14
RT @yeswehack: Half of our 2025 Bucket List has already been achieved 🤯. Kudos to @truffzor, @Icare1337 & @LdrTom for the epic collab, and….
0
5
0
RT @kevin_mizu: I'm thrilled to finally share my research on HTML parsing and DOMPurify at @GreHack 2024 📜. The research article is availab….
0
179
0
RT @yeswehack: 🎬 #TalkiePwnii is LIVE!. Introducing our new series starring @pwnwithlove! In each video, Pwnii will break down Dojo challen….
0
17
0
RT @SwiftOnSecurity: One time I tried to explain Kerberos to someone. Then we both didn't understand it.
0
381
0
My team (France) finishes first at the @Hacker0x01 #AmbassadorWorldCup qualification round. What a pleasure to be part of such an engaged and skilled team !.
The results are in!🥇. Congratulations to these 32 teams who will move on to the Group Round of the 2024 #AmbassadorWorldCup! 🙌 . The next round kicks off at the end of August! Stay tuned for the latest info, and read more about the AWC here.
1
0
15
RT @thomasrinsma: I'm very excited to finally share the first part of the research I did into Ghostscript. This post details the exploitati….
0
94
0
A few weeks ago I found a vulnerability in Apache Allura while reading an excellent paper from @Sonar_Research and the according fix. CVE has been published today. #offensivesec #infosec.
4
2
27
RT @kevin_mizu: DOMLogger++ v1.0.4 is now out and available in stores! It comes with new features that allow you, for example, to easily di….
0
41
0
RT @kevin_mizu: Really proud of those bypass/mXSS variations. They involve some cool second-order DOM Clobbering and a new mutation gadget….
0
13
0
Sometime ago I found another vulnerability on Adobe Commerce while hunting with the French team during @Hacker0x01 world cup. What a pleasure to hunt with one of the best hackers I know => @Blaklis_ 🔥.
It's time of patching if you're using #AdobeCommerce or Magento!.The last version fixes 2 serious bugs, including a pre-auth RCE with some specific prerequisites. Happy to have reported CVE-2024-20758 while @truffzor reported CVE-2024-20759 :D.cc: @AdobeSecurity . #adobecommerce.
2
13
15
RT @Icare1337: Hack Me I’m Famous #2: was amazing live hacking event thank to @LouisVuitton @yeswehack #HMIF2.Big thank to my team squad o….
0
5
0