wcbowling Profile Banner
William Bowling @vakzz@infosec.exchange Profile
William Bowling @[email protected]

@wcbowling

Followers
6K
Following
340
Media
7
Statuses
216

Security Engineer at @zellic_io, a.k.a vakzz when doing bug bounties and CTFs with @pb_ctf - https://t.co/9bjECLAwXg

Tasmania, Australia
Joined July 2013
Don't wanna be here? Send us removal request.
@wcbowling
William Bowling @[email protected]
5 years
Here’s a writeup of the recent ExifTool bug (CVE-2021-22204) I discovered while working on the #bugbounty program at @gitlab! Issue was in the DjVu module but can be embedded it most other formats. Make sure to patch GitLab and ExifTool! https://t.co/sWxkHPTRJS
devcraft.io
Background
12
258
644
@zellic_io
Zellic
5 days
Last month, Zellic researcher @farazsth98 gave an internal talk on pwning Linux kernel. He teased an exploit he'd be submitting to a 0day challenge. Today, @farazsth98 and his teammate just won $40,000 for a Linux kernel 0-day! Congratulations Faith!
@wiz_io
Wiz
6 days
Team CCC (@u1f383 & @farazsth98): Team CCC dropped a Linux Kernel 0-day vulnerability that won them 3rd place (tied) and $40,000. Clean exploit, big win, and stronger Linux security.
2
23
373
@zellic_io
Zellic
3 months
Bad auditors miss obvious bugs. We built an AI tool that finds them. Introducing V12: the only autonomous Solidity auditor that actually finds Highs and Criticals. We'll be releasing it for free. V12 finds Crits in Zellic audits, High/Mediums in Cantina, and a bug in Pendle.
77
139
722
@zellic_io
Zellic
4 months
You’re probably using WebViews wrong. There are a million ways to use a WebView wrong. Properly securing a WebView is hard. In this thread, we’ll cover common vulnerabilities in wallet WebView implementations and the ways to properly secure WebViews.
1
39
245
@zellic_io
Zellic
8 months
How to spot misleading audit competition metrics Competitions are crowdsourced audits, where auditors compete to find bugs in a set timeframe. Last year, we acquired @code4rena which does these. We've also seen tons of misleading sales pitches. Here's what to watch out for: 🧵
12
55
286
@zellic_io
Zellic
9 months
With the rise of AI agents, we expect new bugs, but we’ve instead found old bugs in disguise. Let’s look at two old-school bugs we found while looking at elizaOS: • An SSRF allowing internal services to be accessed • An LFI allowing host files to be read Let’s dive in 🧵
1
11
71
@kamensec
kamensec
11 months
Just completed my 10th audit as a contractor @zellic_io and these are my top favourite things about this place: 1. They have a diverse and deep talent pool. World top Web security, Cosmos, Rust, Golang, MOVE. They have experts in every direction I want to move into (pun
4
8
79
@zellic_io
Zellic
1 year
What happens when Random() isn’t random? Here’s how popular projects, including Proton Wallet and the Dart SDK were all affected by the same underlying weakness we uncovered in the Dart/Flutter ecosystem. All issues found were responsibly disclosed with the vendors. Let’s go
4
31
153
@solidity_lang
Solidity
1 year
✨ Our judges also decided to give a special mention to @wcbowling for his submission in which the bug allows a `multisig` storage variable to be overwritten, allowing the `emergencyWithdraw` function to be called by an attacker. Read @PatrickAlphaC’s thoughts on this
soliditylang.org
Posted by Vishwa Mehta & USC Judges on October 14, 2024
2
6
18
@zellic_io
Zellic
1 year
Version 0.11.0 of gnark was just released, which fixes two vulnerabilities in the Groth16 backend reported by Zellic (CVE-2024-45039, CVE-2024-45040). These affect the soundness and ZK property of generated proofs. Read on for more details and how to check if you're vulnerable.
2
22
132
@zellic_io
Zellic
2 years
Zellic has moved forward to the final voting phase for @arbitrum's Security Council! We ask delegates to vote for Zellic as the Security Council furthers our mission to maximize TVL and extends our commitment to Arbitrum and its ecosystem. Vote here:
0
7
26
@pb_ctf
perfect blue
2 years
2023 was another great year for the team! 🎉 Blue Water, a collab between perfect blue and @Water_Paddler, placed 1st in CTFtime globally!🏆 🥇1st place in 6 CTFs 💻Hosted a successful pbctf 2023 In the past, we also placed first in 2020 and 2021.✌ Looking forward to 2024!🎆
1
15
103
@zellic_io
Zellic
2 years
The dangers of integer truncation: How the Zellic team found a critical vulnerability in the @AstarNetwork. This bug allowed an attacker to drain certain LP contracts on the Astar-EVM, with no bugs required in the contracts. Read more: 🧵👇
3
41
222
@zellic_io
Zellic
2 years
Meet Cairo, the native language of Starknet. In this thread we'll: ✅ Introduce Cairo & Starknet ✅ Explore the security features of Cairo ✅ Examine potential pitfalls when writing contracts in Cairo ✅ Give you things to consider when writing secure code Let's dig in👇🧵:
5
11
33
@zellic_io
Zellic
3 years
Earlier this morning, @safemoon's Liquidity Pool was compromised and USD 8.9M worth of tokens were withdrawn. After looking at the transaction trace and the recent contract changes, we can tell you what happened:
2
6
44
@pb_ctf
perfect blue
3 years
It's finally happening! pbctf 2023 is here 🗓️ Feb 18th, 14:00 UTC to Feb 20th 02:00 UTC (36 hours) 🎁 A $10,000 prize pool Proudly sponsored by @Zellic_io https://t.co/EOKVUMmTBP
0
10
78
@RBTree_
RBTree
3 years
3
2
78
@zellic_io
Zellic
3 years
This weekend, we played 0xmonaco @matchbox_dao, a web3 gaming competition. We developed a highly profitable racing strategy by leveraging clever math and bugs. We got DQ-ed😅 In this thread, we'll break down: 🎯 our car's unique strategy 🎯 the vulnerabilities our car exploited
4
14
79
@wcbowling
William Bowling @[email protected]
3 years
CTF + Bug Bounty + GitLab? How could I refuse such a challenge 😀
@joaxcar
Johan Carlsson
3 years
This is what deep knowledge of your target can do for you while hunting for bugs! Another amazing escalation of a "trivial issue" by @wcbowling Getting at the @gitlab CTF flag https://t.co/AjUbODx20A
1
0
39
@yvvdwf
yvvdwf
3 years
My pleasure to share the details of my first #RCE:
Tweet card summary image
gitlab.com
HackerOne report #1672388 by yvvdwf on 2022-08-17, assigned to @nmalcolm:...
5
128
554