I spent the last year building an LLM-driven web security testing tool.
The hard part wasn’t finding bugs — it was stopping confident false positives.
I wrote up the failures, fixes, and released an offline demo showing how I verify claims before they reach a report.
I spent the last year building an LLM-driven web security testing tool.
The hard part wasn’t finding bugs — it was stopping confident false positives.
I wrote up the failures, fixes, and released an offline demo showing how I verify claims before they reach a report.
Meet jsrip — an open-source JavaScript Analyzer
Crawls targets via Playwright
Downloads & beautifies JS files
Finds secrets, tokens & API endpoints
Exports reports in many formats
👉Try it: https://t.co/KgypsMlZgs
#BugBounty#InfoSec#Hacking#OSINT#CyberSecurity#Recon#jsrip
Meet jsrip — an open-source JavaScript Analyzer
Crawls targets via Playwright
Downloads & beautifies JS files
Finds secrets, tokens & API endpoints
Exports reports in many formats
👉Try it: https://t.co/KgypsMlZgs
#BugBounty#InfoSec#Hacking#OSINT#CyberSecurity#Recon#jsrip
Being a hacker has little to with your job.
It's in your blood, your soul— it's a way of thinking. It's curiosity, creativity, and challenging norms.
It's a relentless pursuit of knowledge, it's embracing the unconventional.
Whatever you do today, bring the hacker mindset.
Lots of analysis of the xz/liblzma vulnerability. Most skip over the first step of the attack:
0. The original maintainer burns out, and only the attacker offers to help (so the attacker inherits the trust of the project built by the maintainer).
Read their words👇🏻 1/
Ok fam. I’m giving away TWO free tickets to my course which takes place in two/three weeks.
All you have to do to win is like, retweet this tweet, and reply with “https://t.co/VnOqGJ5Yyo!”
I’ll pick winners next week!
If you haven’t seen my course, check out the link!
I've run into a lot of JavaScript obfuscation in CTFs and in life in general. Came across this video which is a brilliant walk through of how one such method works.
https://t.co/cyPYNUj4sX
🧵A Practice Target SUPER Thread🧵
Offensive Security People!
Want to take your theory to live targets?
Need some resume filler?
Just want to keep fresh and practice?
Here's a thread of my favorite practice targets to recommend.
🚨Retweet, follow, & like for more! 🚨
1/