== a websec thread ==
Inspired by @0xTib3rius I wanted to post my taxonomy of the different types of web scanning as i think it's important for people getting into web security to know.
I'll frame some of these in their context as it pertains to @PortSwigger 's Burp Suite and some other tools! 👇
We've discovered yet another MCP attack technique!
Attackers can hide malicious payloads using ANSI terminal escape codes. When your AI agent processes these invisible instructions, it can leak data or compromise your supply chain without you seeing anything suspicious.
me, when cybersecurity was the center of my life: exhausted, burnt-out, struggling to balance my friends and family, mental health was poor
me, when cybersecurity is just my *job* and not *who i am*: more sleep, less anxiety, happier, calmer, a more balanced life filled with hobbies not in front of a screen
Yo, big thing: Shift.
AI seamlessly integrated into your HTTP proxy.
Use cases:
"Take this JS and build the JSON request body"
"Fill in these IDs from my notes - UserA"
"Create a match and replace rule to turn on this feature flag"
"Generate a wordlist with all HTTP Verbs"
How to find the manifest.json file of any Chrome extension:
1. Go to chrome://extensions
2. Turn on Developer mode
3. Copy the extension ID
4. Go to ~/Library/Application Support/Google/Chrome/Default/Extensions
5. Find the matching ID then find the manifest.json file!
Be careful with information from @OpenAI ! Today I was trying to write a bump bot for https://t.co/cIAVsMwwFk and asked @ChatGPTapp to help me with the code. I got what I asked but I didn't expect that chatGPT would recommend me a scam @solana API website. I lost around $2.5k 🧵
After a really long time only focused on manual web security stuff, almost everything has started to feel like a QA checklist. There are definitely people doing novel research and dropping crazy bugs, but I think a lot of the big stepping stones require people to build really in-depth stuff (like @CharlieEriksen with @WeaselJs).
When people talk about burnout, I think a lot of it has to do with the fact that there really isn’t a good narrative to tell yourself after becoming reasonably competent and working for a few years on the hands-on hacking part of security.
Let me pick out a team of 3 people and I guarantee you that we could hack pretty much any non-hyper secured target in just a few weeks. Knowing this, it’s a lot less honest to put out work like “we hacked X company” because it’s surprising to no-one who actually does this stuff. It’s getting harder, sure, but it’s still beating the same drum.
I think the collective work of everyone in the bug bounty/pentesting game has definitely massively improved security, but as an individual you just aren’t able to report enough individual vulnerabilities to feel good about the work at a sense of purpose level.
For that reason, I really think the hacking-adjacent stuff is what really becomes important after being in the weeds for so long. I have really enjoyed seeing my friends start companies, big projects, or switch into roles with more responsibility. If you are feeling kind of burnt out with the everyday hacking, I think it’s important to explore the alternatives.
This maybe isn’t super novel and it mirrors how everyone does normal job stuff, but I was stuck in this pit for a better part of this year and think maybe it could help someone. A lot of these thoughts are similar to @gf_256’s Phrack article from earlier this year.
INTRODUCING: Agentic Security - LLM Security Scanner! 🔍
🔑 Features:
Scans for prompt injections, jailbreaking & more.
Provides detailed reports & options to customize attack rules.
🔗access the GitHub Link ↓
ooh, this works on Chrome Canary :D
<input type="hidden" oncontentvisibilityautostatechange="alert(/ChromeCanary/)" style="content-visibility:auto">
If your SSRF attempts don’t work on the first try, try using hostnames that resolve to the same IP address.
https://t.co/YCjxb4VxW6 allows you to map any IP address to a hostname!
Check this out 👇
Working with APIs can be a bit awkward.
Wouldn’t it be nice if there was a tool that did all of the API calls for you, and integrated nicely with your existing tools? 🤔
Yes it would! That’s what haktrails does.
Here's what it can do 👇
https://t.co/hlYriLiRrR
In April, CNN journalists were led to the 'home' of Haitian gang lord Vitel’homme Innocent and interviewed him. He is on @FBIMostWanted's Top 10, with a bounty of up to $2 million.
I mapped their drive and found his home here: 18.5278, -72.2314. Here's how👇🧵