@MiniMjStari
iAccount based inEurope!
About this account
- Account based in
- Europe
- Connected via
- West Asia Android App
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
عاقبت رقص کنان پیش خدا خواهم رفت؛
!IN YOUR HEART
Joined March 2018
- Tweets49.2K
- Following471
- Followers1.5K
- Likes136K
How I Could've Accessed 17 Trillion Microsoft Records
blog.faav.net/how-i-couldve-… :)
MJ_The_DJ🇮🇷 retweeted
There's still some novel attack vectors that are only being operationalised now. @justinsteven is presenting on his research on timing attacks at @BSidesCbr today, and has released tturl as open source! github.com/tantosec/tturl - Justin/Tanto have put a lot of work into this.
MJ_The_DJ🇮🇷 retweeted
I’m excited to share that I’m joining @OpenAI on the Agent Security team!
After an incredible three years at @RobinhoodApp , I’m closing out a chapter that taught me a tremendous amount. I had the opportunity to work across offensive security, red teaming, and penetration testing, while learning from some incredibly talented people along the way. I’m especially grateful to my teammates, mentors, and everyone I had the chance to work with for making my time at Robinhood such a rewarding experience.
I’m looking forward to bringing that experience to OpenAI and helping secure the next generation of agentic systems. Onward to AGI!
MJ_The_DJ🇮🇷 retweeted
سالها قانونمند کار کردم
تهش چی
رنک های خفن دنیا رو تاچ کردم
آسیب پذیری های خاص کشف کردم
روی معروف ترین oauth های معروف ترین شرکت های دنیا آسیب پذیری کشف کردم
کار های بزرگی انجام دادم
هیچکدوم ساده و کم نبودن
هیچوقت هم دنبال انجام کار های کوچیک نبودم
تهش چی؟
میدونید تهش چی؟
This work was done by our team @HacktronAI led by @rootxharsh along with me and @iamnoooob.
We have published the full details of the exploit chain, as well as how we discovered it, on our blog here:
hacktron.ai/blog/hacking-ope…
داره راهنمایی میکنه طرف و اینی که گفت اپن سورس باید بشه بدون لایسنس بخاطر همین قضیه "اوپن سورس بودنه که بدون مالکیته" و خب در کل تمیز جلو بره داستان وگرنه بازم همون اش و همون کاسه اس.
"3 random dudes”
1. hacked apple, again and again.
httpvoid.com/Apple-RCE.md
httpvoid.com/Hello-Lucee!-Le…
httpvoid.com/Hacking-Apple-w…
2. your github enterprise is our github enterprise.
httpvoid.com/GitHub-Enterpri…
3. get a discord message from me, get pwned.
hacktron.ai/blog/discord-rce
youtube.com/watch?v=R3SE4VKj…
4. oh yeah, at one point we basically had shells across the electron ecosystem. check the DEF CON research.
media.defcon.org/DEF%20CON%2…
5. your supabase database is my database.
hacktron.ai/blog/supapwn
6. we got the posthog prod database.
hacktron.ai/blog/posthog-rce
7. react2shell? vercel paid us $170k for helping secure their waf.
hacktron.ai/blog/react2shell…
8. your palo alto vpn is my vpn.
hacktron.ai/blog/cve-2026-02…
9. ai ides? we got shells for you, antigravity
hacktron.ai/blog/hacking-goo…
10. windsurf rce.
youtube.com/watch?v=23Mz7qcR…
11. turning cluely into malware.
hacktron.ai/blog/hacking-clu…
12. ai browsers? sure, uxss: your perplexity browser is my browser.
hacktron.ai/blog/perplexity-…
13. openai atlas too. kinda uxss
hacktron.ai/blog/hacking-ope…
14. hey, it’s not even our first time hacking discourse.
projectdiscovery.io/blog/dis…
15. adobe coldfusion: pre-auth rce. because apparently we needed another one.
projectdiscovery.io/blog/ado…
there’s a lot more. go dig.
anyway, yes: “3 random dudes.”
and @HacktronAI is full of more random dudes like these.
MJ_The_DJ🇮🇷 retweeted
I’ve been using a custom extension on my daily targets for a while. Writing target-specific regexes lets me track new endpoints and catch bugs on upcoming features before they even fully launch.
MJ_The_DJ🇮🇷 retweeted
Confirmed IDOR, Medium severity (CVSS 5.0), full admin record disclosure, reported, validated, fixed by @Zoho. Payout: $50.
Policy says "up to $200" but there's no guarantee you'll see anywhere near that.
Not worth the time/effort for the payout you'll actually get. #bugbounty
MJ_The_DJ🇮🇷 retweeted
Cache poisoning isn’t always about unkeyed input🔑
At @BugBountyDEFCON, @brumens2 showed how cache key injection can lead to unauthenticated cache deception, CPDoS and stored XSS via scheme fragments 🧪
This research is now live on our blog 👇
yeswehack.com/lab/research-c…
MJ_The_DJ🇮🇷 retweeted
۱/۹
ظهر یکشنبه بود
گوشیم هنگ کرد
خاموشش کردم و دیگه روشن نشد
رفتم پاساژ علاءالدین
اولین مغازه رفتم داخل
قیمت مناسبی گفت و منم قبول کردم
موقع تحویل گفت ۱۱/۴۰۰ !
منم پرداخت کردم متاسفانه
شب پیام دادم که فاکتور رو بفرست
نفرستاد
حتی آدرس دقیق مغازه هم نمیدونستم و فقط چشمی بلد بودم
Default configuration of WKWebView can cause downloaded files to instead be rendered on the host page.
This allows HTML injection, and sometimes even XSS, in countless iOS and WebKit apps.
PlayStation 5. Firefox. X. Instagram. TikTok. Telegram. Binance...
Breakdown and POC. 🧵
MJ_The_DJ🇮🇷 retweeted
The site should now display linked articles. The navigation should also be smoother.
I also had a word with Judgy McJudgerson 🧑⚖️, and so we now have 1,763 articles in the repo!
Thanks to those providing links as well 🙏
webhacklist.com
github.com/irsdl/webhacklist
webhacklist.com now includes many more articles - 1,654 to be exact!
Featuring @garethheyes as an author in the screenshot with 40 identified articles! 🫡🔥