@pyn3rdi
iAccount based inNorth America!
About this account
- Account based in
- North America
- Connected via
- North America App Store
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
I’m pyn3rd.
Melbourne, Victoria
Joined February 2016
- Tweets1.1K
- Following733
- Followers15.2K
- Likes4.8K
Let’s connect on LinkedIn.
linkedin.com/in/ewan-xu-6b61…
#WAF Bypassing #AWS #CloudFront & #ALB WAF: Exploring the attack surface of a dual-layer web protection architecture.
The first layer: a malicious XSS payload was blocked by CloudFront’s global WAF. By altering the XSS event-handler tag, I was able to bypass the first layer.
The second layer: the request was then blocked by the regional WAF associated with the ALB. By exploiting normalization differences, I was able to bypass the second layer as well.
The result: the XSS payload reached the origin and ultimately executed in the browser.
In the Tomcat August security bulletin, 6 CVEs were independently discovered and reported by our team (@4ra1n_x and unam4).
Official severity ratings: 2 Important and 4 Low.
If HackerOne’s Internet Bug Bounty hadn’t been suspended, we probably could’ve earned at least a few thousand bucks in bounties.
Apparently, I’m not done hunting JDBC vulnerabilities in IBM products.
It started with my first report years ago. Found another one this year, bringing the total to 4 vulnerabilities reported to IBM, together with @4ra1n_x and unam4.
The rabbit hole goes deeper.🐰
Make JDBC Attacks Great Again!🔥
ibm.com/support/pages/node/7…
ibm.com/support/pages/node/7…
Yet another real-world JDBC attack case.
Back in my Black Hat talk, I pointed out that in cloud environments, attacks can originate from a tenant and reach the control plane, or even enable lateral movement across tenants—especially when container or VM isolation is not properly enforced.
At the time, very few people seemed to understand what I meant, and most dismissed the risk. It’s interesting to see these scenarios continue to emerge in the real world.
This quoted post is unavailable.
Hacking Google with A.I. for $500,000
brutecat.com/r/hacking-googl…