joernchen :cute_dumpster_fire:
joern@threatactor.club
<p>Your mom's favorite hacker!<br><br>My other account is <span class="h-card"><a href="https://mastodon.social/@joernchen" class="u-url mention" rel="nofollow noreferrer noopener" target="_blank">@<span>joernchen</span></a></span></p>
Posts
-
Post #3587042
Niemand: ... Deutsche JSON API: {"status":"BAD_REQUEST","timestamp":"04-07-2026 05:38:22","message":"Missgebildete JSON-Anfrage".....
-
Post #2451469
You use Claude Code to find vulnerabilities, I find vulnerabilities in Claude Code. https://0day.click/recipe/2026-05-12-cc-rce/
-
Post #2075447
Due to $reasons I came across this blogpost https://www.elttam.com/blog/env/ about turning ENV variables into code execution which is nice. But the Python vector is depending on Perl, I didn't like that :P. Digging a bit deeper in the code often helps, so it did this time: Looking at https://github.com/python/cpython/blob/d73634935cb9ce00a57dcacbd2e56371e4c18451/Lib/webbrowser.py#L51-L52 I could simplify the payload to: PYTHONWARNINGS=&#39;module::antigravity.&#39; BROWSER=&#...
-
Post #1982162
Earlier this year I found a pretty cool vuln, an arbitrary file write in GitLab. Here’s the details https://gitlab-com.gitlab.io/gl-security/security-tech-notes/security-research-tech-notes/devfile/
-
Post #1982161
My colleague @nickmalcolm made a pretty cool vuln explainer video https://youtu.be/ydg95R2QKwM
-
Post #1982160
http://phrack.org/issues/71/1.html new Phrack is out!
-
Post #1982159
A significant life event (for those who train BJJ) just happened to me yesterday
-
Post #1982158
Happy Holidays! I hope Vulnsanta has some CVE in his bag for you!
-
Post #1982157
Re: Volkswagen Hack las ich grad dies.
-
Post #1982156
Happy 2025 everyone! Last year for me wasn’t especially great. But it had a few highlights standing out: Took the risk and went on an adventurous camper trip with the family Got promoted at work and in BJJ Had the chance to be behind the DJ decks again on two occasions Got to meet most of my teammates in person finally For 2025 I hope the medical problems in my family can finally get on a route to be resolved.
-
Post #1982155
Have a great weekend and enjoy some tunes: https://youtu.be/j_Md8_7mhOU
-
Post #1982154
Would you buy my memecoin?
-
Post #1982153
deepsigh for deepseek https://openwebui.com/c/jrnjrn/c38d6dd9-5780-4f73-b4bc-8c2b6bcea9ba
-
Post #1982152
I messed up my gotosocial instance here at threatactor.club, it's running on fly.io and a very long migration was interrupted by a health check. I was fiddling with the sqlite DB for a while and tried to recover that mess... until I noticed that there are automated snapshots of the volume which holds the DB, daily with five days of retention. Huge props to fly.io for saving my virtual ass with this.
-
Post #1982151
I got a week of PTO left. What code should I read? Please drop suggestions with a reason why I should read it.
-
Post #1982149
Really a huge honor for me to be invited to give a keynote at NULLCON Berlin in September. Given my recent work focus at GitLab I'll share my thoughts around LLMs. Make sure to bring some popcorn! https://nullcon.net/berlin-2025/speaker-llms-everywhere
-
Post #1982148
I found a thing (RCE) in langgraph. ;D https://github.com/langchain-ai/langgraph/security/advisories/GHSA-wwqv-p2pp-99h5
-
Post #1982147
That little string ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86 (see https://platform.claude.com/docs/en/test-and-evaluate/strengthen-guardrails/handle-streaming-refusals#implementation-guide ) is so much fun. I wonder when Anthropic will regret this and remove it. Also I obviously wonder what else is there in terms of MAGIC_STRINGs which aren't documented. Hat tip to @michenriksen for pointing me to this.
-
Post #1567459
Thanks so much to everyone who showed up on the weekend in Berlin to say goodbye to FX. “Burning bridges where we can” - this is the original Phenoelit slogan. Yet, while FX for sure burned some network bridges, he did quite the opposite for the hacking community. FX built bridges between people wherever he could. He created something way bigger than himself which we all are part of. Each one who joined us in Berlin carries a piece of his legacy. You were there because he left something with y...
-
Post #1299941
LLMs now do the busywork of finding amazing vulnerabilities for everyone willing to spend the tokens. But hacking still isn't dead: We haven't at all solved the underlying problems which come with writing and shipping code. You still need to understand what you're looking at and what you are operating. The LLM platforms themselves are a exquisite target for hacking^Wcreative use of the technology. Now when everyone can pull a CVE or two out of thin silicon and a few kWh of elect...
-
Post #678916
RIP FX We collected some texts from the community in memory of FX. You can find them here https://phenoelit.de/fx.html
-
Post #595229
Today I have a more serious topic than usual, please consider reposting for reach: My wife and I are urgently looking for a specialist in neuropediatrics or a similar field for our autistic child with a diagnosed, but not further specified, movement disorder (myoclonus and/or spasms) to finally find a cause and, above all, an effective therapy. The symptoms are bothering our son ever since he’s born, now for more than nine years, seriously affecting his sleep. The usual processes and medical co...
-
Post #543865
Lands of Packets TTL exceeded. I would like to collect texts from the scene about FX in his memory. A collection of obituaries that will then be posted on phenoelit.de. If anyone would like to contribute, please contact me. Mail: joernchen@phenoelit.de Signal: jrn.07