Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Konstantin :C_H:

@kpwn@infosec.exchange
  • Open on infosec.exchange

I'm a hacker and mainly post about web security.

By profession, I am a pentester and team leader @usdAG@infosec.exchange.

I like to explain and understand things and I am convinced that the two go hand in hand.
So my posts are mostly of an educational nature.

Lately, I spend most of my free time developing CVE Crowd.

⎯⎯⎯⎯⎯⎯

Recent topics:
#CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

0 Followers
0 Following
14 Posts
Joined December 21, 2022
Pronouns:
he/him
Developer of:
https://cvecrowd.com
Blog:
https://kpwn.de

Posts

Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · Jul 19, 2026
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange
I've finally replaced the old-school CAPTCHA required to sign up on https://cvecrowd.com with an open-source, privacy preserving, accessible, and globally compliant alternative: ALTCHA It relies on proof of work and I am super hyped to see whether it will prevent bots from signing up. I'll keep you updated :)
0
0
0
0
Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · Jul 11, 2026
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange
Replying to @unnon89@nrw.social
@unnon89@nrw.social @kattascha@chaos.social Du meinst Cat Kontrolle.
1
0
0
0
Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · Jun 04, 2026
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange

Apparently #Safari on #iOS applies img-src directives of the content security policy to *object tags* that load images like so: https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/551/708/143/302/638/original/8f107909c923fd55.png">

This was the reason, why https://cvecrowd.com did not display avatars on iOS devices: I was using object tags and the object-src directive.

Fixed it by adding an img-src directive as well.

4
2
1
1
Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · Jun 03, 2026
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange

Anyone else having the issue that avatars on https://cvecrowd.com are not loading on a mobile device?

CVE Crowd | Crowd Intelligence on CVEs
cvecrowd.com

CVE Crowd | Crowd Intelligence on CVEs

Keep track of actively discussed CVEs and integrate them into your application or business!

0
2
0
0
Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · Jun 02, 2026
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange

Perfect streak: 2 😊
I solved the daily #CluesBySam, Jun 2nd 2026 (Medium), in 04:42
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
https://cluesbysam.com

0
0
0
0
Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · Jun 01, 2026
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange

One reason to look forward to mondays. Easy Clues by Sam puzzles.

I solved the daily #CluesBySam, Jun 1st 2026 (Easy), in 05:23
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
https://cluesbysam.com

0
0
0
0
Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · May 31, 2026
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange

Damn! Close enough.

I solved the daily #CluesBySam, May 31st 2026 (Hard), in less than 13 minutes
🟨🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
https://cluesbysam.com

1
0
0
0
Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · May 30, 2026
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange

This one was cumbersome. Had an early error… This always tempts me to use hints because a perfect solve isn‘t possible anymore.

I solved the daily #CluesBySam, May 30th 2026 (Hard), in less than 14 minutes
🟩🟩🟩🟩
🟩🟨🟩🟩
🟠🟩🟩🟡
🟩🟨🟩🟩
🟩🟠🟩🟩
https://cluesbysam.com

0
1
0
0
Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · May 29, 2026
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange

Perfect streak gone. But I'm still happy with today’s result, given the advanced difficulty 😊

I solved the daily #CluesBySam, May 29th 2026 (Tricky), in less than 8 minutes
🟩🟩🟩🟨
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
https://cluesbysam.com

0
0
0
0
Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · May 28, 2026
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange

Perfect solve streak: 2 🎉

I solved the daily #CluesBySam, May 28th 2026 (Tricky), in less than 13 minutes
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
https://cluesbysam.com

0
0
0
0
Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · May 27, 2026
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange

Finally a perfect solve again :ablobcatnodfast:

I solved the daily #CluesBySam, May 27th 2026 (Medium), in less than 9 minutes
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
🟩🟩🟩🟩
https://cluesbysam.com

1
0
0
0
Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · May 06, 2026
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange
Replying to @GossiTheDog@cyberplace.social
@GossiTheDog What really hurts about this is that the AI-assisted group performs better than the control group. This means its tempting to use AI to increase performance. Especially in a competitive setting (like everywhere in capitalism) you'll "win" with AI assistance. And in the end, we are left with a group of winners who have less persistence and reduced independent performance. And there's no way out.
12
1
6
0
Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · Feb 28, 2024
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange
Replying to @me@infosec.exchange

@me@infosec.exchange Who are "some people"? :)

Attack Complexity (AC) measures actions taken by the attacker to actively circumvent existing built-in security-enhancing conditions.

What kind of circumvention and evasion must be fulfilled? As far as I see there aren't any.

Attack Requirements (AT) emerge naturally as a consequence of the deployment, not explicitly as an attack mitigation.

According to your argument, it's always AT: Present because every attack requires the attacker to use and setup a computer.

For the scoring to work, you have to assume the most powerful attacker possible, who of course has already set up a rouge password reset URL.

As I said, the only real requirement is the knowledge of an existing email address. With billions of leaked email addresses on the Internet, I am not sure this is a hard requirement to overcome.

0
0
0
0
Open post
kpwn
Konstantin :C_H: @kpwn@infosec.exchange · Feb 28, 2024
Konstantin :C_H:
@kpwn@infosec.exchange

I'm a hacker and mainly post about web security. By profession, I am a pentester and team leader @usdAG. I like to explain and understand things and I am convinced that the two go hand in hand. So my posts are mostly of an educational nature. Lately, I spend most of my free time developing CVE Crowd. ⎯⎯⎯⎯⎯⎯ Recent topics: #CveCrowd, #Phishing, #CVSS, #PromptInjection, #OTP, #JavaScript, #HSTS, #BSCP

infosec.exchange
Replying to @me@infosec.exchange
@me@infosec.exchange I‘d go with: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Score: 5.1/Medium A requirement for the attack, is the knowledge of a registered email address. However, I find this not enough to justify AT:P. Active User Interaction is definitely required because the victim has to click the link. There are no subsequent systems, so we only have to care about the vulnerable system (the vulnerable web app). Confidentiality is impacted because the confidential one-time reset token is leaked. Integrity is impacted because the token can be used to change another user‘s password. What do you think?
1
1
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:15:10 UTC