Kévin Gervot (Mizu)

@mizu.re

About me? | Website: https://mizu.re | Tool: https://github.com/kevin-mizu/domloggerpp | Teams: @rhackgondins, @FlatNetworkOrg, @ECSC_TeamFrance | From: https://twitter.com/kevin_mizu

The #FCSC2026 ended today, and my write-ups are now available here: mizu.re/post/fcsc-20... 🚩 I'm really happy with the challenges I managed to create this year! It would be too long to list everything, so here's a little teaser below 👇 1/2

Bild
Kévin Gervot (Mizu)@mizu.re · 4mo ago

I'm happy to release the first version of my DOMLogger++ plugin for @caido.io! 🔎 It improves the browser extension in several ways: • Persistent, per-project storage • Temporary session recording • AI support • Stack trace reconstitution • ... 👉 github.com/kevin-mizu/d...

A quick update has been made to DOMLogger++ to add / update a few things. It's not a big deal, but it should allow interesting stuff to be done :) It should be available on the stores in the coming hours.

Bild

For the @ASIS_CTF, I created a challenge based on an interesting (novel?) DOM Clobbering technique! 🚩 In short, in non-strict mode, HTMLCollection items are not writable. This blocks property assignment, allowing unexpected values to be created 😄 👉 mizu.re/post/under-t...

Bild

I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥 The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇 gmsgadget.com 1/4

Bild

Today was my last day as a pentester at Bsecure. After a three-year journey of hunting on the side, I’m ready to go all-in as a full-time bug bounty hunter. You can read about my journey from pentester to full-time hunter here: gelu.chat/posts/from-p...

Finding Freedom, One Bug at a Time: My Journey from Pentester to Full-Time Hunter

After seven years in pentesting, I transitioned full-time into bug bounty hunting, leveraging deep experience and continuous learning. This article shares key moments and insights from that journey.

gelu.chat

I've released my CTF bot template! :D It's not a big deal, but it comes with a heavily hardened Docker setup. The bot also sends a lot of debugging information over the TCP socket (console logs, navigation), which makes remote debugging much easier! 🔎 👉 github.com/kevin-mizu/b...

BildBild

The #FCSC2025 ended yesterday, and my write-ups are now available here 👇 mizu.re/post/fcsc-2025… Btw, like every year, all the challenges have also been added to hackropole.fr! 🚩 1/2

Bild
Kévin Gervot (Mizu)@mizu.re · last yr.

This year again, with @bi.tk, we've made the Web challenges 🚩 The CTF is solo and lasts 10 days, if you have some time, please give it a look 😁 Btw, even if you're not doing Web challenges, there are 100+ challenges in various categories, you should find something you like!

This year again, with @bi.tk, we've made the Web challenges 🚩 The CTF is solo and lasts 10 days, if you have some time, please give it a look 😁 Btw, even if you're not doing Web challenges, there are 100+ challenges in various categories, you should find something you like!

Bild
ANSSI@anssi-fr.bsky.social · last yr.

#FCSC | 🐓 Le France Cybersecurity Challenge 2025 démarre maintenant ! 🎮 Crypto, reverse, pwn, web, hardware, forensics, attaque par canaux auxiliaires… Plus de 100 épreuves de difficultés variées vous attendent jusqu'au 27 avril. Rendez-vous sur : 🔗 fcsc.fr

FCSC{BtxZTB9ePWVc}

You might have noticed that the recent SAML writeups omit some crucial details. In "SAML roulette: the hacker always wins", we share everything you need to know for a complete unauthenticated exploit on ruby-saml, using GitLab as a case-study. portswigger.net/research/sam...

SAML roulette: the hacker always wins

Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library

portswigger.net

For this challenge, it was necessary to abuse a discrepancy between the DOM and the rendered page in Firefox's cache handling 💽 👉 bugzilla.mozilla.org/show_bug.cgi... This allows to shift iframe rendering from one to another leading to a sandbox bypass 🔥 👉 mizu.re/post/an-18-y...

Kévin Gervot (Mizu)@mizu.re · last yr.

With @gelu.chat, we created a challenge for the @pwnmectf inspired by a bug he found in bug bounty a year ago! 🚀 If you have some time this weekend, give it a try! 👀 👉 pwnme.phreaks.fr

I'm very happy to finally share the second part of my DOMPurify security research 🔥 This article mostly focuses on DOMPurify misconfigurations, especially hooks, that downgrade the sanitizer's protection (even in the latest version)! Link 👇 mizu.re/post/explori... 1/2