Julien | MrTuxracer

@mrtuxracer.bsky.social

CEO @rcesecurity.com | Full-time #BugBounty | @hacker0x01.bsky.social H1-Elite | $1,500,000 Overall Bounties | ❤️ IDA Pro | Mobile Hacker

I try to get Rocket Software to fix my pre-auth SSRF affecting TRUfusion for 8 months now. Considering I'm doing this for free, and they didn't even bother to credit me last time, I feel they don't really care. Maybe I shouldn't care either and drop a 0day (+chain to RCE)... #security

In terms of that, big shout-out to @proton.me for their stance on #privacy and for their Mail/Drive/Pass products that are a perfect alternative to some of these products! Cheers guys! Appreciate your hard work!

Julien | MrTuxracer@mrtuxracer.bsky.social · last yr.

I am a huge fan of the #BuyFromEU movement! So far, I've ditched a lot of US stuff already, including Microsoft, Dropbox, 1Password, Notion, Grammarly, Amazon, Slack, and Google. This helped a lot: european-alternatives.eu

I'll publish 4 CVEs later today, including one unauthenticated Root/SYSTEM-level RCE. I'm a bit nervous, TBH, because it potentially affects 15k systems on the internet. But, according to the vendor, most instances should've been updated already 😬

Let's say you have a web app that runs on Windows and has its own auth system (so it's decoupled from Windows Auth). It has a built-in feature that allows admin users of the web app to execute code on the underlying server. However, it does so using NT Authority/SYSTEM. Is this a vulnerability?

When you jump on an AI trend just remember the environmental harm that’s causing for absolutely nothing of value whatsoever. Then decide if it’s worth it for an unimpressive image. Just sayin

After being active here for a while now, I noticed that I don't have the same reach compared to X (i.e., waaaaay fewer visits on my blog). I'm considering reposting my stuff there again for visibility; maybe with a delay to lure more users to Bluesky? 🤔