Nicolas Grégoire
@agarri.fr
📤 4387
📥 617
📝 1011
Web hacker 😈 Burp Suite Pro trainer 👨🏫 Maintainer of
@mastering-burp.agarri.fr
🛠️
pinned post!
The 2026 online public sessions of my "Mastering Burp Suite Pro" course have been published 📅 - March 24th to 27th, in French 🇫🇷 - April 14th to 17th, in English 🇬🇧
hackademy.agarri.fr/2026
PS: feel free to ping me if you'd like to temporarily block a seat or are looking for a 10% coupon 🎁
loading . . .
Agarri
Training
https://hackademy.agarri.fr/2026
about 1 month ago
0
7
7
reposted by
Nicolas Grégoire
Anna’s Archive is an incredible project aimed at preserving humanity’s knowledge and culture Their latest exploit is a near-full backup of Spotify. It includes 86 million songs, representing around 99.6% of listens 🎶
annas-archive.org/blog/backing...
loading . . .
Backing up Spotify
We backed up Spotify (metadata and music files). It’s distributed in bulk torrents (~300TB). It’s the world’s first “preservation archive” for music which is fully open (meaning it can easily be mirro...
https://annas-archive.org/blog/backing-up-spotify.html
5 days ago
0
13
6
Anna’s Archive is an incredible project aimed at preserving humanity’s knowledge and culture Their latest exploit is a near-full backup of Spotify. It includes 86 million songs, representing around 99.6% of listens 🎶
annas-archive.org/blog/backing...
loading . . .
Backing up Spotify
We backed up Spotify (metadata and music files). It’s distributed in bulk torrents (~300TB). It’s the world’s first “preservation archive” for music which is fully open (meaning it can easily be mirro...
https://annas-archive.org/blog/backing-up-spotify.html
5 days ago
0
13
6
reposted by
Nicolas Grégoire
SeanWrightSec
7 days ago
Looks like the final OWASP Top 10 (2025) has been published:
owasp.org/Top10/2025/
. Based on commits, looks like this happened 5 days ago.
loading . . .
OWASP Top 10:2025
OWASP Top 10:2025
https://owasp.org/Top10/2025/
0
5
1
reposted by
Nicolas Grégoire
9 days ago
Good read
github.com/readme/guide...
loading . . .
Publishing your work increases your luck
In 12 months, @aarondfrancis changed his life by bypassing fear and embracing risk. Now, he’s working his dream job @tuple. Get his full story on The ReadME Project:
https://github.com/readme/guides/publishing-your-work
0
3
2
reposted by
Nicolas Grégoire
The Hacker's Choice (1995)
19 days ago
THC Release 💥: The world’s largest IP<>Domain database:
ip.thc.org
All forward and reverse IPs, all CNAMES and all subdomains of every domain. For free. Updated monthly. Try: curl
ip.thc.org/1.1.1.1
Raw data (187GB):
ip.thc.org/docs/bulk-da...
(The fine work of messede 👌)
0
44
21
#Protip
Need to go really fast and HEAD is disabled? Use GET and the Range header...
16 days ago
0
5
0
reposted by
Nicolas Grégoire
Phrack Zine
23 days ago
The wait is over! Phrack 72 40th Anniversary Edition is available now. Order straight to your doorstep — the perfect gift for your fellow hacker, just in time for the holidays 🎄 No need to go to rely on the warez scene with scans anymore 😅 Order here:
www.lulu.com/shop/phrack-...
1
28
17
reposted by
Nicolas Grégoire
The Hacker's Choice (1995)
22 days ago
THC Release: 🎄Smallest SSHD backdoor🎄 - Does not add any new file - Survives apt-update - Does not use PAM or authorized_keys Just SSHD trickery....adds one line only. More at
thc.org/tips
👌
0
17
4
Looking for a Christmas gift for yourself?
#burp
#training
#2026 There’s 9 seats left for the English-speaking session, and 5 for the French-speaking one
add a skeleton here at some point
23 days ago
0
4
3
Great article 💎
add a skeleton here at some point
23 days ago
0
6
0
Printed version of Paged Out #7, collected during GreHack 2025 🤩
30 days ago
0
6
1
This vulnerability was the inspiration for the first step of the Panel challenge we played during last week’s Grehack CTF But we found a dumb bypass 😎
add a skeleton here at some point
about 1 month ago
0
4
1
reposted by
Nicolas Grégoire
Molly White
about 1 month ago
www.citationneeded.news/issue-91/#tr...
loading . . .
Issue 91 – GDP on the blockchain
The regulator set to take on primary crypto oversight is down to a single Commissioner, and new pro-crypto PACs focus on installing more Republicans in the midterms
https://www.citationneeded.news/issue-91/#trump-family-business-interests
0
48
3
reposted by
Nicolas Grégoire
ANSSI
about 1 month ago
📜 L’4N551 4 un3 m1551on 9our vou5. S1 vou5 l’4cc3973z, vou5 s3r3z 4m3n3 4 : *53rv1r l’1nt3r37 g3n3r4l 37 9ro73g3r l4 N471on f4c3 4 l4 m3n4c3 cy83r ; *1nc4rn3r l’3xc3ll3nc3 fr4nç4153 3n m4713r3 d3 cy83rd3f3n53. 9our 7rouv3r vo7r3 m1551on : 🔗
www.welcometothejungle.com/fr/companies...
0
8
7
Stealth (from Team-Teso, Phrack staff and other groups) passed away earlier this year 😢 I didn't know him personally, but his groundbreaking research has been a constant influence on my career
www.thc.org/404/
loading . . .
https://www.thc.org/404/
about 1 month ago
0
5
0
Here's the recording of the stream we made earlier this week with
@laluka.bsky.social
,
@thesytten.bsky.social
and
@rhynorater.bsky.social
If you speak French, you may appreciate its title: "Caido de Noël" 😄 🎁 🎅
www.youtube.com/watch?v=JvUm...
loading . . .
EP 208 EN | Caido de Noel ? Ft. @Agarri_FR @Rhynorater @TheSytten
YouTube video by Laluka
https://www.youtube.com/watch?v=JvUmHkUXed8
about 1 month ago
0
4
0
reposted by
Nicolas Grégoire
Matt Blaze
about 1 month ago
I really want to know the full story behind this epic hack, and yet I also hope it is never solved.
add a skeleton here at some point
14
336
82
reposted by
Nicolas Grégoire
Samuel Groß
about 1 month ago
I've uploaded the slides of my recent talk "JS Engine Security in 2025":
saelo.github.io/presentation...
. I think there'll also be a recording available at some point (otherwise I can make one as not everything's in the slides). Fantastic conference as usual, big thanks to the PoC Crew!
loading . . .
https://saelo.github.io/presentations/poc_25_js_engine_security_in_2025.pdf
0
21
10
The 2026 online public sessions of my "Mastering Burp Suite Pro" course have been published 📅 - March 24th to 27th, in French 🇫🇷 - April 14th to 17th, in English 🇬🇧
hackademy.agarri.fr/2026
PS: feel free to ping me if you'd like to temporarily block a seat or are looking for a 10% coupon 🎁
loading . . .
Agarri
Training
https://hackademy.agarri.fr/2026
about 1 month ago
0
7
7
A little command-line trick... 🛠️ 🤓 You can use `rev` twice in order to process something from right to left. For example, in order to sort /etc/passwd by shell: cat /etc/passwd | rev | sort | rev
about 1 month ago
1
0
1
La Quadrature du Net n'est pas contente des récents articles sur GrapheneOS, et elle a bien raison ! 👿 🇫🇷
add a skeleton here at some point
about 1 month ago
0
2
0
reposted by
Nicolas Grégoire
Evariste
about 2 months ago
This year, I have gone back to talk at cybersecurity conferences, presenting the talk "app.alert(1) is the new alert(1)", at BSides Sofia and BSides Krakow. I have analyzed 4 CVEs: now you can find 3 PoCs in my GitHub :) because slides are cool, but code is better:
github.com/luigigubello...
loading . . .
GitHub - luigigubello/bsides-2025: My talk "app.alert(1) is the new alert(1): PDF files as a vector to inject JavaScript code in web applications", presented at BSides Sofia 2025 and BSides Krakow 202...
My talk "app.alert(1) is the new alert(1): PDF files as a vector to inject JavaScript code in web applications", presented at BSides Sofia 2025 and BSides Krakow 2025. - luigigubello/bsid...
https://github.com/luigigubello/bsides-2025
0
5
4
reposted by
Nicolas Grégoire
Juliet Turner
about 2 months ago
POV: you are a young woman celebrating a recent academic success
3180
20481
4085
reposted by
Nicolas Grégoire
about 2 months ago
0
10
1
about 2 months ago
0
10
1
reposted by
Nicolas Grégoire
Laluka
about 2 months ago
Hoy, c'est CE SOIR à 21H ! Dernier heads-up, mettez votre meilleur rappel / mémo / réveil, ou demandez à votre chat de vous ping ! Au programme : Hack Web / Hack IoT / Devops / Troll / Stories / CLI Tools / AI / Red-Team & Le QUIZZ ! Ah, et des goodies à gagner aussi, bc why not ! 🙃
add a skeleton here at some point
0
2
2
reposted by
Nicolas Grégoire
NorthSec
about 2 months ago
🔗 Conférence complète/Full Talk:
youtu.be/pq0NMN9HHOY
🎟️ Billets/Tickets NorthSec 2026:
nsec.io
#NorthSec
#cybersecurity
#infosec
loading . . .
NorthSec 2025 - Wendy Nather - Keynote: A Tabletop As Big As the World
YouTube video by NorthSec
https://youtu.be/pq0NMN9HHOY
0
3
2
Argument injection (and RCE) in three distinct AI agents
blog.trailofbits.com/2025/10/22/p...
loading . . .
Prompt injection to RCE in AI agents
We bypassed human approval protections for system command execution in AI agents, achieving RCE in three agent platforms.
https://blog.trailofbits.com/2025/10/22/prompt-injection-to-rce-in-ai-agents/
about 2 months ago
0
8
5
How the hack of a card shuffler presented at Blackhat 2023 by IOActive was used IRL by the mafia and some NBA members
archive.is/7Pm1E
loading . . .
https://archive.is/7Pm1E
about 2 months ago
0
1
1
reposted by
Nicolas Grégoire
Laluka
about 2 months ago
LA soirée du 200ème épisode est annoncée ! 👀 RDV ce Mardi 18 à 21h sur (oui comme d'hab en fait..) : 💌
www.twitch.tv/thelaluka
💌
0
9
9
AppSec Ezine - 612th edition
#AppSec
#Security
📚
pathonproject.com/zb/?2aa664fa...
loading . . .
AppSec Ezine
https://pathonproject.com/zb/?2aa664faaf82292f#ZEfzy8qLJVy7uGGCPcDICfyL/lPz6UFi3aDFr8IvIrA=
about 2 months ago
0
0
0
Both Chrome and Firefox will disable XSLT in 2026 🪦 I fully agree with them: nobody uses this technology anymore in a browser, and it's full of bugs (as my previous research demonstrates)
bugzilla.mozilla.org/show_bug.cgi...
developer.chrome.com/docs/web-pla...
about 2 months ago
1
3
0
reposted by
Nicolas Grégoire
The release candidate of the OWASP Top 10 2025 has been released
owasp.org/Top10/2025/0...
The definitive release should be out on November 20th
loading . . .
Introduction - OWASP Top 10:2025 RC1
OWASP Top 10:2025 RC1
https://owasp.org/Top10/2025/0x00_2025-Introduction/
about 2 months ago
0
8
11
Bizarrement, personne ne brandit l’article 40 du CPP pour les vidéos de Sainte-Soline publiées par Libération… 🥴
www.dailymotion.com/video/k1Tvpm...
loading . . .
Tirs interdits et volonté de blesser : révélations sur les violences des gendarmes à Sainte-Soline
Dailymotion video by Libération
https://www.dailymotion.com/video/k1TvpmgAEaO9y4E9pew
about 2 months ago
0
1
0
AppSec Ezine - 611th edition
#AppSec
#Security
pathonproject.com/zb/?7a6539c0...
loading . . .
AppSec Ezine
https://pathonproject.com/zb/?7a6539c03cb9bc49#t3tL+C4XTqcvoVFjKcHqzwKudi/E7dZkS2tbNiRQ9lE=
about 2 months ago
1
2
0
The release candidate of the OWASP Top 10 2025 has been released
owasp.org/Top10/2025/0...
The definitive release should be out on November 20th
loading . . .
Introduction - OWASP Top 10:2025 RC1
OWASP Top 10:2025 RC1
https://owasp.org/Top10/2025/0x00_2025-Introduction/
about 2 months ago
0
8
11
reposted by
Nicolas Grégoire
0xacb
about 2 months ago
If you still haven't: set up a JS file monitor to send you notifications via Telegram or Slack every time your target app JavaScript gets updated, a great way to stay on top of updates 👾
https://github.com/robre/jsmon
There's also a fork with Discord support:
loading . . .
GitHub - seczq/jsmon: a javascript change monitoring tool for bugbounties
a javascript change monitoring tool for bugbounties - GitHub - seczq/jsmon: a javascript change monitoring tool for bugbounties
https://github.com/seczq/jsmon
0
4
1
reposted by
Nicolas Grégoire
Kaitlin Kal Lee💋
2 months ago
"who radicalized you" Nothing radicalized me, I was born with basic empathy. The world decided that was radical.
33
2842
956
If you want to see beautiful pictures (and that’s an euphemism) in your feed, simply follow
@armandsarlangue.bsky.social
about 2 months ago
1
4
0
If this is NOT corruption, then I wonder what corruption looks like 🤔
add a skeleton here at some point
about 2 months ago
0
5
0
reposted by
Nicolas Grégoire
Alexandre Borges
2 months ago
How an ex-L3Harris Trenchant boss stole and sold cyber exploits to Russia:
techcrunch.com/2025/11/03/h...
#exploit
#exploitation
#zeroday
#infosec
#informationsecurity
#cybersecurity
loading . . .
How an ex-L3Harris Trenchant boss stole and sold cyber exploits to Russia | TechCrunch
Peter Williams sold eight exploits to a Russian zero-day broker by smuggling them from his employer’s highly secured air-gapped network. A court document, plus exclusive reporting by TechCrunch and in...
https://techcrunch.com/2025/11/03/how-an-ex-l3-harris-trenchant-boss-stole-and-sold-cyber-exploits-to-russia/
0
3
3
Ackman’s take is ridiculous 🤡
add a skeleton here at some point
about 2 months ago
0
0
0
In France, we had a somewhat related story last year. In the end, Florent Curtet was sentenced for criminal conspiracy and complicity in attempted extortion
www.lemonde.fr/pixels/artic...
add a skeleton here at some point
about 2 months ago
1
5
0
reposted by
Nicolas Grégoire
Robin
2 months ago
This is a cool attack, create a machine running in Hyper-V on a victim's machine and do all your attacking through that while it runs in the background.
www.theregister.com/2025/11/04/r...
0
5
1
reposted by
Nicolas Grégoire
Alexandre Borges
about 2 months ago
Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer:
starlabs.sg/blog/2025/11...
#cybersecurity
#exploitation
#printer
#exploit
#vulnerability
0
4
1
AppSec Ezine - 610th edition 🎃
#AppSec
#Security
pathonproject.com/zb/?fac2c832...
loading . . .
AppSec Ezine
https://pathonproject.com/zb/?fac2c8323f558700#0DwF/1lpTvyNrS8TtkN3fE3bZW/t2gCjccD9V+5ggoQ=
2 months ago
0
1
3
reposted by
Nicolas Grégoire
www.agarri.fr/blog/archive...
loading . . .
Traceroute-like HTTP scanner | Agarri : Sécurité informatique offensive
https://www.agarri.fr/blog/archives/2011/11/12/traceroute-like_http_scanner/index.html
2 months ago
0
5
2
reposted by
Nicolas Grégoire
2 months ago
Y'all fantastic news! Save the date,
@blackhoodie.bsky.social
will be at
@districtcon.bsky.social
this year 😱 the fantastic crew has offered to host us for a day of Malware Reverse Engineering!
@synapticrewrite.bsky.social
and myself will be hosting a training for women by women on January 23rd!!
0
20
9
reposted by
Nicolas Grégoire
Cooper
about 1 year ago
I've put together a website which indexes all the recordings my rigs have made thus-far as well as those currently planned:
administraitor.video
(minimalist - I'm a mid-/backend dev! 😋)
loading . . .
Infosec/hacking videos recorded by Cooper (@Ministraitor)
Infosec/hacking videos recorded by Cooper (@Ministraitor)
https://administraitor.video
0
16
9
That looks to me like some wild unauthorized hacking…
samcurry.net/hacking-club...
Shubs and Sam are well known, but in my opinion, this kind of publication only encourages others to go out of scope and hit random websites My advice: don’t do it, even if it’s an easy way to get some fame
loading . . .
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
In June, 2025, Shubs Shah and I discovered a vulnerability in the online poker website ClubWPT Gold which would have allowed an attacker to fully access the core back office application that is used f...
https://samcurry.net/hacking-clubwpt-gold
2 months ago
0
14
2
Load more
feeds!
log in