Antoine Roly
@aroly.bsky.social
📤 206
📥 757
📝 101
Hacker, Bug Bounty Hunter, Pentester,... From Namur, BE.
Nice one !
#lichess
#chess
@lichess.org
3 days ago
0
0
0
reposted by
Antoine Roly
CALL TO ACTIVISM
11 days ago
🚨NEW: "The Late Show with Stephen Colbert" just dropped its first response to ABC, FCC chair, and Disney firing Jimmy Kimmel. Trump ain't sleeping tonight. 🤣 This is a must-watch. 🔥
loading . . .
158
5826
3138
reposted by
Antoine Roly
d4d
26 days ago
We've just published a novel technique to bypass the __Host and __Secure cookie flags, to achieve maximum impact for your cookie injection findings:
portswigger.net/research/coo...
loading . . .
Cookie Chaos: How to bypass __Host and __Secure cookie prefixes
Browsers added cookie prefixes to protect your sessions and stop attackers from setting harmful cookies. In this post, you’ll see how to bypass cookie defenses using discrepancies in browser and serve
https://portswigger.net/research/cookie-chaos-how-to-bypass-host-and-secure-cookie-prefixes
1
11
12
1st time I start Burp to do bug bounty since the begining of June. Let's see if I still enjoy it or if I need more time to get back at it...
about 1 month ago
0
3
0
reposted by
Antoine Roly
James Kettle
3 months ago
How to make $$$ from request smuggling Step 1) Pick the right target:
2
28
2
Euro de basket : les Belgian Cats brillent face à l’Allemagne et filent en demi-finale (83-59)
www.lesoir.be/684043/artic...
#belgiancats
loading . . .
Euro de basket : les Belgian Cats brillent face à l’Allemagne et filent en demi-finale (83-59)
L’équipe nationale féminine belge de basket a poursuivi sur la lancée de son excellent début de tournoi ce mercredi. Une victoire qui leur permet de rejoindre l’Italie en demi-finale.
https://www.lesoir.be/684043/article/2025-06-25/euro-de-basket-les-belgian-cats-brillent-face-lallemagne-et-filent-en-demi
3 months ago
0
1
0
reposted by
Antoine Roly
Mathieu Lehot-Couette
3 months ago
"Ce qu’on est en train de vivre aujourd’hui, c’est les trajectoires qu’on avait imaginées il y a 20 ans. La communauté des climatologues n’est pas du tout surprise par la vague de chaleur qui arrive. Elle est effrayée."
@cassouman40.bsky.social
ce matin sur
@franceinfo.fr
#VagueDeChaleur
#DontLookUp
loading . . .
8
510
401
reposted by
Antoine Roly
James Kettle
4 months ago
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame" is coming to
#DEFCON33
! This talk will feature multiple new classes of desync attack, mass exploitation spanning multiple CDNs, and over $200k in bug bounties. See you there!
0
43
12
Mais putain 🤦 Enfin, au moins on sait pour qui ils roulent...
add a skeleton here at some point
4 months ago
0
3
0
Bye bye full time bug bounty hunting. It's been a hell of a ride, but it's time to move on...
4 months ago
0
3
0
reposted by
Antoine Roly
Nicolas Grégoire
4 months ago
AppSec Ezine - 589th edition
#AppSec
#Security
pathonproject.com/zb/?33afd768...
loading . . .
AppSec Ezine
https://pathonproject.com/zb/?33afd7687908185d#i0U+L14wGdG2sapGqAztLxcX+YN2ixT6DbUx+C4I8k0=
0
5
5
reposted by
Antoine Roly
d4d
4 months ago
Active Scan++ just got sharper - we’ve added new checks for OS command injection, powered by our latest ASCII Control Characters research. Install via Extensions -> BApp Store
1
11
6
No clue if this will be exploitable, but it's at least interesting: when I add an incorrect "X-Forwarded-Port" header using HTTP Request Splitting (CRLF injection with Nginx proxy), I trigger a HTTP 400 and I can then tunnel other HTTP1 requests to the backend. Poke
@t0xodile.com
for the tunneling
4 months ago
2
4
0
I often end up testing weird things, but my current test is so weird that
@burpsuite.bsky.social
can't even handle in propery if I use the Repeater custom action 😅
4 months ago
0
1
0
First one on
@yeswehack.bsky.social
:)
4 months ago
0
3
0
reposted by
Antoine Roly
Thomas Stacey
4 months ago
Thrilled to finally release my latest research "The Single-Packet Shovel: Digging for Desync-Powered Request Tunnelling". Desync vulnerabilities stemming from HP2 downgrading continue to plague even the largest vendors, have a read to find out how!
loading . . .
The Single-Packet Shovel: Digging for Desync-Powered Request Tunnelling
In this paper I will reveal the discovery of wide-spread cases of request tunnelling in applications powered by popular servers including IIS, Azure Front Door and AWS' application load balancer inclu...
https://www.assured.se/posts/the-single-packet-shovel-desync-powered-request-tunnelling
1
15
4
reposted by
Antoine Roly
renniepak
4 months ago
If you’re into bug bounty hunting and like finding weird XSS bugs (like me 😊) in places most people overlook, come check out my talk at NahamCon 2025 this Friday, May 23. "Widgets Gone Wild: Exploiting XSS Through Flawed postMessage Checks"
1
13
4
I'm a big fan of these issues, but I always struggle to actually exploit them 😅
5 months ago
0
1
0
reposted by
Antoine Roly
James Kettle
5 months ago
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame", at
#BHUSA
! This is going to be epic, check out the abstract for a teaser ↓
2
38
19
reposted by
Antoine Roly
Thomas Stacey
5 months ago
If you missed my talk "The Single-Packet Shovel: Digging for Desync-Powered Request Tunnelling" @BSidesExeter you have another chance to catch it on 22/05 at 16:00 BST on the
@portswigger.net
discord.
discord.com/events/11591...
You can find the abstract/resources below. Hope to see you there!
loading . . .
GitHub - t0xodile/the-single-packet-shovel
Contribute to t0xodile/the-single-packet-shovel development by creating an account on GitHub.
https://github.com/t0xodile/the-single-packet-shovel
2
10
4
Niiiiiiiiice game
#chess
#lichess
5 months ago
0
1
0
reposted by
Antoine Roly
Bert Hubert 🇺🇦🇪🇺🇺🇦
5 months ago
I've written lots of words on "the cloud" and specifically Europe's woes. In the post below I tie many articles together into a hopefully useful overview. It may be good to know that nothing I write on the cloud is original, I mostly hope to report things as they are:
berthub.eu/articles/pos...
loading . . .
Cloud Overview - Bert Hubert
Over the past few years I’ve written a lot about the cloud, and what it means for Europe. Here I want to pull the various articles together into a coherent story. Note, nothing what follows is in any ...
https://berthub.eu/articles/posts/cloud-overview/
1
26
12
reposted by
Antoine Roly
Kenn White
5 months ago
Never bet against hax0rs. “The hacker…[found] a token belonging to a GlobalX developer. They then used that to find access and secret keys for GlobalX’s AWS instances which contained the data. They…also sent a copy of the defacement message to GlobalX’s employees, and then deleted company data.”
loading . . .
GlobalX, Airline for Trump’s Deportations, Hacked
Hackers say they have obtained what they say are passenger lists for GlobalX flights from January to this month. The data appears to include people who have been deported.
https://www.404media.co/globalx-airline-for-trumps-deportations-hacked/
0
12
3
La Belgique est dans le top 20, vraiment ?
add a skeleton here at some point
5 months ago
0
0
0
reposted by
Antoine Roly
Noah Barkin
5 months ago
Rubio publicly criticizing an ally for cracking down on right-wing extremism. And Germany hitting back. We are in a new world
2275
51458
13782
When the same HTTP request gets you 3 different response code, you known something is weird... And thanks
@jameskettle.com
for the race condition custom action, it's really convenient to have it directly in Repeater.
5 months ago
1
8
2
reposted by
Antoine Roly
Zack Whittaker
5 months ago
If there's one thing I've learned about covering cybersecurity over the past decade or so, is that the cybersecurity community (the fixers and breakers) and the cybersecurity industry (profits above all else) are two very, very different things.
8
194
56
Bug bounty programs: - only use your own accounts to test, - create multiple accounts to test for access control issues, - use your bug bounty platform email otherwise you're not elligible for a bounty. Also bug bounty program:
5 months ago
0
1
0
When you test a path traversal in a parameter, and you get a HTML error response in a JSON message :)
5 months ago
1
1
0
reposted by
Antoine Roly
CerberusXt
5 months ago
Right wing politics in a nutshell.
6
1945
537
reposted by
Antoine Roly
Randall Munroe
5 months ago
PhD Timeline
xkcd.com/3081
602
60515
21607
When you triggered ONE HTTP callback, but can't reproduce it...
#bugbounty
#ssrf
5 months ago
0
1
0
Potential secondary context path traversal on a nice target, in a GraphQL request variable. Probably tricky to exploit. And as usual, something suspicious has to be found one hour before the week-end, when I'm already exhausted... 😡
5 months ago
0
4
0
reposted by
Antoine Roly
Jenna McLaughlin
6 months ago
My story breaking this news exclusively was 7K+ words and had almost all of this in it, and more:
www.npr.org/2025/04/15/n...
add a skeleton here at some point
90
4576
2126
Chaud pour en arriver à tout débrancher... Bon courage aux équipes.
add a skeleton here at some point
6 months ago
0
0
0
Niiiiice :)
6 months ago
0
0
0
reposted by
Antoine Roly
Pieter Hiele
6 months ago
Anyone up for an
#OSINT
challenge? The photographer of this pic would love to know what flight he captured. Taken from Gierle, Lille, Belgium on Sunday April 13th around 11PM Wonder if it can be done without more details... /cc
@bellingcat.com
@eliothiggins.bsky.social
www.vrt.be/vrtnws/nl/20...
loading . . .
Amateurfotograaf Bart Medaer (55) uit Lanklaar fotografeert uniek beeld van vliegtuig langs de maan: "One lucky shot"
https://www.vrt.be/vrtnws/nl/2025/04/15/amateurfotograaf-bart-medaer-55-uit-lanklaar-fotografeert-unie/
1
1
2
@lesoir.be
Votre stagiaire a laissé une coquille :)
6 months ago
0
1
0
reposted by
Antoine Roly
Kitetoa
6 months ago
add a skeleton here at some point
0
4
4
reposted by
Antoine Roly
C Ce Soir
6 months ago
« Qui peut croire qu'après 9 ans de procédure d'instruction, après 2 mois de procès, dans une décision qui fait plus de 150 pages, les juges auraient pour seule motivation la boussole partisane ? » Magali LAFOURCADE Magistrate
#CCeSoir
➡️
bit.ly/MLPcolereRev...
🎧en podcast
loading . . .
29
1234
583
reposted by
Antoine Roly
Nawak
6 months ago
5
498
143
reposted by
Antoine Roly
Thomas Deridder
6 months ago
Très excité de vous dévoiler ce nouveau projet. 🤩 On peut le dire : en 2025, Charleroi sera le nouvel eldorado de l'ultra-trail avec l'organisation de la 1e édition de la Barakley ! Sur quel site historique se tiendra la course ? Devinez et gagnez votre poids en bières👇
2
6
1
reposted by
Antoine Roly
Actuel Moyen Âge
6 months ago
Si la troisième croisade avait lieu maintenant... 😉😅
20
594
158
reposted by
Antoine Roly
Bert Hubert 🇺🇦🇪🇺🇺🇦
7 months ago
You can't use a clever definition of "cloud native" to pretend that you compete with AWS/Azure/Google stacks. Don't try to fool people, it will backfire eventually. "There is no cloud just other people's computers" means you don't get what developers are doing with clouds
berthub.eu/articles/pos...
loading . . .
The (European) cloud ladder: from virtual server to MS 365 - Bert Hubert
We have extensive discussions about our enormous dependence on American clouds, but what exactly are we talking about? And is Europe equally dependent on all types of cloud? This article is aimed at p...
https://berthub.eu/articles/posts/the-european-cloud-ladder/
3
26
12
That's not good 😟
add a skeleton here at some point
7 months ago
0
1
0
reposted by
Antoine Roly
Bert Hubert 🇺🇦🇪🇺🇺🇦
7 months ago
Europe & European governments can no longer rely on American clouds. European alternatives won’t emerge on their own. So, it’s time for
#industrialpolicy
. In this post, I explore the challenges and immodestly propose a coherent strategy to come to European alternatives:
berthub.eu/articles/pos...
loading . . .
But how to get to that European cloud? - Bert Hubert
The very short version: It has now become clear that European governments can no longer rely on American clouds, and that we lack good and comprehensive alternatives. Market forces have failed to deli...
https://berthub.eu/articles/posts/now-how-to-get-that-european-cloud/
3
33
18
Playing with
@hextreeio.bsky.social
"Android" course and I must say it's really amazing !
7 months ago
0
0
0
reposted by
Antoine Roly
Burp Suite
7 months ago
Are you ready for another Burp AI sneak peek? 👀 Introducing False Positive Reduction - Access Control.
#BurpAI
0
3
1
Load more
feeds!
log in