CryptoCat
@cryptocat.me
π€ 472
π₯ 81
π 111
Security Researcher π Hacking Content @
https://yt.cryptocat.me
π
pinned post!
CTF resources πΊ
loading . . .
GitHub - Crypto-Cat/CTF: CTF chall write-ups, files, scripts etc (trying to be more organised LOL)
CTF chall write-ups, files, scripts etc (trying to be more organised LOL) - GitHub - Crypto-Cat/CTF: CTF chall write-ups, files, scripts etc (trying to be more organised LOL)
https://github.com/Crypto-Cat/CTF
over 2 years ago
0
9
1
New video covering the solution to the Mother Printers challenge I created for
@hackinghub.bsky.social
π Tried to make it as beginner friendly as possible as I know many players aren't familiar with rev/pwn π
youtu.be/ebNYtX_8lOY
loading . . .
Mother Printers (Print2Own) - Full Exploit Chain Walkthrough [HackingHub]
YouTube video by CryptoCat
https://youtu.be/ebNYtX_8lOY
1 day ago
0
1
0
Didn't get chance to solve my "Mothers Printers" challenge on
@hackinghub.bsky.social
? π¨ Here's the official writeup β‘
book.cryptocat.me/blog/ctf/mon...
Prefer video? Stay tuned for a beginner-friendly walkthrough on YT next week βΆ
5 days ago
1
1
0
Time to drop a couple of hints for my
@hackinghub.bsky.social
challenge! 1οΈβ£ First flag is on the website (you need to find it before flag 3/4/5) 2οΈβ£ The chall is inspired by some cool research I read (go find it) Writeups will be published once we hit 10 solves β‘
app.hackinghub.io/hubs/mother-...
loading . . .
https://app.hackinghub.io/hubs/mother-printers
14 days ago
0
0
1
Congratulations to Bhavya for being the first to capture all 5 flags on my
@hackinghub.bsky.social
challenge! π₯³π We've released a small patch. If you were stuck on flag 3, please re-download files! Good time to practice your patch-diffing π
app.hackinghub.io/hubs/mother-...
18 days ago
0
1
0
So, who's gonna blood my new
@hackinghub.bsky.social
challenge? πΌ Challenge π
app.hackinghub.io/hubs/mother-...
First 3 solves will earn the "Hacker Cat" role in my discord server β‘οΈ
discord.cryptocat.me
#ctf
#capturetheflag
#ethicalhacking
#cybersecurity
#infosec
#offsec
19 days ago
1
1
1
The "Ultimate Calculator 3000" challenge is over! β³ You can watch the video walkthrough here β‘
youtu.be/lRJno96za5A
I'll leave everything online for another week or so π
loading . . .
Hidden Product Activation and Serial Keygen - "Ultimate Calculator 3000" [Rev/Web Challenge]
YouTube video by CryptoCat
https://youtu.be/lRJno96za5A
about 1 month ago
1
0
0
My writeup for the September Dojo challenge on
@yeswehack.bsky.social
- Chainfection β The challenge combined multiple CVEs, creating a chain of vulnerabilities: SQL injection -> file write + path traversal -> SSTI (RCE) Read the full writeup β‘οΈ
book.cryptocat.me/blog/ctf/mon...
about 1 month ago
0
0
0
I made a new CTF challenge! It will run until the 30th of October π There's no prizes, but the first 3 solves will earn themselves the "Hacker Cat" rank in my discord server πΈ Download "Ultimate Calculator 3000" to get started β‘
discord.cryptocat.me
about 1 month ago
1
1
0
reposted by
CryptoCat
Trend Zero Day Initiative
about 1 month ago
Recapping Day One of
#Pwn2Own
Ireland 2025. Join
@dustinchilds.bsky.social
(and Maude) as he covers the highlights of the first day of the competition. We awarded $522,500 for 34 unique 0-day bugs, and more is to come.
youtu.be/tiM_StSFvow
loading . . .
Recapping Day One of Pwn2Own Ireland 2025
YouTube video by Trend Zero Day Initiative
https://youtu.be/tiM_StSFvow
0
1
1
reposted by
CryptoCat
Stephen Fewer
about 2 months ago
We just posted our AttackerKB
@rapid7.com
Analysis for the recent Cisco 0day chain; CVE-2025-20362 and CVE-2025-20333. Full technical root cause analysis of both the auth bypass and buffer overflow are here:
attackerkb.com/topics/Szq5u...
loading . . .
CVE-2025-20362 | AttackerKB
On September 25, 2025, Cisco published advisories for two new vulnerabilities, CVE-2025-20362, and CVE-2025-20333, which are known to be exploited in-the-wild β¦
https://attackerkb.com/topics/Szq5u0xgUX/cve-2025-20362/rapid7-analysis
1
2
1
New video looking at some interesting printer vulnerabilities, found by
@stephenfewer.bsky.social
(
@rapid7.com
) π¨ βΆ
youtu.be/--SaQKmcyiU
loading . . .
Print Scan Hacks: Understanding the 8 CVEs Impacting Brother Printers
YouTube video by CryptoCat
https://youtu.be/--SaQKmcyiU
2 months ago
1
1
0
One week until
@bsidesbelfast.bsky.social
, Who's going? π As always, I've got stickers - come say hi! π
3 months ago
0
3
1
Video walkthrough for the "Fancy Login Form" web challenge from the
@why2025.bsky.social
CTF π© Learn how to exfiltrate data via CSS injection β‘οΈ
youtu.be/jUjlj2z5jJk
loading . . .
4 months ago
0
0
0
Played the
@why2025.bsky.social
CTF over the weekend π Here's some web challenge writeups π
book.cryptocat.me/ctf-writeups...
loading . . .
Web | CTF Writeups
https://book.cryptocat.me/ctf-writeups/2025/why/web
4 months ago
0
1
1
Famous beef noodle soup (broth simmering continously for over 50 years!) in one of my all time favourite cities - Bangkok! πΉπ Any hackers here wanna hang out, hmu π€
5 months ago
0
1
1
I've done a lot of awesome hacker meetups but this one was next level! So nice to meet brutecat, dreyand and IDlSSEVERYTHINGπ₯ These guys have some crazy skills (and stories), hope to meet again in the future π
5 months ago
1
1
0
I'll be in Singapore this weekend! I know there's lots of cool hackers there so hmu if you wanna get some coffee/food/drinks π₯°
5 months ago
0
2
1
Finally back in
#KualaLumpur
π Meeting some of my favourite Malaysian hackers for food/drinks tomorrow night. If you wanna join, let me know! π₯°
6 months ago
1
0
0
π
6 months ago
0
1
0
My OSWE review, tips/tricks.. general ramblings ππ
youtu.be/IK4t-i5lDEs
loading . . .
Offensive Security Web Expert (OSWE) Review + Tips/Tricks [OffSec]
YouTube video by CryptoCat
https://youtu.be/IK4t-i5lDEs
6 months ago
0
0
0
Just finished my OSWE exam π Today I write up the report.. while watching
#NahamCon
π
6 months ago
0
2
0
reposted by
CryptoCat
Johan Carlsson
7 months ago
Here is the official writeup of my XSS challenge on Intigriti. I think it contains some fun browser trivia even for those who did not look at the chall
joaxcar.com/blog/2025/05...
loading . . .
Confetti: Solution to my Intigriti May 2025 XSS Challenge - Johan Carlsson
https://joaxcar.com/blog/2025/05/20/confetti-solution-to-my-intigriti-may-xss-challenge/
1
19
6
reposted by
CryptoCat
Jorian
7 months ago
The legendary
@joaxcar.bsky.social
made a really interesting XSS challenge this month for Intigriti. My solution involved winning a race condition with 100 <iframe>s to utilize a DOM Clobbering gadget after bypassing a RegEx. Check out the writeup below:
jorianwoltjer.com/blog/p/hacki...
loading . . .
Intigriti May XSS Challenge (0525) | Jorian Woltjer
A challenge by @joaxcar with a small but complex XSS chain, hitting DOM Clobbering with a race condition and abusing a cool URL parsing quirk in JavaScript.
https://jorianwoltjer.com/blog/p/hacking/intigriti-xss-challenge/0525
2
12
7
Heading back to SE-Asia next month.. Any hackers wanna hang out? π Join my discord to keep up with the travel plans / arrange meetups:
cryptocat.me/discord
π
#cybersecurity
#ethicalhacking
#infosec
#bugbounty
#ctf
#asia
7 months ago
0
1
0
reposted by
CryptoCat
James Kettle
7 months ago
I'm thrilled to announce "HTTP/1 Must Die! The Desync Endgame", at
#BHUSA
! This is going to be epic, check out the abstract for a teaser β
2
38
19
Video walkthrough for the web challenges from Tsuku CTF π
youtu.be/qGd4d0zmhy8
loading . . .
Tsuku CTF Web Challenge Walkthroughs (2025)
YouTube video by CryptoCat
https://youtu.be/qGd4d0zmhy8
7 months ago
1
1
0
reposted by
CryptoCat
Nicolas GrΓ©goire
7 months ago
We already know that any Web server listening on the loopback interface is a security risk, because it may be accessed by a browser or its extensions. But the impact may be way bigger if this Web server is a MCP server π±
blog.extensiontotal.com/trust-me-im-...
loading . . .
Trust Me, Iβm Local: Chrome Extensions, MCP, and the Sandbox Escape
Letβs talk about MCPs. Youβve probably heard of them, and maybe youβve read the security risks associated with them. Sure, they soundβ¦
https://blog.extensiontotal.com/trust-me-im-local-chrome-extensions-mcp-and-the-sandbox-escape-1875a0ee4823
0
26
2
Have YOU joined my discord server yet? Click the link below and let's talk about hacking stuff π
discord.cryptocat.me
7 months ago
0
0
0
Added a video walkthrough for the web challenges from the recent CTF@CIT π
youtu.be/ZBdApaw0r0M
#capturetheflag
#ctf
#websecurity
#bugbounty
#cybersecurity
#ethicalhacking
#infosec
loading . . .
CTF@CIT Web Challenge Walkthroughs
YouTube video by CryptoCat
https://youtu.be/ZBdApaw0r0M
7 months ago
0
0
0
Made writeups for the web challs featured in the CTF@CIT competition this weekend π© 1) SQL injection 2) Git repo dumping 3) Local file read with basic filter bypass 4) Flask session cookie tampering + SSTI 5) Credential reuse / HTTP method tampering
book.cryptocat.me/ctf-writeups...
7 months ago
0
0
1
Video for the HackDonalds Challenge by
@intigriti.com
π
youtu.be/KwD_TKZr0YY
loading . . .
Next.js Middleware Auth Bypass (CVE-2025-29927) and Local File Read via XXE - HackDonalds Challenge
YouTube video by Intigriti
https://youtu.be/KwD_TKZr0YY?si=Anj3agAZrOTHi4kc
8 months ago
0
2
1
My YouTube channel has reached a new milestone; 3 million views! π₯³π Next up - 50k subscribers! Help me get there π₯Ί
yt.cryptocat.me
8 months ago
0
5
0
Who wants a bonus
@intigriti.com
challenge? Easier than usual π First blood + best writeup win a β¬50 swag voucher π Find the flag before 15/04/25 π
hackdonalds.intigriti.io
loading . . .
HackDonalds
π Welcome to the most exploitable fast food chain on the net.
https://hackdonalds.intigriti.io
8 months ago
1
3
1
London π¬π§ππ¨
8 months ago
0
3
0
reposted by
CryptoCat
Intigriti
8 months ago
Check out the walkthrough for the fourth (and currently final)
@portswigger.net
lab on NoSQL injection by
@cryptocat.me
πΌ
youtu.be/aSXlmJ3lN4o
loading . . .
Exploiting NoSQL Operator Injection to Extract Unknown Fields
YouTube video by Intigriti
https://youtu.be/aSXlmJ3lN4o
1
3
1
Almost 600 hackers at ZeroDays CTF in
#Dublin
this year!! π
#ZeroDays
#CTF
#CaptureTheFlag
#CyberSecurity
#EthicalHacking
#InfoSec
#BugBounty
#Ireland
8 months ago
0
6
1
As promised, I've updated my YouTube playlist with a walkthrough for the new API testing module in
@digi.ninja
's Damn Vulnerable Web Application (DVWA) π
www.youtube.com/watch?v=c_6R...
loading . . .
18 - API Security (low/med/high) - Damn Vulnerable Web Application (DVWA)
YouTube video by CryptoCat
https://www.youtube.com/watch?v=c_6RaCekH40
9 months ago
0
0
0
Met so many cool hackers over the past few days in Kuala Lumpur! π
9 months ago
0
2
0
reposted by
CryptoCat
Lennaert89
9 months ago
Attending the amazing
@1ns0mn1h4ck.bsky.social
to represent
@intigriti.com
today! Hit me up if you want to chat. I've got stickers and invite codes to hand out π.
0
6
2
New
@portswigger.net
video released over on the
@intigriti.com
channel! π
youtu.be/mVYu_3b_dOE
loading . . .
Exploiting Syntax Injection to Extract Data
YouTube video by Intigriti
https://youtu.be/mVYu_3b_dOE
9 months ago
1
3
1
Yay, another hacker hangout! So nice to finally meet
@taeluralexis.bsky.social
π
9 months ago
0
2
0
When I saw
@digi.ninja
announced a new API testing module for the DVWA, I figured it was a good time to update my YouTube series! Turns out I missed a crypto module (π) so let's get it over with π Stay tuned for the API module π
youtu.be/7WySPRERN0Q
loading . . .
17 - Cryptography (low/med/high) - Damn Vulnerable Web Application (DVWA)
YouTube video by CryptoCat
https://youtu.be/7WySPRERN0Q?si=L6fMskv8SfvosfHw
9 months ago
0
4
1
Met one of my favourite
@intigriti.com
hackers today! ngyostuan π
9 months ago
1
6
1
reposted by
CryptoCat
KΓ©vin Gervot (Mizu)
9 months ago
With
@gelu.chat
, we created a challenge for the @pwnmectf inspired by a bug he found in bug bounty a year ago! π If you have some time this weekend, give it a try! π π
pwnme.phreaks.fr
0
14
5
Amazing writeups and crazy chain of bugs π€― Well worth a read π―
vitorfalcao.com/posts/hackin...
loading . . .
Hacking High-Profile Bug Bounty Targets: Deep Dive into a Client-Side Chain
Iβve always wanted to hack on one of those targets that top hackers were going afterβnot just because they pay well, but because they usually have fair triaging and amazing scopes. But how? Finding bu...
https://vitorfalcao.com/posts/hacking-high-profile-targets/
9 months ago
1
0
1
I hit the 40k subscribers milestone on YouTube this week π₯³π Thank you to everyone who has checked out my content ππ₯° If you haven't yet and are interested in CTF walkthroughs; web, pwn, rev etc Hope you will take a look and help me get to 50k! π
yt.cryptocat.me
9 months ago
0
5
0
Here's the second
@portswigger.net
lab on NoSQL Injection by
@intigriti.com
π It covers NoSQL injection using MongoDB operators, leading to an authentication bypass π
youtu.be/DBNmAJaWcGk
loading . . .
Exploiting NoSQL Operator Injection to Bypass Authentication
YouTube video by Intigriti
https://youtu.be/DBNmAJaWcGk?si=gnXlsslIlPrkdu9H
9 months ago
1
7
2
reposted by
CryptoCat
Nicolas GrΓ©goire
9 months ago
How Chinese cyber companies report on US APT groups πΊπΈππ¨π³
www.inversecos.com/2025/02/an-i...
loading . . .
An inside look at NSA (Equation Group) TTPs from Chinaβs lense
https://www.inversecos.com/2025/02/an-inside-look-at-nsa-equation-group.html
0
8
5
reposted by
CryptoCat
James Kettle
9 months ago
For me, Shadow Repeater is AI in web security done right - taking full advantage of the users' manual testing skills, and providing an extra edge on top without changing their workflow
add a skeleton here at some point
0
17
5
reposted by
CryptoCat
PentesterLab
10 months ago
Articles worth reading discovered last week: π
mizu.re/post/explori...
βοΈ
devanshbatham.hashnode.dev/fragility-of...
π«
www.wiz.io/blog/nvidia-...
π
www.reversinglabs.com/blog/rl-iden...
π₯
brutecat.com/articles/lea...
loading . . .
Exploring the DOMPurify library: Hunting for Misconfigurations (2/2). Tags:Article - Article - Web - mXSS
Exploring the DOMPurify library: Hunting for Misconfigurations (2/2)
https://mizu.re/post/exploring-the-dompurify-library-hunting-for-misconfigurations
0
7
5
Load more
feeds!
log in