Aethlios
@aethlios.bsky.social
📤 710
📥 145
📝 7
Lead developer | Bug hunter (approximately every 3 months) >
https://aeth.cc
I'm excited to share that I recently found a XSS in Quasar Framework. The CVE-2025-43954 has just been published to document this security issue. You can learn more about it here: -
github.com/advisories/G...
6 months ago
0
6
0
reposted by
Aethlios
Gareth Heyes
7 months ago
You might have noticed that the recent SAML writeups omit some crucial details. In "SAML roulette: the hacker always wins", we share everything you need to know for a complete unauthenticated exploit on ruby-saml, using GitLab as a case-study.
portswigger.net/research/sam...
loading . . .
SAML roulette: the hacker always wins
Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library
https://portswigger.net/research/saml-roulette-the-hacker-always-wins
0
52
27
Great resource on secret leakage, I invite you to read it.
loading . . .
The State of Secrets Sprawl Report | GitGuardian
https://www.gitguardian.com/files/the-state-of-secrets-sprawl-report-2025
8 months ago
0
2
1
reposted by
Aethlios
James Kettle
9 months ago
I’ve updated the bug bounty & content creators starter pack with classic research group
@hackerschoice.bsky.social
! Let me know if you’re not on this list and would like to be added.
go.bsky.app/GD7hKPX
add a skeleton here at some point
7
44
13
reposted by
Aethlios
James Kettle
9 months ago
Thanks for your all your votes! The public vote is now closed, and we're kicking off the panel vote with fifteen quality nominations. In the meantime we just published a new technique ourselves - check it out here:
add a skeleton here at some point
0
14
5
reposted by
Aethlios
James Kettle
9 months ago
24 hours remaining until voting closes on the Top 10 (new) Web Hacking Techniques of 2024! If you haven't already voted now's the time to do it.
portswigger.net/polls/top-10...
loading . . .
Top 10 web hacking techniques of 2024
Welcome to the community vote for the Top 10 Web Hacking Techniques of 2024.
https://portswigger.net/polls/top-10-web-hacking-techniques-2024
1
12
6
reposted by
Aethlios
James Kettle
9 months ago
Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here:
portswigger.net/polls/top-10...
loading . . .
Top 10 web hacking techniques of 2024
Welcome to the community vote for the Top 10 Web Hacking Techniques of 2024.
https://portswigger.net/polls/top-10-web-hacking-techniques-2024
0
24
15
reposted by
Aethlios
BitK
10 months ago
I've pushed some updates to Dom-Explorer: - Allow multiple pipeline embed - Short links for sharing/sync - Support for DomPurify triggers - User settings Give it a try and share your findings!
yeswehack.github.io/Dom-Explorer
loading . . .
Dom-Explorer
https://yeswehack.github.io/Dom-Explorer
2
20
6
reposted by
Aethlios
Laluka
10 months ago
Last part/EP with
@aethlios.bsky.social
&
@penthium2.bsky.social
😘
www.youtube.com/watch?v=UeOS...
loading . . .
EP 173 | Le récap : Kamal, Dokploy, Dokku, Portainer Ft. @AethliosIK & @penthium2
YouTube video by Laluka
https://www.youtube.com/watch?v=UeOSMpGlmg4
0
2
2
reposted by
Aethlios
Laluka
10 months ago
youtu.be/67DIr_OmXVk
cc
@penthium2.bsky.social
@aethlios.bsky.social
🌹
loading . . .
EP 172 | Portainer, and UID remap! Ft. @penthium2 & @AethliosIK
YouTube video by Laluka
https://youtu.be/67DIr_OmXVk
0
3
2
reposted by
Aethlios
Nicolas Grégoire
10 months ago
A younger me, as a pentester and bug hunter, had exactly the bias described in this article 🤫 Luckily, I later worked with and for "the other side" and it changed my mind 🤯 I hope young people reading it will avoid taking years to understand the complexities of fixing bugs in a timely manner 🤞
loading . . .
Why Can't You Fix This Bug Faster?
Fixing security vulnerabilities in a timely manner is more complicated than you realize.
https://maxwelldulin.com/BlogPost/Why-Can't-You-Fix-This-Bug-Faster
2
60
21
reposted by
Aethlios
Laluka
10 months ago
www.youtube.com/watch?v=adf3...
with
@aethlios.bsky.social
&
@penthium2.bsky.social
💝
loading . . .
EP 171 | Reset-tolkien Ft. @AethliosIK & @penthium2
YouTube video by Laluka
https://www.youtube.com/watch?v=adf3ulc9xYQ
0
3
2
reposted by
Aethlios
Laluka
11 months ago
Yo ! 🧙♂️ Prochain stream demain -mardi 10 Dec- à 21h ! Au programme ? We Deep Dive ! 🧐 - Reset-tolkien par @AethliosIK (X) 🗝️ - Portainer & UID remap par @penthium2 (X) 🐳
www.twitch.tv/thelaluka
loading . . .
Twitch
Twitch is the world
https://www.twitch.tv/thelaluka
2
6
3
reposted by
Aethlios
Gabriel Thierry
11 months ago
Bonjour, Bienvenue dans ce live-skeet du procès de Florent Curtet, ce trentenaire poursuivi pour des extorsions numériques, jugé en cette fin de mois à Paris par le tribunal judiciaire.
6
50
32
A really comprehensive resource on CORS attacks. I'm going to rework my course slides based on this research, thank you for your contribution!
add a skeleton here at some point
11 months ago
1
9
2
reposted by
Aethlios
James Kettle
11 months ago
Custom lists are super cool! I enjoy reading social posts, but want to make sure I never miss a quality writeup or technique. To achieve this, I'm building a 'high signal web security' list of topic-focused accounts, which you can pin next to 'Following' if you want :)
bsky.app/profile/jame...
add a skeleton here at some point
2
57
16
I'm glad to see so many people switching over to Bluesky and following me! Take the time to discover my open source tool on sandwich attacks : 👉
github.com/AethliosIK/r...
loading . . .
GitHub - AethliosIK/reset-tolkien: Unsecure time-based secret exploitation and Sandwich attack implementation Resources
Unsecure time-based secret exploitation and Sandwich attack implementation Resources - GitHub - AethliosIK/reset-tolkien: Unsecure time-based secret exploitation and Sandwich attack implementatio...
https://github.com/AethliosIK/reset-tolkien
11 months ago
1
7
0
reposted by
Aethlios
Nicolas Grégoire
11 months ago
In case you're a professional Burp Suite user, there's a few seats left for the Q1 2025 training sessions
hackademy.agarri.fr/2025
add a skeleton here at some point
1
15
9
reposted by
Aethlios
James Kettle
11 months ago
Any bug bounty people around? I'm creating a starter pack of people to follow but it's pretty brief currently! Let me know if you'd like to be added:
go.bsky.app/GD7hKPX
add a skeleton here at some point
45
95
32
My second article on time-based secrets has just been published! 🚀 I explore a new usecase of the sandwich attack to set up a scenario for real-time monitoring of web application invitations. - English version:
aeth.cc/public/Artic...
- French version:
aeth.cc/public/Artic...
over 1 year ago
0
3
1
Following
#bugbounty
findings, I started focusing my research on time-based secrets. This research began for me a year ago, and enabled me to take the time to implement my open source tool: “Reset Tolkien”. 🚀 I've written an article detailing my research : - 🇬🇧 EN :
www.aeth.cc/public/Artic...
over 1 year ago
0
1
0
you reached the end!!
feeds!
log in