Alex Chapman
@ajxchapman.bsky.social
📤 2837
📥 464
📝 215
Full Time
#BugBounty
Vulnerability Researcher
https://blog.ajxchapman.com
pinned post!
My bug hunting methodology
over 1 year ago
2
40
0
If you run a Bug Bounty program (or platform) now might be a good time for you to publish the average time to triage for various issue severities. There are a _lot_ of disgruntled hackers out there at the moment who are waiting weeks / months for a program to even perform a first look at a report!
24 days ago
3
9
1
Bug Bounty is remotely debugging last year's unreliable n-day using last week's reliable n-day... which I can't report because the vendor needs "time to patch." 🤦
28 days ago
0
3
0
reposted by
Alex Chapman
Ollie Whitehouse
29 days ago
Heading to OffensiveCON this week? Thank you for coming to my talk...
claude.ai/share/227b48...
0
11
2
Well this is depressing.
about 1 month ago
1
0
0
reposted by
Alex Chapman
Patrick Gray
about 1 month ago
If you would like to see a preview of
@jameskettle.com
's Blackhat talk "the HTTP terminator" then check out this interview my colleague
@jameswilson.io
recorded with him. Some pretty freaky stuff! VIDEO:
www.youtube.com/watch?v=GdFG...
AUDIO:
risky.biz/RBNEWSSI126/
loading . . .
Sponsored: James Kettle built an AI hacker
YouTube video by Risky Business Media
https://www.youtube.com/watch?v=GdFG85oCWFI
2
15
8
2026 and Bug Bounty triage is broken. This has on the horizon for years, even without LLM pressure, but it still seems to have caught _every_ major platform and large private program by surprise.
about 2 months ago
0
11
2
reposted by
Alex Chapman
James Kettle
about 2 months ago
I'm thrilled to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" will premiere at Black Hat USA! Check out the abstract:
blackhat.com/us-26/briefi...
0
13
5
👏
@intigriti.com
about 2 months ago
1
3
0
The VSCode remote editor function has really gone to crap recently. Any form of linting is just spinning server CPU at 100% and OOM killing random processes. Going to have to go back to filesystem monitoring and rsync at this rate.
2 months ago
0
4
0
reposted by
Alex Chapman
renniepak
3 months ago
When reviewing pull requests with new additions for
CSPBypass.com
, I often find myself questioning how useful a given entry actually is. If no websites whitelist a specific host, there is little point in adding it.
1
5
5
Every bug hunter / vulnerability researcher / pentester should have to write their own blind or timing based SQL injection tool. It's like a rite of passage, if you've taken the time to understand and produce your own you'll probably make it in this world, if not 😬
x.com/slonser_/sta...
3 months ago
1
5
2
reposted by
Alex Chapman
mkultra tournament edition
3 months ago
Last BSidesNYC I sat behind a guy doing the CTF with ChatGPT. Ctrl-a paste page source and a screenshot, hit enter, repeat. User totally not reading the output. LLM got the flag (flappybird-style JS challenge) after maybe ten rounds of this. Last message dude sent in the session was "We did it!".
1
4
1
This post on LLM use in CTFs sums up my feelings on the subject nicely.
vt.social/@lina/116198...
When simply directing LLMs for development / security research / CTFs it's quick, often accurate, often useful, but I don't inherently learn anything other than how to direct the LLM.
loading . . .
Hoshino Lina (星乃リナ) 🩵 3D Yuri Wedding 2026!!! (@
[email protected]
)
There's a lot of discourse on Twitter about people using LLMs to solve CTF challenges. I used to write CTF challenges in a past life, so I threw a couple of my hardest ones at it. We're screwed. At ...
https://vt.social/@lina/116198976928184530
3 months ago
3
4
1
What I'm waiting for: Email updates to 5 separate Bug Bounty reports What I get: Email notifications of 3 year old reports being closed 😭
3 months ago
2
3
0
reposted by
Alex Chapman
🇵🇹 snipe, lixo tóxico ⭑⭒⭒⭒⭒
5 months ago
Same.
6
111
36
If you are selling a mirror and your ad creative includes images of the product with impossible reflections, I'm going to have to go ahead and assume your product doesn't work very well!
6 months ago
1
1
0
I'm sympathetic to corporate policy "patch gaps", but when it's framed as "acceptable exploitation window" it hits on a different level 🤔
7 months ago
2
8
0
reposted by
Alex Chapman
Rhianna Pratchett
8 months ago
Dad’s books are full of empathy, common sense, and a healthy suspicion of the powerful. But at its heart his work is also about how systems keep people poor while pretending it’s their own fault. So I hope Kemi’s taking notes as well as reading the jokes.
add a skeleton here at some point
138
7780
2011
reposted by
Alex Chapman
An in depth summary of the consequence of Google VRP increasing bounties in 2024. "We observe statistically significant increases in the reporting of high-value bugs, especially in the highest impact tiers and high merit submissions." 🔥
arxiv.org/abs/2509.16655
loading . . .
Incentives and Outcomes in Bug Bounties
Bug bounty programs have contributed significantly to security in technology firms in the last decade, but little is known about the role of reward incentives in producing useful outcomes. We analyze ...
https://arxiv.org/abs/2509.16655
8 months ago
0
8
3
An in depth summary of the consequence of Google VRP increasing bounties in 2024. "We observe statistically significant increases in the reporting of high-value bugs, especially in the highest impact tiers and high merit submissions." 🔥
arxiv.org/abs/2509.16655
loading . . .
Incentives and Outcomes in Bug Bounties
Bug bounty programs have contributed significantly to security in technology firms in the last decade, but little is known about the role of reward incentives in producing useful outcomes. We analyze ...
https://arxiv.org/abs/2509.16655
8 months ago
0
8
3
The new favourite fidget toy on my desk is the Zippo lighter I've had since I was a teenager. There is something about the noise of the cap flipping open and flint sparking. This has replaced the ever popular poker chips. Needless to say, I am not a great example for my kids 😬
9 months ago
2
2
0
Hackers tops the list of films that have influenced my life. Without seeing this film as a young teen I may not have misspent my youth in front of a computer trying to understand how it all worked. Which, despite what my parents suggested at the time, seems to have worked out well for me 😆
add a skeleton here at some point
9 months ago
0
9
0
That feeling when you finally read that blog post you've had open in a browser tab for 3 months, and it's complete garbage 😑
9 months ago
0
31
2
It's been another year since my wife and I lost our first daughter Chloë. She would have been 7 today. With each passing year I can't help but think about what her life would have been like, what our life would have been like, had she been given a chance. I love her so much, but don't even know her.
10 months ago
1
22
0
This jaw dropping write-up of an LLM solving a DEF CON CTF challenge(!) with minimal human interaction 🤯 It seems like "vibe-reversing" is becoming a viable option now...
loading . . .
All You Need Is MCP - LLMs Solving a DEF CON CTF Finals Challenge
DEF CON CTF Every year world-class teams play difficult CTFs such as Plaid CTF and HITCON CTF in an attempt to qualify for DEF CON CTF by getting first place. There are usually only 3-4 CTFs a year de...
https://wilgibbs.com/blog/defcon-finals-mcp/
10 months ago
1
11
3
There is something quite depressing about many of the advertised agentic AI use cases being posting "viral" content to social media. It stinks of one person assuming their time is inherently worth more than everyone else.
10 months ago
0
3
0
I've said it before and I'll say it again, Windows 11 is _such_ a hostile user experience, it's like they've actively tried to make it unpleasant to use 😑
10 months ago
1
8
2
reposted by
Alex Chapman
avi bagla
10 months ago
Can Bluesky say every word in the dictionary? I dunno but I plan to find out! I made a website that tracks every single word said on bluesky (as of yesterday).
loading . . .
66
612
208
reposted by
Alex Chapman
James Kettle
10 months ago
The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die:
http1mustdie.com
loading . . .
HTTP/1.1 Must Die
Upstream HTTP/1.1 is inherently insecure, and routinely exposes millions of websites to hostile takeover. Join the mission to kill HTTP/1.1 now
https://http1mustdie.com/
0
40
24
reposted by
Alex Chapman
Samuel Groß
10 months ago
We released our Fuzzilli-based V8 Sandbox fuzzer:
github.com/googleprojec...
It explores the heap to find interesting objects and corrupts them in a deterministic way using V8's memory corruption API. Happy fuzzing!
loading . . .
Add V8SandboxFuzzer · googleprojectzero/fuzzilli@675eccd
This is a basic fuzzer for the V8 Sandbox. It uses the memory corruption API to implement a random-but-deterministic (given a seed) traversal through the V8 heap object graph and corrupts some obje...
https://github.com/googleprojectzero/fuzzilli/commit/675eccd6b6d0c35ea6c7df24a0a1e513cce45bb3
0
25
7
reposted by
Alex Chapman
I presented my magnum opus in 2014 and have been in steady decline ever since.
11 months ago
0
2
1
reposted by
Alex Chapman
There are bad security takes, and then there is
@daniel.haxx.se
attempting to shame
@jameskettle.com
for not "responsibly disclosing" a vulnerability to the curl project that doesn't affect the curl project... and _then_ complaining the details are being kept "secret" :facepalm:
loading . . .
daniel:// stenberg:// (@
[email protected]
)
@
[email protected]
@
[email protected]
@
[email protected]
the website, the naming, the scare, the secrecy
https://mastodon.social/@bagder/114890176383466057
11 months ago
2
8
2
I presented my magnum opus in 2014 and have been in steady decline ever since.
11 months ago
0
2
1
There are bad security takes, and then there is
@daniel.haxx.se
attempting to shame
@jameskettle.com
for not "responsibly disclosing" a vulnerability to the curl project that doesn't affect the curl project... and _then_ complaining the details are being kept "secret" :facepalm:
loading . . .
daniel:// stenberg:// (@
[email protected]
)
@
[email protected]
@
[email protected]
@
[email protected]
the website, the naming, the scare, the secrecy
https://mastodon.social/@bagder/114890176383466057
11 months ago
2
8
2
After the intense focus of Live Hacking Events, I often find myself at quite a deep emotional low point. The highs of the event fade, focus needs to completely shift to other, usually less valuable, targets. I find these events hugely rewarding, but need to remember to be kind to myself after them.
11 months ago
0
6
0
reposted by
Alex Chapman
Samuel Groß
11 months ago
If you have a machine with PKEY support and somewhat recent Linux kernel you can now play around with hardware support for the V8 sandbox. When active, JS + Wasm code has no write permissions outside the sandbox address space. To enable, simply set `v8_enable_sandbox_hardware_support = true`.
1
18
6
Famous last words: > This just leads to weird behavior, not a vulnerability
11 months ago
0
1
0
reposted by
Alex Chapman
Geluchat
11 months ago
Today was my last day as a pentester at Bsecure. After a three-year journey of hunting on the side, I’m ready to go all-in as a full-time bug bounty hunter. You can read about my journey from pentester to full-time hunter here:
gelu.chat/posts/from-p...
loading . . .
Finding Freedom, One Bug at a Time: My Journey from Pentester to Full-Time Hunter
After seven years in pentesting, I transitioned full-time into bug bounty hunting, leveraging deep experience and continuous learning. This article shares key moments and insights from that journey.
https://gelu.chat/posts/from-pentester-to-fulltime-hunter
3
24
7
Yesterday I discovered it's theoretically possible to create an ASCII Jar file, one where each byte of the file is a valid ASCII character. Today I'm trying to create one. Sometimes I regret my impulses.
11 months ago
0
5
0
I often find when explaining complex exploits that it can appear like such an unlikely event that the exploitable steps exist. In reality it's just _this_ is the particular set of unlikely steps I found. I'm sure there are others, but I stopped looking after these steps were successful 🤔
11 months ago
1
7
0
I love it when I answer my own questions
11 months ago
0
4
0
I've recently reported a bug that was _caused_ by patching. If the old version of the library was left unpatched it wouldn't have been vulnerable 🫣 Remember folks, don't patch your dependencies... or do... or you are damned either way 🤷♂️
12 months ago
0
8
0
At 33,500,000,000 hashes / second, it'll only take *checks calculator* 17.5 years and $115,000 for an exhaustive search... I might need to rethink this 🤔
add a skeleton here at some point
12 months ago
2
4
1
I'm currently at the "Is it worth it to rent some cloud GPUs in order to attempt to bruteforce a hash" stage of bug hunting 😬
12 months ago
2
11
2
CVE-2025-5419 ITW Chrome exploit mitigated in 1(!) day after report to all users without requiring a browser update 🤯 I hand't read up on the Finch Kill Switch before, such a powerful exploit mitigation feature from the Chrome team!
developer.chrome.com/docs/web-pla...
loading . . .
What is a Chrome Finch experiment? | Web Platform | Chrome for Developers
Learn about how Chrome safely ships new features.
https://developer.chrome.com/docs/web-platform/chrome-finch
about 1 year ago
0
3
1
reposted by
Alex Chapman
James Kettle
about 1 year ago
The recording of my recent AMA with the Burp Suite Discord community has just landed on YouTube! 40 minutes of unscripted Q&A on security research, AI, and Burp Suite:
youtu.be/mgmUZ9odkvU
loading . . .
AMA: James Kettle on Burp Suite, AI & Security Research
YouTube video by PortSwigger
https://youtu.be/mgmUZ9odkvU
0
18
8
reposted by
Alex Chapman
renniepak
about 1 year ago
For those who missed it, check out my talk, “Widgets Gone Wild: Exploiting XSS through Flawed postMessage Origin Checks.” 📺 Watch here:
www.youtube.com/watch?v=qgB0...
🖥️ Follow along with the slides:
0-a.nl/nahamcon/
loading . . .
Widgets Gone Wild: Exploiting XSS Through Flawed postMessage Origin Checks
YouTube video by renniepak
https://www.youtube.com/watch?v=qgB0ygRW2Ug
1
20
9
reposted by
Alex Chapman
renniepak
about 1 year ago
The slides and examples for my talk "Widgets Gone Wild: Exploiting XSS Through Flawed postMessage Origin Checks" at NahamCon can be found here:
0-a.nl/nahamcon/
1
8
4
reposted by
Alex Chapman
renniepak
about 1 year ago
If you’re into bug bounty hunting and like finding weird XSS bugs (like me 😊) in places most people overlook, come check out my talk at NahamCon 2025 this Friday, May 23. "Widgets Gone Wild: Exploiting XSS Through Flawed postMessage Checks"
1
13
4
Load more
feeds!
log in