@fwrnr

Hacking vagrant. Flexing on computers, every bone and muscle, and previously: Vulnerability Research @NCSC / @interruptlabs / @pwc_uk

Bangkok
Joined April 2016
I was awarded $65,400 for my submissions on @bugcrowd #ItTakesACrowd The #bugbounty #bugbountytip here is turn off your testing mindset and turn on your vulnerability research mindset.
54
35
8
761
92,826
'The implementation confirms that the disc drive is fully capable of reading legacy disc formats directly' complete bs. the PS2 discs don't have blu-ray disc encryption so ofc they can be read... shitty reporting. TIL 'disc reader can read unencrypted bytes from disc'
en.gamegpu.com/news/igry/mod… The PlayStation 5 jailbreak community has successfully achieved direct playback of classic PlayStation 2 games straight from original discs using emulation. Players can now insert their retro media into the console drive without dumping image files. Following this breakthrough, modders are actively finalizing similar disc reading capabilities for PlayStation 3 physical media. The implementation confirms that the disc drive is fully capable of reading legacy disc formats directly. These community results clearly demonstrate that Sony possessed the technical ability to offer comprehensive disc backwards compatibility throughout the entire console lifecycle, yet opted not to invest effort into this feature. #PlayStation #PS5 #PS2 #PS3 #Emulation #Jailbreak #Gaming
1
198
Like this really isn't useful, you can dump those games and load the EBOOTs without a console
57
You're making a mistake, this doesn't make PS2 games any more useful, as you can just rip them anyway and load them up as game EBOOTs...
PS2 discs. Straight into a PS5. 20+ years of nostalgia, one disc away. PS5SX2 🎮 special thanks to @_AlAzif 🔗 github.com/Swordpdf/PS5SX2 💬 discord.gg/mFpkX6gng ☕ ko-fi.com/sword95 #PS5 #PS2 #PlayStation #PS5SX2 #Homebrew #Emulation
2
258
*sigh*
Replying to @iBSparkes
I have a buddy who now says 'gate' to represent anything logically conditional...
226
another one
your 'free thinking' homo sapiens, sir...
1
298
your 'free thinking' homo sapiens, sir...
y’all ever get that “can’t tell if this post is ai or if buddy has just used it so much he can no longer speak like a normal human”? it’s a bit worrying
1
1
3
912
My accuracy dropped from 100% to 20% on @Bugcrowd with the new changes, and I haven't reported a bug on bc in over a year, wild
4
1
75
4,046
Exactly. You, the person actually suffering financially, you are not the 'human' in this equation, the person getting paid consistently every month to triage reports... THEY are the human, suffering immensely! Empathize with them a bit, you meanie! - The bug bounty middle class
Apparently calling out the person because of whom we lose thousands of dollars is not being kind to them. 👏👏👏
8
580
'fuel prices are straining families and quality of life, that's not acceptable! I want to help. So today, I am officially announcing A/B testable fuel prices!'
I know people are worried about fuel prices. And I get it. You get to the pump, watch the numbers climb, and wonder why it's costing so much more than it used to.   The reality is that global events are pushing up costs, and families here at home are feeling the impact.   But I won't accept that there's nothing I can do to help.   That's why from today, you'll be able to see petrol and diesel prices on Google Maps, compare nearby stations and find the cheapest option before you fill up.   It's a small change, but if there's a practical way to help people keep more money in their pocket, I'll do it.
221
Here is how this works: triagers held accountable -> triagers hold management accountable for putting them in position where they can't triage effectively -> this recurses up the chain until someone is held accountable. OR you can loop forever with "they're hoomans!" WE KNOW...
Attacking triagers is NOT OK. People who haven't done the job think it's easy, and they could do better. Hackers always think their submissions are perfect, are always first, should never dupe, and it's the triagers fault if not. You could not be more wrong!
2
1
26
1,649
This is the greatest idea ever. Let's have a directory of 'bug hunters' who introduce the most triage friction to platforms, and the same for triagers. But you'll quickly see that platforms are punishing actual hunters because 99% are being allowed to take part in a slop fest.
Replying to @fwrnr @vortexau
Would you feel the same if a company’s employee said “‘worst hackers on our program is______. Fill in the blank?” And every other program owner chimed in? It’s never okay to name drop and blame them. I agree triage hasn’t been the best experience for a lot of us, but remember they’re also humans like us who make mistakes and are trying to make a living.
4
1,018
This is the kind of token burning I can get behind
The optimality of the packing for 11 squares has been formalized in lean thanks to Astra and Claude! Huge thanks to @ojoshe, @kleddamag, @wand_125, @guzhou0806, and @ctjlewis for aiding in the process. Image credit: jlevy.github.io/squares/case… 1/n
244
Felipe Warrener-Iglesias retweeted
Yes. On the set of The Punisher (2004), a prop mix-up left a real butterfly knife instead of the retractable one. Thomas Jane stabbed Kevin Nash in the collarbone during their fight scene. Both actors have confirmed the incident in interviews.
5
16
4
2,826
229,707
'may lead to privilege escalation' yeah we'll see
"Several vulnerabilities" in the Linux kernel lwn.net/Articles/1097401/
1
377
It's risky drinking decaf in a place like Vietnam, where the coffee is triple the strength of other places... one small barista-error and you might end up with Vietnamese coffee flowing through your veins. Long story short, I will be having a panic attack in about 20 minutes.
2
15
1,510
Felipe Warrener-Iglesias retweeted
C’est IMMONDE. Comment tu peux faire ça à des pompiers ? 😤 Je n’ai plus les mots. J’ai tellement la rage devant ces images insupportables.
1,798
9,697
831
33,347
851,121
Why do programs take something out-of-scope when you start hacking it? What's the point? It just devalues your research... They should give you a bonus for every internal finding from their internal audit when they take something out-of-scope as a result of you.
It blew my mind - someone got 133700*3 !
5
1
81
8,112
Not to mention people who are mid-research, especially deep research, on a target for them to be suddenly not interested in bugs anymore. People who did well in the early days of bug bounty did not have to deal with stuff like this as far as I understand. You were paid per bug.
1
6
666
Felipe Warrener-Iglesias retweeted
LLM arena but for code aesthethics
1
6
1
77
25,961
This is, surely, a massive liability to customers? Like, if someone submits 5 duplicates through no fault of their own (just decent coverage or slow time to fix) then comes across a major critical... They can't report it? Surely there is some sort of risk/liability here?
If you're trying to get started on H1, good luck. Their trial report system makes no sense. If you submit 6 bugs that are all valid but sadly a duplicate, then ohh bad luck, can't report anymore for a month...
1
4
1,324