0xbro

Penetration tester, content creator & wannabe ethical hacker.

I have a YouTube channel where I demonstrate breakdowns of some CTFs or explore topics related to offensive cybersecurity.

I also have a blog where I post the same content as YouTube but in an "old-school" text format.

2023-11-16

I'm happy to share the attribution of my first #CVE!

Authenticated Static Code Injections in #OpenCart (CVE-2023-47444)

You can find the details and PoCs about the two vulnerabilities on my blog:
0xbro.red/disclosures/disclose

2023-05-03

Easy-peasy #android emulator setup without using Genymotion or Android Studio + installation of custom certificates inside the system #certificate store of an Android 10 device.

youtu.be/v-p1dTWmWDY

#mobilehacking #androidhacking #androidstudio #androidemulator

2023-04-17

Waffle-y Order is a medium-difficulty Web challenge from #HackTheBox, involving the exploitation of parser differential vulnerabilities to bypass a regex-based #WAF and chain a PHP arbitrary #deserialization with a blind #XXE to read arbitrary files and, finally, exfiltrate data.

Read the writeup here:
maoutis.github.io/writeups/Web

See the video here:
youtu.be/IESwry_l-UU

#hacking #wafbypass #applicationsecurity #writeup

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst