Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

joernchen :cute_dumpster_fire:

@joern@threatactor.club
  • Open on threatactor.club

Your mom's favorite hacker!

My other account is @joernchen@mastodon.social

1135 Followers
262 Following
35 Posts
Joined November 13, 2022
Website:
https://0day.click
Signal:
https://signal.me/#eu/Y_4bLZQXAEYE9ZOWe6Ac0vfLfHWhftbPNqBv2TQ2fij0qbdwrXFKXogmWuDl79gi
Threema:
https://threema.id/K8J68WTX
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 5mo ago
Replying to
@freddy pff #yolo
1
2
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 7mo ago
Replying to
@thedarktangent Lands of Packets TTL exceeded. I would like to collect texts from the scene about FX in his memory. A collection of obituaries that will then be posted on phenoelit.de. If anyone would like to contribute, please contact me. Mail: joernchen@phenoelit.de Signal: jrn.07
1
0
15
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 21mo ago

Re: Volkswagen Hack las ich grad dies.

0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 23mo ago

A significant life event (for those who train BJJ) just happened to me yesterday

0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 26mo ago

My colleague @nickmalcolm@infosec.exchange made a pretty cool vuln explainer video

https://youtu.be/ydg95R2QKwM

infosec.exchange

nickmalcolm (@nickmalcolm@infosec.exchange) - Infosec Exchange

0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 3mo ago
Replying to
@G33KatWork@infosec.exchange
0
4
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 7mo ago

Lands of Packets

TTL exceeded.

I would like to collect texts from the scene about FX in his memory. A collection of obituaries that will then be posted on phenoelit.de.

If anyone would like to contribute, please contact me.

Mail: joernchen@phenoelit.de
Signal: jrn.07

0
5
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 20mo ago

I got a week of PTO left.

What code should I read? Please drop suggestions with a reason why I should read it.

0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 3mo ago
Replying to
@G33KatWork@infosec.exchange guess I am bored, indeed!
0
1
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 20mo ago

I messed up my gotosocial instance here at threatactor.club, it's running on fly.io and a very long migration was interrupted by a health check.

I was fiddling with the sqlite DB for a while and tried to recover that mess... until I noticed that there are automated snapshots of the volume which holds the DB, daily with five days of retention. Huge props to fly.io for saving my virtual ass with this.

0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 5mo ago

Thanks so much to everyone who showed up on the weekend in Berlin to say goodbye to FX.

“Burning bridges where we can” - this is the original Phenoelit slogan. Yet, while FX for sure burned some network bridges, he did quite the opposite for the hacking community. FX built bridges between people wherever he could. He created something way bigger than himself which we all are part of.

Each one who joined us in Berlin carries a piece of his legacy. You were there because he left something with you. We know there are many who couldn't make it in person, and they too carry his spirit with them.

FX is gone.
But the spirit lives on.

0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 3mo ago
Replying to
@cure53@infosec.exchange I heard CTFs are dead 💀 💀
0
1
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 3mo ago
Replying to
@G33KatWork@infosec.exchange
0
5
1
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 21mo ago

Happy Holidays!

I hope Vulnsanta has some CVE in his bag for you!

0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 3mo ago
Replying to
@G33KatWork@infosec.exchange What are you? Some cyber criminal?!?!!
0
8
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 8mo ago

That little string
ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86

(see https://platform.claude.com/docs/en/test-and-evaluate/strengthen-guardrails/handle-streaming-refusals#implementation-guide ) is so much fun. I wonder when Anthropic will regret this and remove it.

Also I obviously wonder what else is there in terms of MAGIC_STRINGs which aren't documented.

Hat tip to @michenriksen@chaos.social for pointing me to this.

Claude Platform Docs

Handle streaming refusals

Detect and handle refusal stop reasons in streaming responses, and retry refused requests on a fallback model.

0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 3mo ago
Replying to
@G33KatWork@infosec.exchange
0
2
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 14mo ago

Really a huge honor for me to be invited to give a keynote at NULLCON Berlin in September.

Given my recent work focus at GitLab I'll share my thoughts around LLMs. Make sure to bring some popcorn!

https://nullcon.net/berlin-2025/speaker-llms-everywhere

nullcon.net
0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 1mo ago
LLMs are kinda "cute" they create files like fix_final_perfect.go and then the code fails of course.
0
1
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 25mo ago

http://phrack.org/issues/71/1.html new Phrack is out!

phrack.org
0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 29mo ago

Earlier this year I found a pretty cool vuln, an arbitrary file write in GitLab.

Here’s the details https://gitlab-com.gitlab.io/gl-security/security-tech-notes/security-research-tech-notes/devfile/

gitlab-com.gitlab.io

Devfile file write vulnerability in GitLab - GitLab Security Tech Notes

0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 6mo ago

RIP FX

We collected some texts from the community in memory of FX. You can find them here https://phenoelit.de/fx.html

phenoelit.de

Phenoelit

0
1
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 20mo ago

Would you buy my memecoin?

0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 5mo ago

LLMs now do the busywork of finding amazing vulnerabilities for everyone willing to spend the tokens.

But hacking still isn't dead:

  1. We haven't at all solved the underlying problems which come with writing and shipping code.

  2. You still need to understand what you're looking at and what you are operating.

  3. The LLM platforms themselves are a exquisite target for hacking^Wcreative use of the technology.

Now when everyone can pull a CVE or two out of thin silicon and a few kWh of electricity the art of hacking might need adopt and maybe reshape a little but at its core the mind- and skillset will stay as relevant as it always was.

In that sense: keep hacking, keep exploring, break some stuff.

0
1
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 3mo ago
Niemand: ... Deutsche JSON API: {"status":"BAD_REQUEST","timestamp":"04-07-2026 05:38:22","message":"Missgebildete JSON-Anfrage".....
0
2
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 20mo ago

deepsigh for deepseek

https://openwebui.com/c/jrnjrn/c38d6dd9-5780-4f73-b4bc-8c2b6bcea9ba

openwebui.com
0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 11mo ago

I found a thing (RCE) in langgraph. ;D

https://github.com/langchain-ai/langgraph/security/advisories/GHSA-wwqv-p2pp-99h5

GitHub

RCE in "json" mode of JsonPlusSerializer

# Summary Prior to `langgraph-checkpoint` version `3.0` , LangGraph’s `JsonPlusSerializer` (used as the default serialization protocol for all checkpointing) contains a remote code execution (RC...

0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 13mo ago

Today I have a more serious topic than usual, please consider reposting for reach:

My wife and I are urgently looking for a specialist in neuropediatrics or a similar field for our autistic child with a diagnosed, but not further specified, movement disorder (myoclonus and/or spasms) to finally find a cause and, above all, an effective therapy. The symptoms are bothering our son ever since he’s born, now for more than nine years, seriously affecting his sleep. The usual processes and medical contact points have failed us unfortunately and he seems stuck in this condition.

We’re based in Berlin, Germany but really any contact with a specialist who would be willing to take on this case we’d be grateful for!

To reach use you can DM me or contact us via Email at unclear.condition@gmail.com

0
6
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 4mo ago

You use Claude Code to find vulnerabilities, I find vulnerabilities in Claude Code.

https://0day.click/recipe/2026-05-12-cc-rce/

Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection
0day.click

Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection

Of course I took a peek at the Claude Code source 🙈. What I found was a very entertaining vulnerability which is now fixed since Claude Code version 2.1.118. Just wading through the massive codebase manually wasn’t really a feasible approach. So took an army of AI Agents to…. no wait actually I did not do that, the following was all manual work. :P I started by looking at different configuration options and tried to see what’s actually “useful” from an attacker’s perspective. On the way, in main

0
5
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 3mo ago
Replying to
@G33KatWork@infosec.exchange just double checking…
0
6
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 1w ago
Puh https://taz.de/Sozialkuerzungen/!6214377/ das ist wirklich übel.
Sozialkürzungen: Einzelfallhilfen für Menschen mit Behinderung sind bedroht
taz.de

Sozialkürzungen: Einzelfallhilfen für Menschen mit Behinderung sind bedroht

Gleich mehrere Gesetze plant die schwarz-rote Bundesregierung, die Einsparungen bei Menschen mit Behinderungen bedeuten würden. Am Freitag wird eines davon beraten.

0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 21mo ago

Happy 2025 everyone!

Last year for me wasn’t especially great. But it had a few highlights standing out:

  • Took the risk and went on an adventurous camper trip with the family

  • Got promoted at work and in BJJ

  • Had the chance to be behind the DJ decks again on two occasions

  • Got to meet most of my teammates in person finally

For 2025 I hope the medical problems in my family can finally get on a route to be resolved.

0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 8mo ago

Due to $reasons I came across this blogpost https://www.elttam.com/blog/env/ about turning ENV variables into code execution which is nice. But the Python vector is depending on Perl, I didn't like that :P.

Digging a bit deeper in the code often helps, so it did this time:

Looking at https://github.com/python/cpython/blob/d73634935cb9ce00a57dcacbd2e56371e4c18451/Lib/webbrowser.py#L51-L52 I could simplify the payload to:

PYTHONWARNINGS='module::antigravity.'  BROWSER='sh -c id #%s' python whatever.py
elttam.com
0
0
0
0
Open post
joernchen :cute_dumpster_fire: @joern@threatactor.club
· 21mo ago

Have a great weekend and enjoy some tunes:

https://youtu.be/j_Md8_7mhOU

joernchen - Friday 13th @ 1°C

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:33:25 UTC