JacoubRob's profile picture. toujours derrière ton pare-feu.

makarov

@JacoubRob

toujours derrière ton pare-feu.

makarov reposted

One thing I like do do when auditing is picking a state variable alone and focusing on it. Sometimes moving the focus away from the main flows but focusing just on how each var is updated everywhere makes bugs more obvious / increases the understanding of the codebase faster.


makarov reposted

Our Balancer retro is live. The ecosystem has evolved & rounding issues are more critical than ever. Here are recommendations for preventing rounding issues and other important lessons from this incident: blog.trailofbits.com/2025/11/07/bal…

Since the Balancer hack on Monday, we've been working around the clock to help the Balancer team understand the bug and its implications. We've verified the bug's cause and have independently verified that the exploit does not work on Balancer V3. Once the dust settles, we plan…



makarov reposted

“If debugging is the process of removing software bugs, then programming must be the process of putting them in.” E Dijkstra


makarov reposted

Most JWT vulnerabilities go unnoticed as they're notoriously tricky to test for 😬 Yet, when present, they can allow for account takeovers, SQL injections and in-app privilege escalations 🤠 In our latest article, we break down every common JWT attack vector with practical…

intigriti's tweet image. Most JWT vulnerabilities go unnoticed as they're notoriously tricky to test for 😬

Yet, when present, they can allow for account takeovers, SQL injections and in-app privilege escalations 🤠 

In our latest article, we break down every common JWT attack vector with practical…

makarov reposted

Oh look, BAC made #1 🤣 If you ask 10 people to stand in a line and count each other, they will count off: 1.. 2... 3... 4.... NOT 52b25168-d784-4b3d-97ff-70841b39e8e9... be30ae3d-aa22-4cbc-8ecb-a172dffa066a..... We will have IDORs as long as we have humans making code.

This post is unavailable.

makarov reposted

This is still the way I recommend most people start in Web3 Security: 1. Get blockchain/smart contract basics 2. Do shadow audits 3. Analyse mistakes 4. Read similar reports/issues 5. After 1-2 month start in contests 6. Audit 80% / Study 20% 7. Repeat it type(uint256.max) times


makarov reposted

The demon at the end of my bed every night.

IAmAaronWill's tweet image. The demon at the end of my bed every night.

makarov reposted

I saw a post claiming it was simply access control bypass via user-provided input. unbelievable I remember hunting on this codebase back at the very beginning. part of me decidedly put it in the bucket of projects "too OG to contain bugs" which everyone looking at it must have…

I'm mad that I didn't catch the issue. I'm also mad that no whitehat or auditor did either. It's one of the pillars of DeFi, and they had a respectable bounty. We have no excuses. Sad day. The bug will probably be something trivial once understood. I still got much to learn.



makarov reposted

New cool updates in audit-rewards.xyz Now there are Contest tabs + per-issue hide feature. You can either track multiple contests or multiple reward scenarios, all at once. You can dup, rename, delete/add a new tab. suggestions by @s4muraii77 🫡

valuevalk's tweet image. New cool updates in audit-rewards.xyz

Now there are Contest tabs + per-issue hide feature. You can either track multiple contests or multiple reward scenarios, all at once.

You can dup, rename, delete/add a new tab.

suggestions by @s4muraii77 🫡

makarov reposted
HackenProof's tweet image.

makarov reposted

It’s extra scary when a protocol with a long track history is attacked. Waiting to see the post mortem so we can figure out how to improve industry best practices to stay safer…

We’re aware of a potential exploit impacting Balancer v2 pools. Our engineering and security teams are investigating with high priority. We’ll share verified updates and next steps as soon as we have more information.



makarov reposted

The article you've all been waiting for, finally! 🦄 Uniswap V4 Hooks Security Deep Dive 🦄 ✨ Epic @DevDacian style heuristic-based deep dive ✨ 26 categories & 126 examples of real bugs in the wild ✨ Learnings from 7 @areta_io @UniswapFND subsidized @CyfrinAudits Link 👇

giovannidisiena's tweet image. The article you've all been waiting for, finally!

🦄 Uniswap V4 Hooks Security Deep Dive 🦄

✨ Epic @DevDacian style heuristic-based deep dive
✨ 26 categories & 126 examples of real bugs in the wild
✨ Learnings from 7 @areta_io @UniswapFND subsidized @CyfrinAudits 

Link 👇

makarov reposted

Mastering Ethereum 2nd edition is officially out. How can you read it? - Online for free: in the next few days/weeks we will publish it on github/x and probably other venues - Kindle: you can buy it on amazon - Paperback: you can buy it on amazon - Online not for free (doesn't…

I probably have the biggest announcement of my career to make. Me, @crypto_ita2, and @idrocortisone are going to write "Mastering Ethereum: Second Edition." It is an honor for us to have the opportunity to update the masterpiece of @aantonop and @gavofyork. This is the biggest…

ManInBlackie's tweet image. I probably have the biggest announcement of my career to make.

Me, @crypto_ita2, and @idrocortisone are going to write "Mastering Ethereum: Second Edition." It is an honor for us to have the opportunity to update the masterpiece of @aantonop and @gavofyork.

This is the biggest…
ManInBlackie's tweet image. I probably have the biggest announcement of my career to make.

Me, @crypto_ita2, and @idrocortisone are going to write "Mastering Ethereum: Second Edition." It is an honor for us to have the opportunity to update the masterpiece of @aantonop and @gavofyork.

This is the biggest…


makarov reposted

Shoutout to those building their own future: - No rich parents - No connections - No help - No excuses Just hard work, consistency, commitment, and focus.


makarov reposted

The hardest part of bug bounty isn't finding vulnerabilities. It's dealing with: - Programs that ghost you - $100 "critical" payouts - Months of waiting Mental strength > technical skills.


makarov reposted

I just built a custom action to let you test for race conditions with a single click! No tab groups required, and it uses the cutting edge single-packet attack under the hood.

albinowax's tweet image. I just built a custom action to let you test for race conditions with a single click! No tab groups required, and it uses the cutting edge single-packet attack under the hood.

makarov reposted

1/6 Tired of manually testing every parameter hoping to find an XSS? Yeah us too. It's time-consuming, repetitive, and let's be honest, not the most exciting part of the job. So we built a Burp Suite extension @onetestfr to automate the entire process (Caido coming soon).

0xEdra's tweet image. 1/6 Tired of manually testing every parameter hoping to find an XSS?
Yeah us too. It's time-consuming, repetitive, and let's be honest, not the most exciting part of the job.

So we built a Burp Suite extension @onetestfr to automate the entire process (Caido coming soon).

makarov reposted

Security Researcher walks into a bar. Orders a beer. Orders 0 beers. Orders 999999999 beers. Orders a lizard. Orders -1 beers. Orders a sfdeljknesv.


makarov reposted

Want to know how to exploit HTTP headers? From basic to advanced techniques, our guide to HTTP header hacks gives you invaluable knowledge for securing bug bounties 💸 👉 yeswehack.com/learn-bug-boun… #YesWeRHackers #BugBounty #BugBountyTips

yeswehack's tweet image. Want to know how to exploit HTTP headers? From basic to advanced techniques, our guide to HTTP header hacks gives you invaluable knowledge for securing bug bounties 💸

👉 yeswehack.com/learn-bug-boun…

#YesWeRHackers #BugBounty #BugBountyTips

makarov reposted

🔌 Introducing the Burp Suite MCP Server extension Join us this Tuesday at 4pm BST (11am EDT) to see how you can leverage MCP for powerful AI integrations with Burp Suite. Live demo + Q&A with the devs. Join the PortSwigger Discord to attend 👉 bit.ly/4jwJDHt

Burp_Suite's tweet image. 🔌 Introducing the Burp Suite MCP Server extension

Join us this Tuesday at 4pm BST (11am EDT) to see how you can leverage MCP for powerful AI integrations with Burp Suite. Live demo + Q&A with the devs.

Join the PortSwigger Discord to attend 👉 bit.ly/4jwJDHt

Loading...

Something went wrong.


Something went wrong.