Joined December 2022
2 Photos and videos
caon retweeted
31 Oct 2025
Not even in Brazil yet, and the @BugBountyBr guys already gave me such a warm welcome 😁 @highustavo @zeroc00i @locs3c @_caon__ — thanks for the live, guys. That was insanely genuine!
1
5
17
1,423
caon retweeted
15 Oct 2025
🟥 Positive Hack Talks → São Paulo 🇧🇷 Dec 10th, 2025 🗣️ Speakers — submit papers (flights/hotel covered). CFP link in thread 👇 💻 Cybersecurity community — join our most community-driven event. ➡️ phtalks.ptsecurity.com/saopa… Free · 8 talks · limited spots #PHTalks
3
34
88
17,867
20 Oct 2025
Ótima oportunidade para a comunidade! 🚨 LHE – Mercado Livre Hacking Event 2025 🚨 🗓 25/10 a 01/11 Escopo ampliado, desafios, bounties e premiações exclusivas! Inscreva-se: forms.gle/Cs35PeYcoGsm8enV9
2
2
17
3,338
20 Oct 2025
1
1
423
caon retweeted
🚨 CALL 4 PAPERS — Bug Bounty Village @ H2HC 2025 🚨 Caçou um bug insano? Tem case real ou técnica nova? Esse é seu palco! Envie sua proposta pelo form: bit.ly/4n4hXf9 #H2HC #BugBountyVillage #Call4Papers #HackerCulture
1
8
8
3,195
caon retweeted
21 Aug 2025
Hackers, To make our pricing fairer worldwide, we’re trying out localized pricing. We’re starting with Brazil 🇧🇷, with Individual plan prices dropping by about 50%. 💸 Monthly: ~110 BRL → 55 BRL 💸 Yearly: ~1,100 BRL → 550 BRL Which country should we do next? caido.io/blog/2025-08-21-loc…
47
26
314
35,556
caon retweeted
I don't know who this will help but I put together a page listing JavaScript APIs that can break Shadow DOM encapsulation :) github.com/masatokinugawa/Sh…
2
51
206
18,719
caon retweeted
16 Aug 2025
Try this out on your next target! Some more gold from the guys at @ctbbpodcast! 🔥
2
48
278
16,801
caon retweeted
New Android host validation bypass technique! [1/4] All parsed URIs in Android are android.net.Uri.StringUri objects. However, the scheme parser only looks for the ":" delimiter
5
73
300
28,992
caon retweeted
How to find viable targets for client-side desync attacks: 1️⃣ Open Burp Suite and intercept requests. 2️⃣ Choose an endpoint that wouldn't usually expect a POST request (e.g GET) and send it to repeater. 3️⃣ Go to Inspector > Request Attributes > Protocol field > Upgrade to HTTP/2. 4️⃣ Send the Modified Request and look for this error message: "Server ALPN does not advertise HTTP/2 support"... 5️⃣ Enable ALPN Override in request settings and send again. If you see "Stream failed to close correctly" then you've confirmed that the server does not support HTTP/2 and is a valid target for desync testing! Want to learn more about desync attacks? On August 6, at Black Hat USA, James Kettle from PortSwigger Research will reveal new classes of desync attack that enabled him to compromise multiple CDNs and kick off the desync endgame! 😲 Stay up to date here: http1mustdie.com/
3
51
338
16,455
caon retweeted
3 May 2025
If the origin server treats a delimiter, but the cache doesn’t and the cache normalizes paths before applying static directory rules you can leverage path traversal! Take this payload: /myAccount$/../static/any - The cache sees: /static/any - The origin sees: /myAccount The response for /myAccount is cached under /static/any and anyone that visits that static URL gets leaked data.
1
67
340
16,275
caon retweeted
Want to know how I discovered this vector? Read the blog... thespanner.co.uk/the-curious…
2
21
142
7,973
caon retweeted
24 Apr 2025
RFC 2047 "encoded-word" is crazy! It lets you smuggle encoded payloads into email addresses and the craziest thing is that some parsers decode it before validation 👇 Shout out to @garethheyes for this  🔥
5
69
441
32,458
caon retweeted
31 Mar 2025
JS, Python & Ruby all disagree on this regex rule 🤔👇
1
22
181
17,806
caon retweeted
20 Mar 2025
I've just released my proof-of-concept tool called pugDNS. It's an experimental high-performance DNS bruteforcer built with AF_XDP. It's up to 3x faster than massdns, and 30x faster than dnsx. github.com/c3l3si4n/pugdns
1
49
242
13,136
caon retweeted
🚨 AI Security Failure 🚨 @AnthropicAI I bypassed the #constitutionalclassifiers designed to block harmful content and extracted detailed chemical information on a restricted substance. Despite passing multiple safeguards, the content checker failed to flag it as harmful. Here’s what happened: 🧵
2
1
13
1,572
caon retweeted
Hi HACKERS, here are my suggestions for the Top Ten (New) Web Hacking Techniques of 2024 @PortSwigger @PortSwiggerRes : • “Another Vision of SSRF” (@ph0r3nsic) • “Unveiling TE.0 HTTP Request Smuggling” (@bsysop) • “Supply Chain Attacks: A New Era” (@caueobici) If you haven’t read these yet, what are you waiting for? Let’s dive in! portswigger.net/polls/top-10…

1
15
1,505
caon retweeted
I found you could use the ISO-2022-JP escape sequences inside JS URLs! Found using this: hackvertor.co.uk/hack-pad/5 Poc: portswigger-labs.net/xss/cha…
4
80
407
54,883
caon retweeted
19 Dec 2024
Where there’s bug bounty, there’s #Bugcrowd. 😉✨ We’re honored to have supported the @BugBountyBr at H2HC in #Brazil, big thanks to @bsysop! Seeing the hacker community come together with such passion was nothing short of amazing (as always). 🥲 Huge thanks to the organizers, sponsors, and everyone who joined—you made it unforgettable! 🎉💚
11
32
5,779