ε‹ζ°‘ε…š / CTF with ${cYsTiCk} / @D3VC0R3 / TΓ’i-gΓ­, zh-TW, en-US, es-PY / πŸˆβ€β¬›

Joined July 2019
29 Photos and videos
some supply chain compromise
10
13
214
16,032
splitline πŸ‘οΈπŸˆβ€β¬› retweeted
That's a wrap on Pwn2Own Berlin 2026! πŸ† $1,298,250 awarded. 47 unique 0-days. 3 days of absolute chaos. And talk about main character energy - congrats to DEVCORE for claiming Master of Pwn with 50.5 points and $505,000 - they never slowed down. See you next year! #Pwn2Own #P2OBerlin
21
96
683
81,740
Booyah it's been confirmed! πŸŽ‰ splitline (@_splitline_) of DEVCORE Research Team chained 2 bugs to exploit Microsoft SharePoint, earning $100,000 and 10 Master of Pwn points. Massive aura farming this year at #P2OBerlin. Full win! #Pwn2Own
4
13
171
15,827
pure logic bug chain to pwn browser no memory corruption found without AI assistance 🍊 is built different omg
Confirmed! Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) chained 4 logic bugs to achieve a sandbox escape on Microsoft Edge, earning $175,000 and 17.5 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
1
80
7,601
splitline πŸ‘οΈπŸˆβ€β¬› retweeted
Honestly, with a little LLM help, I found variants, built a working PoC, and sent a polished patch to maintainer on the same day CopyFail dropped. So I’m curious why Xint didn’t find those variants before disclosure, assuming AI tools are used heavily in their workflowπŸ‘€ Disclaimer: I’m an independent reporter and the patch author of the xfrm-ESP vulnerability, unrelated to the Dirty Frag post.
May 7
πŸ’₯ Introducing "Dirty Frag" A universal Linux LPE chaining two vulns in xfrm-ESP and RxRPC. A successor class to Dirty Pipe & Copy Fail. No race, no panic on failure, fully deterministic. ~9 years latent. Ubuntu / RHEL / Fedora / openSUSE / CentOS / AlmaLinux, and more. Even if you've applied the "Copy Fail" mitigation, your Linux is still vulnerable to "Dirty Frag". Apply the Dirty Frag mitigation. Details: dirtyfrag.io
5
11
110
26,667
is there any cool non-frontend web ctf challenges this year that aren't llm-solvable πŸ‘€
1
4
830
splitline πŸ‘οΈπŸˆβ€β¬› retweeted
And this makes sense given how many CTFs are held per year. However, the ideal CTF challenge, in my opinion, should follow this formula: "The author conducted a mini-research project and instead of publishing it, turned it into a challenge."
3
15
127
14,374
splitline πŸ‘οΈπŸˆβ€β¬› retweeted
What I’ve always found amazing about CTFs is that "flag is flag". Whether you found an unintentional solve or pwned the browser with n-day for a XSS challenge, it didn't matter. I totally get the frustration of AI, but there is no solution other than accepting the change.
I started playing CTFs in 2022, and LLMs definitely changed the **competitive** CTF scene a lot, especially since mid-2025. I also started using LLMs in late 2025. Yes, those models did one-shot many challenges, but what's the fun of slopping them? I learned absolutely nothing πŸ₯²
18
38
447
69,545
splitline πŸ‘οΈπŸˆβ€β¬› retweeted
Jan 28
71
752
7,235
269,855
splitline πŸ‘οΈπŸˆβ€β¬› retweeted
4 Dec 2025
A POC for CVE-2025-55182 gist.github.com/maple3142/48…
32
429
1,968
550,315
splitline πŸ‘οΈπŸˆβ€β¬› retweeted
A bit late, but I just published my blog post on bypassing Ubuntu’s sandbox! Hope you enjoy it! u1f383.github.io/linux/2025/…
5
110
389
40,735
splitline πŸ‘οΈπŸˆβ€β¬› retweeted
12 Feb 2025
The blog post is the full version of my talk at 38c3. It's about some vulnerabilities we found in libarchive and some interesting behaviors of libarchive that you don't want to miss. My favorite part is it only took us 56 seconds to trigger a crash by AFL .
12 Feb 2025
Our latest deep dive explores libarchive vulnerabilities under recent Windows 11 updates. πŸ”πŸ”“ Check out NiNi's (@terrynini38514) technical write-up for key insights and security implications. Read more here: devco.re/blog/2025/02/12/fro… #VulnerabilityResearch #Cybersecurity
18
80
14,272
splitline πŸ‘οΈπŸˆβ€β¬› retweeted
11 Feb 2025
This is just a rumor to make themselves feel better, CTFers doesn't have life and probably all single
3
42
2,191
I will drop one web challenge there πŸˆβ€β¬›
25 Dec 2024
🚨 Brace yourselves, hackers! 🚨 The #ASIS #CTF Finals 2024 are coming on December 28th! πŸ’₯ 24 hours of non-stop hacking with mind-bending challenges that will push your limits. 🧠 Prepare for a thrilling ride - this is gonna be epic! #ASISCTF #CTF #Hacking
17
2,075
🍊 pumped my followers to 1k
15
1,764
Our hackathon for that website Worst.Fit was done successfully πŸ₯°

Our talk at #BHEU is done! Hope you all enjoyed it. πŸ˜‰ A detailed blog is on the way, but in the meantime, check out the pre-alpha website worst.fit/ for early access and the slides! Huge thanks to @BlackHatEvents and my awesome co-presenter @_splitline_! πŸˆβ€
1
2
22
3,653
Cool findings πŸˆβ€β¬›
Remember CVE-2024-4577, the PHP-CGI RCE bypass? Actually, the Best-Fit 'feature' also impacts non-CJK codepages such as locales in the Americas, Western Europe, Oceania, and more! @_splitline_ and I will share these cool findings at @BlackHatEvents! πŸ”₯ Let's make argument injection great again! πŸ˜‰ blackhat.com/eu-24/briefings…
1
10
2,626
I made one harder challenge πŸˆβ€β¬› wargame.d3vc0r3.tw/

20 Aug 2024
I've prepared 3 easy wargame challenges for HITCON CMT 2024 event, plus my coworker's challenge for a total of 7 challenges. I hope everyone enjoys themπŸ₯³
1
10
2,400