Joined March 2016
48 Photos and videos
Karel Origin retweeted
11 Jun 2025
Launching today! Volerion transforms raw CVEs into structured and instant insights #CVE #CyberSecurity #infosec
2
17
40
14,735
Easy you say?👀
1
2
1,025
Found myself in a scenario where I had to query a rate-limited API. The sleep command works but will waste a lot of time, as it cannot take into account the time passed since the call originally started. Couldn't find anything existing, so I created: github.com/karelorigin/limit…
3
8
47
9,176
Nothing too special, but it seems to work well :)
1
633
Karel Origin retweeted
I just published Identifying and Exploiting Unsafe Deserialization in Ruby XMLRPC link.medium.com/tc9mOBQlUBb
1
104
306
27,941
Karel Origin retweeted
You have command injection in a GitHub Actions workflow. Now what? Read my blogpost on leaking secrets from GitHub Actions workflows: karimrahal.com/2023/01/05/gi…

3
37
145
34,413
Okay, who's going to be the first to find an IDOR in Twitter's Edit Tweet functionality?
1
3
Karel Origin retweeted
20 Sep 2022
In yesterday's @CoreRuleSet release several critical issues are getting fixed which I and other hackers reported during #1337up0522. The most interesting bug affecting broader number of WAFs is yet to be released so stay tuned!👾👾 coreruleset.org/20220919/crs…
1
9
42
Had a lot of fun this event with @intigriti and @TheParanoids! Meeting the hackers and Yahoo/Intigriti people was a real pleasure :) #1337up0822
27 Aug 2022
🚥 Get ready, set, go! 🏎️💨 Time for these top hackers to relax and watch some top racers! #1337up0822 @TheParanoids @intigriti
1
19
All good things come to an end, even 1337up0522. Never thought that I would finish in 2nd place. Super grateful for the Most Valuable Hacker award. Thanks a lot @intigriti! Hope I get to do this again sometime! :)
3
2
28
Karel Origin retweeted
17 Feb 2022
What are some creative or less known takeover techniques using DNS? Such as subdomain or zone takeovers
5
12
Karel Origin retweeted
27 Sep 2021
.@Karel_Origin, @kapytein and I won the most advanced hack prize and second price for the hackademic award 🥳 was a fun day and I'm looking forward to next year IRL
We're thrilled to announce the winners of #HTH21: 1st Most Creative Hack: Bazen 1st Most Impactful Hack: Omegapoint--Göteborg 1st Most Advanced Hack: {{hubs.li/H0YcmsJ0}} 1st Hâckademic Award: FlosSecurity #HTH21 | @GemeenteDenHaag | @cybersprintnl | @zerocopter
1
4
20
Karel Origin retweeted
8 Mar 2021
Introducing: Wingman Wingman is an XSS scanner designed for bug bounty hunters, infosec professionals, and hobbyists. Read more: xsswingman.com/blog/posts/an…

7
87
289
Read all about our investigation on the HouseParty hack! 👇
31 Dec 2020
I couldn't bear the thought of going a full year without publishing a blog post on my website. So to end 2020, @KarimPwnz, @Karel_Origin, and I have published our investigation into the Houseparty hack: "The Story of the Million Dollar Bounty" — edoverflow.com/2020/housepar…
1
4
BOOM! This is it. The "BOOM" that started it all, or as @securinti likes to call it: The big BOOM. 6 years ago: hackerone.com/reports/16392
2
3
52
Pain is what you experience when you have a decent amount of followers but 0 likes on your latest tweet :P
6
I knew it
18 Sep 2020
of course I still love you
1
Wondering how much sensitive info example.com has in its access logs

5
Bug bounty was so much more exciting to me back in 2016
5
22
It really amazes me how many straightforward path traversal vulnerabilities exist, multiple (recent) popular CVEs are based on this exact bug.
2
1
10