Information security enthusiast. Riyadh DEF CON group @dc9661

Joined August 2009
405 Photos and videos
Mazin retweeted
PoCs for Apache Tomcat Unauth RCE (CVE-2026-34486) and Apache httpd Pre-auth RCE (CVE-2026-23918) are now public on our Github. Tomcat exploit is fully reliable. httpd chain works in a controlled lab setup with a known info leak. github.com/striga-ai/CVE-202… github.com/striga-ai/CVE-202…
4
184
739
93,818
Mazin retweeted
🚀 هكذا سيتم نشر اقمار ستارلنك في الجو 😍 تستعد SpaceX لإطلاق الجيل الجديد من أقمارها الصناعية (Starlink V3) بالاعتماد على مركبة Starship العملاقة. 🛰️ أبرز القدرات التقنية للجيل الجديد: 🔻 سرعات تنزيل بيانات (Downlink) مرعبة تصل إلى 1 تيرابت في الثانية (1 Tbps). 🔺 سرعات رفع (Uplink) تصل إلى 160 جيجابت في الثانية. حجم حمولة Starship الضخم سيسمح بنشر أعداد كبيرة من هذه الأقمار دفعة واحدة، مما يسرّع بشكل هائل من بناء شبكة إنترنت عالمية فائقة السرعة وتتحمل نقل بيانات ضخمة. 🌍
10
10
79
18,617
نظام مايكروسوفت المتخلف يبلشك حتى وانت بنص الفضاء.
JUST IN: Artemis II crew experiences issues with Microsoft Outlook on their way to the Moon, asks ground crew for assistance.
1
3
37
16,633
Mazin retweeted
JUST IN: Artemis II crew experiences issues with Microsoft Outlook on their way to the Moon, asks ground crew for assistance.
1,531
2,836
32,139
20,629,877
Mazin retweeted

37
240
1,076
223,819
Mar 1
1
45
Mazin retweeted
Did you know these Super Mario Bros. secrets!? 😲
49
303
1,440
110,262
🔴 تحذير أمني: بادر بإجراء التحديثات الأمنية على منتجات Lenovo. 🔗nca.gov.sa/ar/cert/7322/
6
6
2,071
I was recently laid off, so I’m officially open to new opportunities. If you need a Hacker, or a teachable moment using Red Team tactics. I can also be a trainer, community builder & liaison. I want more than a job I need a company & purpose I can believe in. Please share! 💜🤗💜
37
159
455
35,475
Mazin retweeted
9 Dec 2025
#CVE-2025-55182 #React2Shell Let me walk you through the technical path of the WAF bypass. When a request is sent as multipart/form-data, Next.js hands the raw body stream to Busboy. The bypass comes from Busboy’s charset logic: it cleanly accepts UTF‑16LE (and legacy UCS‑2) and forwards the decoded bytes straight into the RSC payload deserializer. charset=base64 is a dead route — that path hits base64Slice(), which encodes instead of decodes, corrupting the payload and killing the exploit chain. So the only viable encodings for smuggling malicious RSC payloads past WAF normalization are UTF‑16LE and UCS‑2. And if the WAF isn’t performing proper normalization on non‑UTF8 charsets, it will miss the payload entirely.
16
123
559
70,512
Mazin retweeted
شباب الـ IDE الجديد من جوجل Google Antigravity لازم تجربه شخصيا من أول استخدام له نويت أنقله وأترك ال VSCode عيوبه إلى الأن ما ظهرتلي لكنه ثابت جدا وقريب جدا من VSCode
1
1
2
328
🔴 تحذير أمني: بادر بإجراء التحديثات الأمنية على منتجات Google. 🔗nca.gov.sa/ar/cert/7185/
3
5
4,970
16 Nov 2025
RT @Ikennect: 😂This might be better than the original='Bodies'😂
2,090
Mazin retweeted
This was one of the greatest WiFi routers of all time.
WRT54G Router
154
197
3,439
154,991
Mazin retweeted
Something you may not know about Sonnet 4.5: it’s a special model for cybersecurity. For the past few months, the Frontier Red Team has been researching how to make models more useful for defenders. We now think we’re at an inflection point. New post on Red:
8
48
311
71,524
Mazin retweeted
28 Sep 2025
We triggered WhatsApp 0-click on iOS/macOS/iPadOS. CVE-2025-55177 arises from missing validation that the [Redacted] message originates from a linked device, enabling specially crafted DNG parsing that triggers CVE-2025-43300. Analysis of Samsung CVE-2025-21043 is also ongoing.
37
265
1,118
278,887