Konstantin :C_H:
banner
kpwn.infosec.exchange.ap.brid.gy
Konstantin :C_H:
@kpwn.infosec.exchange.ap.brid.gy
I'm a hacker and mainly post about web security.

By profession, I am a pentester and team leader @usdAG.

I like to explain and understand things and I am […]

[bridged from https://infosec.exchange/@kpwn on the fediverse by https://fed.brid.gy/ ]
I recently ran into an interesting discrepancy:

What you see below are 120-bit Session IDs, one printed as hex and one in the format of a #uuidv4.

After validating their randomness, I would classify the first as secure but raise concerns about the second […]

[Original post on infosec.exchange]
July 1, 2025 at 12:37 PM
May 27, 2025 at 10:01 AM
Just a reminder to always lock your door!
#latchslipping #pentesting #physicalpentesting #security
May 22, 2025 at 8:31 PM
- 403 Forbidden
- 403 Forbidden
- 403 Forbidden

I've recently encountered a web application firewall in a pentest, blocking all my attempts to insert an XSS payload.

In such […]

[Original post on infosec.exchange]
May 7, 2025 at 12:27 PM
That moment when Apache Felix HTTP Webconsole Plugin destroys your layout… 🫠
March 13, 2025 at 7:02 PM
Wow! 119 new users joined #cvecrowd in just two days - except… they're all bots! 😂

Anyway, there’s a CAPTCHA now for sign-ups.
February 2, 2025 at 10:26 PM
Love the high quality content in #linkedin groups!
December 7, 2024 at 6:30 PM