RyotaK(@ryotkak) 's Twitter Profileg
RyotaK

@ryotkak

20 years old / Security researcher?
| Icon: @MelvilleTw
| Private: @RyotaK_Private
| Keybase: https://t.co/At1h6p5Kxf
| Misskey: https://t.co/63E5Rpv2pk

ID:1114004787324805120

linkhttps://blog.ryotak.net calendar_today05-04-2019 03:20:13

3,5K Tweets

5,3K Followers

705 Following

RyotaK(@ryotkak) 's Twitter Profile Photo

Reproduced DOMPurify 3.1.0 bypass, but my payload requires two mutations. Has anyone managed to trigger it with a single mutation?

Reproduced DOMPurify 3.1.0 bypass, but my payload requires two mutations. Has anyone managed to trigger it with a single mutation?
account_circle
RyotaK(@ryotkak) 's Twitter Profile Photo

I posted a blog regarding the vulnerabilities in the runtime of programming languages, including the recent Rust's critical vulnerability.

account_circle
首相官邸(災害・危機管理情報)(@Kantei_Saigai) 's Twitter Profile Photo

【津波警報】
津波警報を発表しました。
ただちに避難してください。
発表日時 3日09時01分
対象地域:沖縄本島地方、宮古島・八重山地方

account_circle
RyotaK(@ryotkak) 's Twitter Profile Photo

HackerOneアンバサダークラブの日本部門アンバサダーになりました。
日本におけるバグバウンティコミュニティはまだまだ小さいのが現状ですが、これから更に盛り上げていけるよう尽力します。

また、日本在住のバグハンターの方でアンバサダークラブの会員になりたいという方はDM等でご一報ください。

account_circle
RyotaK(@ryotkak) 's Twitter Profile Photo

I posted about a bypass of a recent DOMPurify patch, which allowed DOMPurify bypass in certain cases.

twitter.com/flatt_sec_en/s…

account_circle
CISA Cyber(@CISACyber) 's Twitter Profile Photo

We’re responding to CVE-2024-3094, a reported supply chain compromise affecting XZ Utils versions 5.6.0 and 5.6.1. XZ Utils may be present in Linux distributions. See our additional guidance at cisa.gov/news-events/al….

account_circle
Cure53(@cure53berlin) 's Twitter Profile Photo

Another really impressive variation of the XML Processing Instruction attack was spotted by RyotaK, thanks for reporting ❤️

It is now fixed, DOMPurify 2.4.9 & 3.0.11 were released.
Note that the attacks only work in case XML & HTML are mixed, most users might not be affected.

account_circle
RyotaK(@ryotkak) 's Twitter Profile Photo

特定条件下で刺さるDOMPurifyのバイパスを報告しました。後日軽い解説記事を書くかもしれません

account_circle
RyotaK(@ryotkak) 's Twitter Profile Photo

osu!gaming CTFで謎のRTA(?)をして89位でした
4時間でpp-ranking以外のWeb問潰したので許してくださいの気持ちです

account_circle
RyotaK(@ryotkak) 's Twitter Profile Photo

確定申告が終わったことを記念して、確定申告をやる際に使用したワールドを公開しました(?)

vrchat.com/home/world/wrl…

公開にあたってワールドデータを手直ししていただいた🥞氏に改めて感謝申し上げます

account_circle
NERV(@EN_NERV) 's Twitter Profile Photo

Major Tsunami Warning – 1/1, 4:22pm
The Tsunami Warning has been upgraded to a Major Tsunami Warning. Waves of up to 5m are expected. Those near coastal areas, rivers, or lakes should evacuate to higher ground immediately.

Major Tsunami Warning – 1/1, 4:22pm The Tsunami Warning has been upgraded to a Major Tsunami Warning. Waves of up to 5m are expected. Those near coastal areas, rivers, or lakes should evacuate to higher ground immediately. #tsunami
account_circle