J0R1AN Profile Banner
Jorian Profile
Jorian

@J0R1AN

Followers
446
Following
1K
Statuses
130

Normalize being weird. (also here: https://t.co/cr9Y0kDEBi)

He/Him
Joined November 2019
Don't wanna be here? Send us removal request.
@J0R1AN
Jorian
1 year
I almost can't believe it, but I am finally releasing my Gitbook about CTF and Hacking, which is a year in the making. It contains many tricks, explanations, and resources from my experience and research. I hope it becomes a valuable resource for everyone!
1
4
31
@J0R1AN
Jorian
17 hours
RT @kevin_mizu: I'm very happy to finally share the second part of my DOMPurify security research 🔥 This article mostly focuses on DOMPuri…
0
72
0
@J0R1AN
Jorian
3 days
RT @ruben_v_pina: form-action Content Security Policy Bypass This bypass can help you turn those unexploitable XSS bugs into exploitable v…
0
15
0
@J0R1AN
Jorian
14 days
@Rhynorater @garethheyes @kinugawamasato Next up: alert() in CSS!
0
0
4
@J0R1AN
Jorian
15 days
@ankursundara @x3ctf @EhhThing Yes! That was an awesome challenge, I also link to it in my writeup. That was the inspiration for abusing crashes, and I just found that is possible to leak cross-site
0
0
1
@J0R1AN
Jorian
19 days
We all use tools while pentesting, but what if these tools are vulnerable themselves? We found multiple high vulnerabilities in PwnDoc and its libraries docx-templater & angular-expressions. My favorites are the JavaScript templating sandbox escape tricks!
0
6
29
@J0R1AN
Jorian
23 days
RT @slonser_: In 2024, I interacted a lot with Extensions. I decided to create a resource that will help with a basic understanding of ext…
0
94
0
@J0R1AN
Jorian
25 days
My colleague is organizing the first ever BSides in Groningen, Netherlands! This is a community-driven event taking place May 2nd. If you have a cool story or piece of research for a talk and want to attend, be sure to submit to the Call for Presentations:
0
0
4
@J0R1AN
Jorian
26 days
RT @albinowax: Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: http…
0
72
0
@J0R1AN
Jorian
1 month
I loved playing with team Superflat during the IrisCTF 2025 last weekend, where we ended up in 4th place. The challenge I enjoyed most was about a cool DNS Rebinding technique with a cache, and learning some Java/Kotlin along the way!
1
11
50
@J0R1AN
Jorian
1 month
@UK_Daniel_Card To be honest a lot of my client-side attacks require the victim to get on my site. Making them click a link seems like a pretty good way to do that. You don't need a Chrome RCE, sometimes CSRF/Reflected XSS is enough
3
0
2
@J0R1AN
Jorian
1 month
RT @ctbbpodcast: We had some delays in the video version of the pod this week, but the latest episode is up on YouTube now. We covered a b…
0
2
0
@J0R1AN
Jorian
2 months
Just arrived at #38C3, just as excited as I was last year 🙌
0
0
4
@J0R1AN
Jorian
2 months
@garethheyes @terjanq I've noticed on Chrome it sometimes needs a bit of convincing by repeating the escape sequences a few times. Learned this from @LooseSecurity's challenge:
1
1
7
@J0R1AN
Jorian
2 months
Have you tried my december XSS challenge? The solution's public now in this writeup! It includes two vulnerabilities in CodeIgniter that abuse the cache storage format and bypass its builtin XSS filter. Merry Christmas! 🎄
@intigriti
Intigriti
2 months
đź“š Can't get enough of this challenge? Here's the official writeup by @J0R1AN đź’ś
1
0
16
@J0R1AN
Jorian
2 months
RT @intigriti: As a final hint, we'll give you our plan to save Christmas! First, look into this mysterious "cache" to find an escape rout…
0
2
0
@J0R1AN
Jorian
2 months
@disclosedh1 Blog post incoming :D
0
0
2
@J0R1AN
Jorian
2 months
RT @S1r1u5_: Imagine opening a Discord message and suddenly your computer is hacked. We discovered a bug that made this possible and earne…
0
171
0
@J0R1AN
Jorian
2 months
Good luck and have fun!
@intigriti
Intigriti
2 months
⏰ It's CHALLENGE O'CLOCK! 👉 Pop an alert before Thursday 19th of December 👉 Win €600 in SWAG prizes 👉 We'll release a tip for every 100 likes on this tweet Thanks @J0R1AN for the challenge 👇
1
0
6
@J0R1AN
Jorian
2 months
RT @YNizry: 🧬🔬 I wrote about this finding a bit more extensively in my blog: #mXSS #XSS
0
23
0