Louis Nyffenegger Profile Banner
Louis Nyffenegger Profile
Louis Nyffenegger

@snyff

Followers
19,119
Following
601
Media
948
Statuses
11,724

Founder/CEO/Trainer/Researcher/CVE archeologist @PentesterLab . Security engineer. Bugs are my own, not of my employer...

Joined December 2011
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@snyff
Louis Nyffenegger
12 days
Do you want to get into code review or improve your code review skills? Make sure you check out my upcoming live trainings: "Web Security Code Review Training"!
0
6
24
@snyff
Louis Nyffenegger
2 years
By age 30, You Should Have a Drawer with a Raspberry PI you don't use and a dozen USB cables.
537
1K
16K
@snyff
Louis Nyffenegger
5 years
I saw a guy reporting a vulnerability today. No logo. No website. No drama. He just emailed a write-up. Providing all the details needed to reproduce and fix the issue. Like a psychopath.
62
931
6K
@snyff
Louis Nyffenegger
10 months
I can't wait to open this one for Christmas!
Tweet media one
42
257
2K
@snyff
Louis Nyffenegger
3 years
Get the latest Windows security enhancements on Linux with this one simple trick: # chmod 755 /etc/shadow
24
263
1K
@snyff
Louis Nyffenegger
10 months
Christmas gift for your blue team friends
Tweet media one
25
221
1K
@snyff
Louis Nyffenegger
6 months
Certifications.
@HackingBaseball
Zack
6 months
What’s the biggest scam in tech that has become widely accepted?
1K
187
2K
23
128
1K
@snyff
Louis Nyffenegger
4 months
Tweet media one
11
125
891
@snyff
Louis Nyffenegger
3 years
16
220
879
@snyff
Louis Nyffenegger
4 years
A lot of people working in infosec often forget how lucky they were that their passion became a job in high demand...
35
91
839
@snyff
Louis Nyffenegger
4 years
I know sex is great but have you ever shell'd a company after they insisted the pentest was a waste of time...
27
56
798
@snyff
Louis Nyffenegger
2 years
Metasploit is written in Ruby. #infosec : we should all learn Python.
44
56
764
@snyff
Louis Nyffenegger
3 years
You need a degree, 5 years experience and 2 certifications to become a cybercriminal.
47
71
723
@snyff
Louis Nyffenegger
3 years
Just popped a shell? Run this command to increase the impact of your finding: export PS1="# " #bugbountytips
8
90
660
@snyff
Louis Nyffenegger
8 months
People who get SANS training
24
76
634
@snyff
Louis Nyffenegger
4 years
"Yes, the 3 types of hackers: blackhat, whitehat and asshat..."
17
82
609
@snyff
Louis Nyffenegger
3 years
This is a weird screensaver and not at all the one I downloaded...
Tweet media one
22
53
599
@snyff
Louis Nyffenegger
2 months
Tweet media one
9
82
564
@snyff
Louis Nyffenegger
3 years
A wise hacker once said: "you don't call yourself a hacker, other people do".
18
96
548
@snyff
Louis Nyffenegger
3 years
rockyou.txt
12
47
536
@snyff
Louis Nyffenegger
6 years
Everybody wants to be a hacker until it’s time to read/write code for few hours...
29
125
517
@snyff
Louis Nyffenegger
2 years
Are we going back to IRC?
74
28
496
@snyff
Louis Nyffenegger
3 years
How to Learn hacking in 30 Days? 🧵👇
63
86
473
@snyff
Louis Nyffenegger
8 months
Cyber security students be like: "If I win the lottery, I’m not telling anyone. But there will be signs."
Tweet media one
11
51
484
@snyff
Louis Nyffenegger
4 years
The world needs an old-school CTF... So far the challenges are: - Read this 5.25" floppy - Read this 3.5" floppy - Burn a CD - Crimp your own ethernet cable - Deploy a Peg DHCP server () - Connect to this token ring network Anything else?
223
77
472
@snyff
Louis Nyffenegger
4 years
Unpopular opinion: No one will be work as a "pentester" in a few years. People will perform pentest as part of their job as a security engineer, appsec engineer or redteamer. It has already started.
60
54
438
@snyff
Louis Nyffenegger
3 years
Infosec: "People sucks at threat modelling" Also infosec: "An attacker spends millions for a Super Bowl ad to get me to scan a QR code"
16
42
368
@snyff
Louis Nyffenegger
4 years
9 years ago, between Christmas and New Year, I started what will become @PentesterLab
25
8
361
@snyff
Louis Nyffenegger
4 years
Don't focus on tools, focus on techniques!
10
76
360
@snyff
Louis Nyffenegger
6 months
Too many people fall into the traps of gamification or certification, focusing on the wrong objectives. Your goal should be to learn, not to be at the top of the leaderboard or merely to pass an exam. [1/2]
9
80
353
@snyff
Louis Nyffenegger
3 years
Blackhat swag as seen by people outside of infosec: "This person is definitely a badass hacker". Blackhat swag as seen by people in infosec: "This person is most likely not doing any hacking".
16
30
341
@snyff
Louis Nyffenegger
1 year
Entertain your blue team with this amazing screensaver:
Tweet media one
10
48
351
@snyff
Louis Nyffenegger
5 years
TIL: How to exploit directory traversal in file upload with #curl using curl -F "file= @PentesterLab .jsp;filename=../../../../../../../../hacker.jsp"
Tweet media one
2
116
346
@snyff
Louis Nyffenegger
4 years
Hackers: 25 years later. Zero Cool manages a team of pre-sales engineers solving APT. Acid Burn and Lord Nikon are both CISO. Cereal Killer works for the government. Joey Pardella is trying to cover up a security breach. They are all #infosec thought leaders on twitter.
9
90
346
@snyff
Louis Nyffenegger
2 years
Recent photo of me getting ready to start reviewing code
Tweet media one
4
25
319
@snyff
Louis Nyffenegger
2 years
If you're looking for a job, try to blog regularly about CVEs (one you didn't find): 📚 You will learn so much ✍️ You will have something to show for it 🆓 It is completely free (unlike certifications🤔) 🎲 It removes the randomness out of your study/content (finding the bug)
7
37
301
@snyff
Louis Nyffenegger
7 months
Junior pentesters when a bunch of internal pentests gets allocated to the team
7
44
298
@snyff
Louis Nyffenegger
4 years
Security recommendation: Use bcrypt for passwords Implementation:
Tweet media one
17
38
282
@snyff
Louis Nyffenegger
3 months
They call me 007...
Tweet media one
7
33
286
@snyff
Louis Nyffenegger
3 years
“Hacking cannot be taught. Hacking can only be learned.” (based on a quote from Mikhail Botvinnik about Chess)
8
53
271
@snyff
Louis Nyffenegger
5 years
Metasploit: $0 Exploiting known unpatched vulnerabilities: $0 Leveraging public security research: $0 Deploying 0-dayz to compromise random phones using public USB power charging stations: $3000000 Someone who is good at the economy help me budget this my APT group is dying.
3
46
275
@snyff
Louis Nyffenegger
3 years
For people being surprised to see so many security tools in the twitch leak... This is what a modern security team looks like. Less buying off-the-shelf tools, more building tools based on your actual needs. 🛠🧰💰
12
31
272
@snyff
Louis Nyffenegger
2 years
Is #infosec ok?
Tweet media one
38
44
266
@snyff
Louis Nyffenegger
10 months
Tweet media one
2
43
270
@snyff
Louis Nyffenegger
3 years
Do you want to find new vulnerabilities? 1. Look at the patch for a recent CVE (for example: CVE-2021-43350) 2. Write a @semgrep rule for them (tune your rule using the CVE you picked) 3. Scan a lot of code repository with this rule. 4. Manually confirm the matches.
4
65
265
@snyff
Louis Nyffenegger
3 years
Lol... good luck!
9
3
258
@snyff
Louis Nyffenegger
3 years
I couldn't resist...
Tweet media one
12
17
252
@snyff
Louis Nyffenegger
4 years
Troll bug bounty hunters with this one mad trick: str.gsub!('${7*7}', '49')
9
39
254
@snyff
Louis Nyffenegger
5 years
Checkmate!
Tweet media one
17
76
236
@snyff
Louis Nyffenegger
7 months
“We take security seriously...” A   B     s      o      l    u      t      e     l    y    n o t ・ 。 ・゚ 。°*. 。*・。
Tweet media one
3
45
238
@snyff
Louis Nyffenegger
3 years
Do not get into hacking. I cannot emphasize this hard enough. Do not ever start hacking.
39
18
232
@snyff
Louis Nyffenegger
4 years
When people subscribe to @PentesterLab , they give me two things... Their $ and their time, I can't refund the latter and that's why I try to provide a lot of value...
8
11
232
@snyff
Louis Nyffenegger
1 year
Between me and the @RedTeamVillage_ there should be around 2000 of those at defcon!
Tweet media one
21
18
229
@snyff
Louis Nyffenegger
3 years
No need to sign your JWT, we are all friends here on the Internet!
5
14
214
@snyff
Louis Nyffenegger
6 months
Pentesters: “Bug bounties involve too much grinding for unpredictable outcomes.” Also pentesters: “I want to become a vulnerability researcher.”
8
21
213
@snyff
Louis Nyffenegger
3 years
You shout "Hack the planet" but your behaviour screams "Run a vulnerability scanner against Earth".
4
32
208
@snyff
Louis Nyffenegger
1 year
Unpopular opinion: A lot of people stick to CTF instead of Bug Bounty or Vulnerability Research because it is a lot more comfortable. Not easier, more comfortable, you know there is something to be found.
25
33
207
@snyff
Louis Nyffenegger
5 years
Give a man an open redirect, and you feed him for a day. Teach a man to chain open redirects with other bugs, and you feed him for a lifetime.
7
26
205
@snyff
Louis Nyffenegger
2 years
One day I will understand why most of infosec picked Python...
36
8
193
@snyff
Louis Nyffenegger
4 years
I made a bug bounty bingo card (with a shameless @PentesterLab plug)!
Tweet media one
11
45
192
@snyff
Louis Nyffenegger
3 years
I remember trying to learn Linux by printing pages and pages of Mandrake/RedHat manuals and trying to read them... THAT DID NOT WORK. What worked? Using Linux as my daily driver for months. It was hard, it was annoying, it was frustrating but this was the way.
17
13
186
@snyff
Louis Nyffenegger
10 months
Tweet media one
1
23
192
@snyff
Louis Nyffenegger
4 years
Not that it matters but since I saw another tweet on this: I have 0 CVE, 0 certification. People judging others on CVE or certs are at best lazy, at worst downright stupid...
14
23
188
@snyff
Louis Nyffenegger
3 years
There is one way to get better at hacking, it's hacking!
10
16
188
@snyff
Louis Nyffenegger
1 year
You are offered 20k. But you can never use Burp Suite again. Do you accept?
91
6
187
@snyff
Louis Nyffenegger
6 years
Who will be the first person to pass their OSCP naked?
20
42
183
@snyff
Louis Nyffenegger
2 years
It's important to remember that some infosec influencers are not achieving much and that a few infosec people with < 100 followers are killing it.
11
19
185
@snyff
Louis Nyffenegger
2 years
This is going viral so I'm sharing my "drawer"
Tweet media one
8
4
180
@snyff
Louis Nyffenegger
1 year
Thank you people writing PHP
Tweet media one
6
2
181
@snyff
Louis Nyffenegger
8 months
See mum! It is a real job!
@PentesterLab
PentesterLab
8 months
Our booth at CyberSec Asia
Tweet media one
2
7
176
9
2
179
@snyff
Louis Nyffenegger
4 months
If you have trouble keeping up with security research, security news, new technical content, make sure you check out: by @elttam
2
54
181
@snyff
Louis Nyffenegger
3 years
This one seems very relevant to security/hacking: "It doesn’t matter if you’re a beginner or an expert as long as you’re on the path. If a beginner is on the path, all they need is time. If an expert is off the path, they won’t be an expert for long." – @JamesClear
3
35
172
@snyff
Louis Nyffenegger
3 years
One man's shell is another man's incident.
8
40
169
@snyff
Louis Nyffenegger
4 years
I'm lucky to be working on some of the hardest Computer Science problems of our time... Like aligning text in CSS...
9
15
170
@snyff
Louis Nyffenegger
3 years
Tweet media one
6
21
168
@snyff
Louis Nyffenegger
4 years
One of the cheapest and most efficient way to improve your infosec skills is to read code. Literally, linux+vim+git on a raspberry pi with a 12” display is enough... Read the code of opensource projects, tools you use, diff from advisories. You don’t even need a browser!
5
25
168
@snyff
Louis Nyffenegger
2 years
"Do you need to learn to write code to get a job in infosec?" Absolutely not! You need to learn to write code because that is one of the coolest things you can do with a computer.
8
21
163
@snyff
Louis Nyffenegger
4 years
...
Tweet media one
6
18
161
@snyff
Louis Nyffenegger
3 years
This is very cool! (it's for a ridiculously simple patch in the Linux kernel)
Tweet media one
7
6
159
@snyff
Louis Nyffenegger
3 years
Let's all agree: Hacker skills == Number of followers. 👹👹👹👹
19
7
157
@snyff
Louis Nyffenegger
2 years
HODL
Tweet media one
8
18
158
@snyff
Louis Nyffenegger
1 year
I make a living teaching how to hack JWT, I will even run a workshop at Defcon on hacking JWT. If you are a developer and your application uses JWT spend 5 minutes and watch this video!
@PentesterLab
PentesterLab
1 year
Level up your #AppSec skills with our new video on JSON Web Tokens (JWT)! Join us as we share six practical tips to enhance your security practices. Arm yourself with these insights today! Watch, learn, apply! 🔒🎥💡
Tweet media one
2
27
114
0
30
156
@snyff
Louis Nyffenegger
4 years
Two years full-time on @PentesterLab ... Time flies.
15
2
156
@snyff
Louis Nyffenegger
3 years
Tweet media one
1
11
156
@snyff
Louis Nyffenegger
2 years
I cooked a beef bourguignon today. After a few hours cooking, the meat is falling appart like a pentest boutique that just got acquired.
12
14
155
@snyff
Louis Nyffenegger
3 years
@j2k3k 1. Take screenshot of desktop. 2. Use screenshot as screensaver/lock screen. 3. Leave laptop "unlocked" in public places. 4. Wait for outrage or LinkedIn thoughtleadership
3
7
151
@snyff
Louis Nyffenegger
1 year
You can find the slides for my 2 workshops at DEFCON here: SAML_DEFCON_2023.pdf and JWT_DEFCON_2023
1
56
148
@snyff
Louis Nyffenegger
2 years
Your script kiddie name is your first name followed by your last name.
10
12
145
@snyff
Louis Nyffenegger
3 years
My kids think I have the best job: My job is to send stickers to people all around the world.
16
5
147
@snyff
Louis Nyffenegger
7 years
Slides from my talk at @Ruxmon on the insecurity of JSON Web Tokens
1
82
144
@snyff
Louis Nyffenegger
2 years
Tweet media one
3
13
145
@snyff
Louis Nyffenegger
3 years
If people were spending as much time learning to code as they are spending debating whether or not you need to code to work in infosec, they will be pretty decent programmer...
7
18
142
@snyff
Louis Nyffenegger
4 years
Infosec literally only want one thing and it's fucking disgusting... @PentesterLab Black Friday Deal. 😜😜😜
16
3
143
@snyff
Louis Nyffenegger
4 years
9
21
143
@snyff
Louis Nyffenegger
2 years
Indian Postal Service == UDP You send packets but you're never sure they will arrive.
15
7
139
@snyff
Louis Nyffenegger
5 years
Don’t forget to check my soundcloud if you want help finding&exploiting bugs
0
8
136
@snyff
Louis Nyffenegger
3 years
Tweet media one
3
10
134
@snyff
Louis Nyffenegger
3 years
HTML goes <br/>...
5
11
133
@snyff
Louis Nyffenegger
5 months
🤪
Tweet media one
4
9
132
@snyff
Louis Nyffenegger
4 years
Creating content is hard... So if you have nothing nice to say don't say anything at all. (Especially if it's free content)
4
13
131