sshell's Avatar

sshell

@sshell.co

propane and propane accessories ai + security research ccdc red team

1,474
Followers
224
Following
61
Posts
01.05.2023
Joined
Posts Following

Latest posts by sshell @sshell.co

checking in to let everyone know that i am still using a computer

04.03.2026 03:11 πŸ‘ 7 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Preview
a group of cartoon characters are dancing together in a park . ALT: a group of cartoon characters are dancing together in a park .

The Sixth Annual Binary Golf Grand Prix #BGGP6 will start Friday 10/17!!!

@binary.golf Fall/Winter 2025

11.10.2025 19:09 πŸ‘ 17 πŸ” 11 πŸ’¬ 1 πŸ“Œ 0
Preview
QR Codes You Shouldn't Scan Number 3 may surprise you! I’m kidding of course, blatant web-based phishing attacks are boring. This blog isn’t about those. Most of these examples will probably surprise you in some way. This blog i...

Every year there’s some discourse around how safe/unsafe it is to scan QR codes at BlackHat and DefCon.
Last year, I set out to enumerate the scope, and did!
And then promptly forgot for a year.

QR codes you shouldn’t have scanned last year; this year.

remyhax.xyz/posts/no-sca...

07.08.2025 03:40 πŸ‘ 24 πŸ” 8 πŸ’¬ 0 πŸ“Œ 1

i am very excited to see all of my friends in las vegas, nevada

03.08.2025 19:45 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

hahaha, never thought about it but post should have come with a warning for anyone with service indicator-related ptsd.

also, being at nationals back-to-back years is impressive!

03.08.2025 18:44 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Red Teaming at National CCDC 2025 There's nothing quite like the feeling of playing Doom on someone's hypervisor and watching as they frantically try to figure out how to eject you from the system.

New blog post about all the fun I had red teaming at @NationalCCDC this year!

Covers some of the fun we had this year specifically relating to the web side of things, as well as some tips and resources for competitors & those interested in participating

www.sshell.co/red-teaming-...

27.07.2025 18:40 πŸ‘ 4 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

As of this morning I am unemployed. I am looking for work! I have a range of experience that can be valuable to the right team. A short list of relevant skills that I'd call out: reverse engineering & vuln research, DFIR, project management, infrastructure architecting, system administration.

01.07.2025 19:01 πŸ‘ 62 πŸ” 30 πŸ’¬ 2 πŸ“Œ 5
screenshot of an app saving a bookmark, but being stuck at 50%

screenshot of an app saving a bookmark, but being stuck at 50%

what do you mean β€œstuck at 50% done saving a bookmark?”

you completed one half of one api call?
i hate it here.

01.06.2025 18:29 πŸ‘ 4 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0
Flyer for the Phrack 40th anniversary edition CFP. It contains the text of the CFP at phrack.org, with additional text "CFP EXTEND!! Papers due June 15 2025" and "Phrack Since 1985"

Flyer for the Phrack 40th anniversary edition CFP. It contains the text of the CFP at phrack.org, with additional text "CFP EXTEND!! Papers due June 15 2025" and "Phrack Since 1985"

We heard you needed some more time, so we wanted to let you cook.

We decided to push the Phrack 72 CFP deadline back until June 15th.

Stay tuned for upcoming Phrack events.

Print this flyer out and give it to someone IRL!!

17.03.2025 13:58 πŸ‘ 112 πŸ” 52 πŸ’¬ 1 πŸ“Œ 5

Report government waste to DOGE:

- Every Electron app wastes hundreds of MB of disk space (and RAM) by bundling it's own Chrome browser. Make native UI great again!

- Every Go binary is too large. What are they hiding in there?

- Windows installs 500+ language packs. In the US we only use en-US!

18.02.2025 16:57 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

i wish there was a very serious medical drama where everything was normal EXCEPT every patient was played by the same actor, and it was never brought up or addressed in any way.

09.02.2025 00:35 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Got an MRI recently and @sshell.co immediately turned it into a banger

07.02.2025 23:12 πŸ‘ 52 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0

i tried openai operator and got jumpscared because i forgot how terrible it was to rawdog the internet without an ad-blocker.

24.01.2025 01:03 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Many YouTube videos lately are clickbait and stretch out a Wikipedia page into 30 minutes. Many videos are just questions with simple answers.

So I built tldw.tube: put in the URL and save your time!

(No hate on Veritasium, it just happened to work well for the screenshot)

11.01.2025 05:24 πŸ‘ 60 πŸ” 18 πŸ’¬ 9 πŸ“Œ 1

i am attendee at the local shmoo conference today. i can’t wait to talk about the latest developments in shmoo technology.

10.01.2025 20:12 πŸ‘ 4 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

Yup, same result set across all tests! A lot of it was deduplicating requests, removing feature bloat, smart tuning based on internet speeds, and being much more efficient with memory.

19.12.2024 20:13 πŸ‘ 3 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Note: this is as much an indictment of default settings on tools as it is of feature bloat. Even painstaking optimization of the original tool didn't approach these numbers.

19.12.2024 18:52 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
run times starting at 12 seconds, decreasing down to 2.2 seconds over 5 runs

run times starting at 12 seconds, decreasing down to 2.2 seconds over 5 runs

Took an existing open-source tool that 105 seconds to run on default settings out of the box.

Had Cursor rewrite it in a more performant language with only functionality I needed, and tuned for performance on my specific setup. Kept prompting it to further optimize and...

19.12.2024 18:51 πŸ‘ 4 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
screenshot of the CFP on phrack.org

screenshot of the CFP on phrack.org

We updated our CFP for Phrack 72! The deadline is now April 1st 2025. Check the site for specifics on how to contribute, as well as some inspiration! We also posted a link to purchase physical copies of Phrack 71, and a donation link too. Enjoy!

phrack.org

16.12.2024 22:56 πŸ‘ 116 πŸ” 59 πŸ’¬ 4 πŸ“Œ 4
Preview
a man talking on a phone with the words put that cookie down on the bottom Alt: a man talking on a phone with the words put that cookie down on the bottom

the best part about december is watching β€œjingle all the way” at least 7 times

14.12.2024 22:33 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Yo, new big thing: Shift.
AI seamlessly integrated into your HTTP proxy.

Use cases:
"Take this JS and build the JSON request body"
"Fill in these IDs from my notes - UserA"
"Create a match and replace rule to turn on this feature flag"
"Generate a wordlist with all HTTP Verbs"

06.12.2024 15:38 πŸ‘ 11 πŸ” 5 πŸ’¬ 1 πŸ“Œ 1

Me reverse engineering: Haha fuck yeah!!! Yes!!

Me engineering: Well this fucking sucks. What the fuck.

03.12.2024 18:59 πŸ‘ 481 πŸ” 98 πŸ’¬ 4 πŸ“Œ 4
Post image

truly believe pompeii/herculaneum graffiti should be required reading in school to really emphasize this point

02.12.2024 15:24 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Tool Use | Scale Leaderboards Explore ToolComp, Scale AI's SEAL leaderboard evaluating large language model agents on their ability to plan, reason, and orchestrate complex, dependent tool calls. Discover the latest results and in...

yeah, even the best models in general are pretty fragile with wording when it comes to tool use.

scale.com/leaderboard/...

30.11.2024 20:58 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

who are some of your favorite hackers and companies working with AI for offensive security right now?

30.11.2024 20:51 πŸ‘ 1 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

many such cases

30.11.2024 19:03 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

any agent framework can by just writing a function (or series of fuctions) for it to use as a tool.
it's really easy to do with a private custom GPT if the API is on the open internet too

30.11.2024 19:02 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

i’ve been playing around with common crawl URLs and the Internet Archive URLTeam project. definitely need to find a good way to categorize URLs as trash or useful at scale, LOTS and lots of noise

tracker.archiveteam.org:1338/status

28.11.2024 03:31 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I've released 'brainstorm': an alternative way to do web fuzzing combining my fav fuzzing tool 'ffuf' (from @joohoi.bsky.social )with local LLMs (via Ollama API) to generate smarter filename tests. It usually finds more endpoints with fewer requests. Added a IIS shortname support @irsdl.bsky.social

26.11.2024 08:57 πŸ‘ 39 πŸ” 9 πŸ’¬ 5 πŸ“Œ 0