renniepak's Avatar

renniepak

@renniepak.nl

Self-XSS connoisseur. Elite Hacker. MVH H11337UPBash. One-Percent Man. Creator of CSPBypass.com. (he/him)

2,150
Followers
206
Following
165
Posts
06.08.2023
Joined
Posts Following

Latest posts by renniepak @renniepak.nl

What windows or MacOs files reliably contain the username of the currently logged in user WITHOUT that username being part of the file path?

06.03.2026 11:24 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

The best time to quit bug bounty was 20 months ago. The second best time is now.

12.02.2026 18:43 πŸ‘ 6 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

Added a small feature to cspbypass.com to warn the user if unsafe-inline is detected, in which case you typically don’t need to waste time hunting for 3rd-party whitelisted CSP bypasses and go straight to inline scripts / event handlers.

07.02.2026 18:50 πŸ‘ 8 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Bypass CSP in a single click using my new Custom Action, powered by @renniepak.nl's excellent CSP bypass project.

16.12.2025 15:31 πŸ‘ 12 πŸ” 6 πŸ’¬ 1 πŸ“Œ 0

It depends. Might want to checkout @intigriti.com latest blog.

05.12.2025 11:18 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Thanks for mentioning our site cspbypass.com

01.12.2025 17:28 πŸ‘ 4 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

we at cspbypass.com recommend cspbypass.com

29.11.2025 17:46 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I was naive and deleted it myself. Someone else claimed it.

27.10.2025 18:33 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Video thumbnail

Found an XSS but got blocked by the CSP?

https://cspbypass.com has a compiled list of ways to bypass the Content-Security Policy. Check out the video below πŸ‘‡

21.10.2025 09:16 πŸ‘ 7 πŸ” 6 πŸ’¬ 1 πŸ“Œ 0
https://www.amazon.com/dp/B0BRD9B3GS

https://www.amazon.com/dp/B0BRD9B3GS

In a shameless effort to promote my book. I've crafted some very special vectors for you. If you like them please purchase my book to read more.

www.amazon.com/dp/B0BRD9B3GS

26.09.2025 11:20 πŸ‘ 15 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0

I was unaware of coding music to begin with. So I guess I'll check out sonicpi as well. :)

06.09.2025 15:33 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Strudel REPL Strudel is a music live coding environment for the browser, porting the TidalCycles pattern language to JavaScript.

Been playing around with strudel.cc recently. It is pretty awesome!

strudel.cc#Ly9Td2VldCBE...

06.09.2025 14:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Social Engineer: YOU are Easier to Hack than your Computer
Social Engineer: YOU are Easier to Hack than your Computer YouTube video by Scammer Payback

Great interview with @racheltobac.bsky.social shining a light in a lot of important topics, like what are likely attack vectors, impact of #AI on #security, #ethics, affecting social interactions and #privacy .

"Be politely paranoid." πŸ‘

www.youtube.com/watch?v=xEdZ...

02.09.2025 11:15 πŸ‘ 12 πŸ” 6 πŸ’¬ 3 πŸ“Œ 0

Coded some PHP today without using ChatGPT, like a mad man.

27.08.2025 16:13 πŸ‘ 6 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Time to reveal what I was doing withΒ @teknogeek.ioΒ back in '19.

All the hard work and sleepless nights have paid off!

26.08.2025 09:02 πŸ‘ 13 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
CSP Bypass Search A tool designed to help ethical hackers bypass restrictive Content Security Policies

Just finished a major UI overhaul of CSPBypass.com and would love your feedback. Excited to welcome ProjectDiscovery as our first sponsor. Huge thanks to their team for supporting the project and recognizing its value to the community.

25.08.2025 12:31 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
CSP Bypass Search A tool designed to help ethical hackers bypass restrictive Content Security Policies

I enabled sponsorships on Github for cspbypass.com.

The main goal is to cover hosting fees etc. So if you want to support my work, I would highly appreciate it if you could become a sponsor.

github.com/sponsors/ren...

Thanks!

24.08.2025 17:41 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Forgot how to bug bounty.

21.08.2025 12:31 πŸ‘ 2 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
NVD - CVE-2025-53836

LOL. almost 3 years after reporting it and it being fixed, I got assigned a CVE for a vuln I found πŸ™ƒ

nvd.nist.gov/vuln/detail/...

17.07.2025 07:30 πŸ‘ 6 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

That's awesome! Congrats!

26.06.2025 17:25 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Video thumbnail

Made hacking rooms work in real time. This demo connects three browsers with real time editing on. From Chrome I edit some HTML. This gets sent over websockets to the other browsers which call postMessage to a blob with a sandboxed iframe.

20.06.2025 11:55 πŸ‘ 5 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Post image

😍

19.06.2025 14:30 πŸ‘ 8 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I have no clue any more. I have stored XSS on a specific subdomain, I have another subdomain that reflects all cookies (also http only), I can register my own OAuth clients somewhere else. But uh, I dunno. Stuff.

14.06.2025 09:46 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I feel like I have all the pieces to a ATO chain. I just have no idea what the chain would be...

12.06.2025 11:51 πŸ‘ 4 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I thought he would. That dude is awesome.

11.06.2025 14:26 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I think @mrtuxracer.bsky.social already does this kind of stuff as part of his bug bounty. Not cloud though.

10.06.2025 09:14 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

No, the conference took place quite a while ago. This is my website, and the slides will remain available here.

10.06.2025 07:16 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
<object data=# codebase=javascript:alert(document.domain)//>
<embed src=# codebase=javascript:alert(document.domain)//>
<object data="#
alert(1)" codebase=javascript://>
<embed src="#!
alert(1)" codebase=javascript:>

<object data=# codebase=javascript:alert(document.domain)//> <embed src=# codebase=javascript:alert(document.domain)//> <object data="# alert(1)" codebase=javascript://> <embed src="#! alert(1)" codebase=javascript:>

Epic Firefox XSS vectors by Masato Kinugawa. Now available on our XSS cheat sheet including variants found by me.

Link to vectorsπŸ‘‡
portswigger.net/web-security...

09.06.2025 13:26 πŸ‘ 11 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0

πŸ³οΈβ€πŸŒˆ

07.06.2025 10:51 πŸ‘ 4 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

What are the benefits?

06.06.2025 11:09 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0