Rebane
@rebane2001.bsky.social
1.4K followers 370 following 630 posts
🇪🇪🏳️‍⚧️ | Archivist | 9 CVEs in Chrome | CSS noob | MapartCraft | Horse | rebane2001#3716 | Lyra 🦊 she/her https://lyra.horse/ @[email protected]
Posts Media Videos Starter Packs
Pinned
rebane2001.bsky.social
bumping this because some people dismissed it as an april fools joke and others didn't realize it worked on mobile (android) too

it's a fun little clicker game i made that uses no javascript and runs all the game logic in css ^^

lyra.horse/css-clicker/
rebane2001.bsky.social
it's finally time...

this is css clicker, a fully-featured incremental game where your goal is to design your own personal website and get as many views on it as possible

the fun part? it's a pure-css game, meaning it runs no javascript or server-side code.

have fun!

lyra.horse/css-clicker/
CSS Clicker
a pure-CSS idle game where you build your own website
lyra.horse
rebane2001.bsky.social
the whole 3kliks thing is fucking me up so much cuz like his content was so meaningful and inspirational to me, and i think he's just too stubborn/defensive and sees putting out a statement as giving in to demands or picking a side 💔
rebane2001.bsky.social
normal people favorite band: imagine dragons
computer people favorite band: imagine heap
rebane2001.bsky.social
okay so the last two pics was me doing a bit, but today i found this in my hair and now i'm actually scared....
paper sticker that says QC Pass 6 in red text
rebane2001.bsky.social
okay so the last two pics was me doing a bit, but today i found this in my hair and now i'm actually scared....
paper sticker that says QC Pass 6 in red text
rebane2001.bsky.social
another unintended jorian solve for a chall of mine 🥹
jorianwoltjer.com
Follow your rabbit holes is the takeaway from my latest CTF writeup.
I found several interesting techniques that can help tricky situations, such as using the Connection Pool to make Client-Side Race Conditions easier!

Read the whole thing on my blog:
jorianwoltjer.com/blog/p/ctf/o...
openECSC 2025 - kittychat-secure | Jorian Woltjer
Overcomplicating a hard client-side web challenge involving complex CSP script gadgets. Exploit Math.random() predictability, and learn how to use the Connection Pool to make Race Conditions easier.
jorianwoltjer.com
Reposted by Rebane
jorianwoltjer.com
Follow your rabbit holes is the takeaway from my latest CTF writeup.
I found several interesting techniques that can help tricky situations, such as using the Connection Pool to make Client-Side Race Conditions easier!

Read the whole thing on my blog:
jorianwoltjer.com/blog/p/ctf/o...
openECSC 2025 - kittychat-secure | Jorian Woltjer
Overcomplicating a hard client-side web challenge involving complex CSP script gadgets. Exploit Math.random() predictability, and learn how to use the Connection Pool to make Race Conditions easier.
jorianwoltjer.com
rebane2001.bsky.social
was wearing my collar at the airport and a woman came up to me and said she was from seattle (pic unrelated)
rebane2001.bsky.social
what does this mean chat
my arm with a holographic 256MB sticker on it
rebane2001.bsky.social
i think my tweets might be the reason why proton increased their bounties tbh
rebane2001.bsky.social
nooooo!! i have the worst luck with google vrp

last year i submitted my google drive chain bug right before they increased the bounties by 5x

and this year i submitted my novel svg clickjacking attack technique right before they announced a bonus for novelty!!
Google Bug Hunters

Rewarding Innovation: The New Novelty Bonus

Beyond report quality, we want to explicitly recognize truly unique or innovative research. To this end, we're introducing a Novelty Bonus, ranging from +$1,000 to +$5,000. This discretionary bonus will be awarded for reports that cause our security teams to think differently about a problem or uncover entirely new vulnerability classes.
rebane2001.bsky.social
huh, seems like discord had a breach or something of its support tickets?
(email from Discord)

Hello,

We’re reaching out to you because of a recent security incident on September 20 involving your personal data. Specifically, an unauthorized party gained limited access to a third-party customer service system used by Discord. We have confirmed that some of your personal data associated with your contact with our Customer Support or Trust & Safety teams was exposed in this incident.
This may include:

Your name, Discord username, email and other contact details if you provided them
Limited payment information, including payment type, last four digits of your credit card, and purchase history if associated with your account
IP addresses
Messages and attachments sent to our Customer Support or Trust & Safety agents
The incident did not include:

Full credit card numbers or CCV codes
Your physical address
Your messages or activity on Discord beyond what you may have discussed with customer support or trust and safety agents
Your Discord password or authentication data
The ticket numbers impacted for your account were: [redacted]. You can use these ticket numbers to search for the relevant exchanges in your email account.

As soon as we became aware of this incident, we followed our incident response procedures and took immediate steps to address the situation, including revoking the customer support provider’s third-party access to our ticketing system, launching an internal investigation, and engaging a leading forensics IT firm to support our investigation and remediation efforts. We’ve also notified law enforcement of the incident.
rebane2001.bsky.social
btw, if you like cool web challs, now's your last chance to play my `kittychat-secure` chall at openecsc 2025!

it's still running until the end of sunday

have fun!!

openec.sc
kittychat-secure
3 Solves

LEET

BY	rebane2001
TAGS	web, xssbot
POINTS	499
we fixed our vulnerabilities using csp technology!
rebane2001.bsky.social
i read blog posts because 5 months ago i opened a tab and now it's time to finally close it
rebane2001.bsky.social
how to make slow + reverb music:

1. import mp3 into after effects
2. create a new composition 1920x1080@60fps
3. put the mp3 in the comp
4. press play
5. ??? (NOT realtime)
6. profit
rebane2001.bsky.social
fuck having an unregistered copy, i'm rolling up w this
windows desktop, Sublime Text window with (LICENSE UPGRADE REQUIRED) on the title bar
rebane2001.bsky.social
it's for a travel-themed ctf ^_^
rebane2001.bsky.social
making charts with funky z-indexes to keep people on their toes
Reposted by Rebane
rebane2001.bsky.social
the overengineered solution would be to already start the update while asking for the link
Reposted by Rebane
makaryo.bsky.social
Hatsune Miku and Her Pony
#MLP #mylittlepony