Make a deal with leonjza :verified:
🔒 Paid proposals held safely in escrow — released only when the work's approved.
Known for
28 views
Two blog posts just dropped - one with the details on the bloatware pwning shenanigans I was up to earlier in the year, and another on pipetap, a new Windows named pipe proxy/tool.
https://sensepost.com/blog/2025/pwning-asus-driverhub-msi-center-acer-control-centre-and-razer-synapse-4/
https://sense
26 views
I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :)
Of course, I'm aware alternatives exist (and
15 views
Quick lunch time side quest building a simple lab to play with the inetutils-telnetd authentication bypass as disclosed on oss-sec ₁.
https://github.com/leonjza/inetutils-telnetd-auth-bypass
₁ https://seclists.org/oss-sec/2026/q1/89
11 views
Had a case this week of a fairly secure deployment of BeyondTrust, but vulnerable to CVE-2026-1731. With basically zero egress, I implemented a timing oracle POC instead. Takes about 20 minutes to get the ls command output in this demo, but hey, it works! :D
📊 Post engagement
🔥 Top post: Two blog posts just dropped - one with the details on the bloatw · 28 likes + reposts
📊 Activity & format
Recent posts
View on Mastodon ↗
🔥 Top post
Two blog posts just dropped - one with the details on the bloatware pwning shenanigans I was up to earlier in the year, and another on pipetap, a new Windows named pipe proxy/tool.
https://sensepost.com/blog/2025/pwning-asus-driverhub-msi-center-acer-control-centre-and-razer-syn…
Just pushed some slides and labs polish for next weeks @1ns0mn1h4ck before my flight. The whole repo (which includes the training platform, labs, and slides) is quite... diverse :D
▶
A clip introducing our new Binary Instrumentation with Frida course, aimed at getting you more comfortable with the @fridadotre ecosystem - coming to a conference near you!
You've used Frida-based tools like objection before, but now you w…
▶
Had a case this week of a fairly secure deployment of BeyondTrust, but vulnerable to CVE-2026-1731. With basically zero egress, I implemented a timing oracle POC instead. Takes about 20 minutes to get the ls command output in this demo, bu…
▶
Noone asked for this, but I'm trying to get more comfortable with qemu as a whole which has resulted in this overly fancy Qemu Machine Protocol (QMP) socket client, complete with dynamic schema parsing, event subscriptions and tab completi…
Thank you for applying the patch carefully.
Quick lunch time side quest building a simple lab to play with the inetutils-telnetd authentication bypass as disclosed on oss-sec ₁.
https://github.com/leonjza/inetutils-telnetd-auth-bypass
₁ https://seclists.org/oss-sec/2026/q1/89
It's a nice feeling wrapping up some research! :D
It's... been a while since the last objection release got tagged. We finally landed a 1.12 release today which also means pypi is up to date again, and for the foreseeable future! Work never really stopped, and plenty of bug fixes are incl…
Romhack was absolute 🔥! The conference, the community, the vibe - all of it was just something else. Special mention to @merlos and the @cybersaiyan team for making the speaking experience excellent too. 🙃
I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly comp…
Using @radareorg to dynamically get the virtual address of a Golang embed.FS structure to extract some sus embed's with go-embed-extractor¹ in this "dodgy-go-bin" 🔥
¹https://github.com/BreakOnCrash/go-embed-extractor
🐘 Community & instance
💡 Facts
🕵️ Fake follower check
Estimated- Est. 99% real, active audience · Low fake-follower risk.
- Strong engagement (~2.9% of followers engage each post) — an active, real audience.
- Verified account.
- Established account (8+ years old).
Heuristic estimate from engagement, follower ratios, account age & growth — a screening signal, not a guarantee.
About
📸 Gallery
🔀 Audience overlap
EstimatedEstimated shared audience with similar creators — useful for avoiding overlap (or doubling down) when planning a campaign.
More like this
Find more →✉ Message leonjza :verified:
Reaching out to influencers is a Pro feature. Upgrade to message any influencer directly — perfect for brands and agencies booking sponsorships.
- ✓ Message any influencer from their listing
- ✓ The influencer gets notified by email
- ✓ Manage every conversation in one inbox
Already Pro? Log in.
🎤 Event / appearance with leonjza :verified:
Booking an event / appearance is a Pro feature. Upgrade to book leonjza :verified: for an in-person or virtual appearance — payment held safely in escrow until the event is done.
- ✓ Book them for events, livestreams, panels & more
- ✓ leonjza :verified: gets notified by email
- ✓ Fee held in escrow, released after the appearance
Already Pro? Log in.
You're out of free requests this month
Free accounts get 5 per month. Go Pro for unlimited sponsor pitches, collab requests & sponsorship deals — plus featured placement, the Verified badge, free withdrawals and more.
Upgrade to Pro — $9.95/mo →Your free limit resets on the 1st of next month.