Dominique Righetto's Avatar

Dominique Righetto

@righettod.eu

๐Ÿ‘จโ€๐Ÿ’ป AppSec enthusiast | ๐Ÿถ Addicted to Shetland Sheepdogs | ๐ŸŒ Open Source/AppSec/OWASP junkie | ๐Ÿ OWASP Secure Headers Project Leader. ๐Ÿšฉ Opinions mentioned are mine.

1,240
Followers
139
Following
164
Posts
13.11.2024
Joined
Posts Following

Latest posts by Dominique Righetto @righettod.eu

CVE-2026-1731 Metasploit module demo

CVE-2026-1731 Metasploit module demo

My first @metasploit-r7.bsky.social module is live! You can now exploit CVE-2026-1731 (BeyondTrust command injection) with the latest version ๐Ÿ˜Ž

04.03.2026 09:36 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Browser-Based Port Scanning in the Age of LNA

๐—ฅ๐—ฒ๐˜€๐—ฒ๐—ฎ๐—ฟ๐—ฐ๐—ต ๐—ช๐—ผ๐—ฟ๐˜๐—ต ๐—ฅ๐—ฒ๐—ฎ๐—ฑ๐—ถ๐—ป๐—ด - ๐—ช๐—ฒ๐—ฒ๐—ธ ๐Ÿต, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ
Mostly AI...

๐Ÿ’ป ๐—•๐—ฟ๐—ผ๐˜„๐˜€๐—ฒ๐—ฟ-๐—•๐—ฎ๐˜€๐—ฒ๐—ฑ ๐—ฃ๐—ผ๐—ฟ๐˜ ๐—ฆ๐—ฐ๐—ฎ๐—ป๐—ป๐—ถ๐—ป๐—ด ๐—ถ๐—ป ๐˜๐—ต๐—ฒ ๐—”๐—ด๐—ฒ ๐—ผ๐—ณ ๐—Ÿ๐—ก๐—”
Leveraging Local Network Access to create a port scanner! wiki.notveg.ninja/tools/lna-po....

01.03.2026 23:58 ๐Ÿ‘ 2 ๐Ÿ” 3 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
What you don't see - PentesterLab's Blog More and more, with the progress of coding agents, people are rewriting software.And honestly, it looks easy. You write a good ...

I wrote about what happens when you rewrite mature software with agents. You rebuild the features. You don't rebuild the scars.

vinext: one engineer, one week, $1,100 in tokens. Then plenty of vulnerabilities found within days.

pentesterlab.com/blog/what-yo...

02.03.2026 00:04 ๐Ÿ‘ 4 ๐Ÿ” 5 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
vue de zensical

vue de zensical

Zensical : un gรฉnรฉrateur de sites statiques qui permet de transformer rapidement une documentation Markdown en un site professionnel, personnalisable et multilingue. (Dรฉcouvert via Mat V. )

๐Ÿ‘‰ Le projet : github.com/zensical/...
๐Ÿ‘‰ En savoir plus : https://zensical.org/

28.02.2026 18:30 ๐Ÿ‘ 35 ๐Ÿ” 11 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 1
Preview
PentesterLab: Learn with our JavaScript Code Review The JavaScript Code Review Badge is our badge dedicated to security code review in JavaScript. It covers the discovery of weaknesses and vulnerabilities using source code review.

6 new code review labs just dropped ๐Ÿš€
+3 for JavaScript Code Review
+3 for Python Code Review

JS: pentesterlab.com/badges/javas...

Python: pentesterlab.com/badges/pytho...

28.02.2026 04:03 ๐Ÿ‘ 5 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Overview of one repo

Overview of one repo

๐Ÿง‘โ€๐ŸŽ“ As part of my homework on AI from an AppSec perspective, I have decided to gather all my content on GitHub so that I can share it in case anyone is interested.

๐Ÿ“– Cheat sheet, methodology and tools: github.com/righettod/to...

๐Ÿ”ฌ R&D: github.com/righettod/po...

#appsec #appsecurity #ai

26.02.2026 07:50 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

๐Ÿ”ฅ OWASP CRS is evolving! Introducing #CRSLang โ€” a new YAML-based rule language replacing Seclang. Cleaner syntax, multi-engine support, bidirectional translation, and a lower barrier for new contributors.
Check it out ๐Ÿ‘‰ coreruleset.org/2026...
#WAF #AppSec #OWASP #ModSecurity

18.02.2026 01:43 ๐Ÿ‘ 4 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1

Erratum, it's opened tonight February the 15th ๐Ÿ˜‚
--------------
Erratum, c'est ouvert ce soir le 15 fรฉvrier ๐Ÿ˜‚

15.02.2026 12:15 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Video thumbnail

Voxxed Days Luxembourg's CFP will be opened from tonight February the 17th at 11:30 PM to March the 29th at midnight.Luxembourg
----------------
L'appel aux orateurs de Voxxed Days sera ouvert ร  partir de ce soir, le 17 fรฉvrier ร  23h30 jusqu'au 29 mars ร  minuit.
---
voxxedlu2026.cfp.dev

15.02.2026 12:04 ๐Ÿ‘ 6 ๐Ÿ” 8 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0
Preview
Release Release v2.6.0 ยท OWASP/cornucopia What's Changed Bump svelte from 5.49.2 to 5.50.0 in /cornucopia.owasp.org by @dependabot[bot] in #2188 Bump postgrex from 0.21.1 to 0.22.0 in /copi.owasp.org by @dependabot[bot] in #2186 Bump wait...

OWASP Cornucopia just release v2.6.0

github.com/OWASP/cornuc...

The new release comes with support for continuing the game session even if players can not continue the game when playing on copi.owasp.org

#owasp #appsec #security #cornucopia

10.02.2026 20:39 ๐Ÿ‘ 7 ๐Ÿ” 4 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

Added a small feature to cspbypass.com to warn the user if unsafe-inline is detected, in which case you typically donโ€™t need to waste time hunting for 3rd-party whitelisted CSP bypasses and go straight to inline scripts / event handlers.

07.02.2026 18:50 ๐Ÿ‘ 8 ๐Ÿ” 5 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Sqldef : un outil CLI qui permet le "diffing" de deux schรฉmas SQL et de gรฉnรฉrer automatiquement les instructions de migration nรฉcessaires.

๐Ÿ‘‰ sqldef.github.io/

06.02.2026 16:30 ๐Ÿ‘ 17 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

MORE LABS IN OUR JAVASCRIPT CODE REVIEW BADGE:

pentesterlab.com/badges/javas...

06.02.2026 00:53 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Thank you very much for this amazing free software ๐Ÿ™

05.02.2026 11:28 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Important Clarification: Notepad++ Security Incident | Notepad++

Important Clarification: Notepad++ Security Incident (Indicators of Compromise provided by our former hosting provider is included):
notepad-plus-plus.org/news/clarifi...

05.02.2026 03:28 ๐Ÿ‘ 8 ๐Ÿ” 3 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Master Web Hacking and Security Code Review! Master advanced penetration testing and deep security code review through real-world CVEs, detailed vulnerability analysis, and expert-led code reviews. Ideal for professionals seeking expert-level un...

๐Ÿ“– References used:

- pentesterlab.com
- www.regular-expressions.info

02.02.2026 10:28 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Execution of the POC performed.

Execution of the POC performed.

๐Ÿง‘โ€๐ŸŽ“ Learning of the day for me thanks to @pentesterlab.com and Claude.

๐Ÿ”ฌ For the regular expression "[A-z]":

In a character class [X-Y], it matches all characters with ASCII codes from X to Y inclusive. So [A-z] means all ASCII characters from 65 (A) to 122 (z).

#appsec #appsecurity

02.02.2026 10:28 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Notepad++ Hijacked by State-Sponsored Hackers | Notepad++

Notepad++ Hijacked by State-Sponsored Hackers
Security Update - Resolution of Notepad++ Update Server Compromise
notepad-plus-plus.org/news/hijacke...

02.02.2026 00:44 ๐Ÿ‘ 53 ๐Ÿ” 29 ๐Ÿ’ฌ 11 ๐Ÿ“Œ 4
Preview
GitHub - jub0bs/cors: perhaps the best CORS middleware library for Go perhaps the best CORS middleware library for Go. Contribute to jub0bs/cors development by creating an account on GitHub.

๐ŸŽ‰ I've just released v0.11.0 of jub0bs/cors, my CORS middleware library for Go!

Bar any surprises, this will be the last minor release before v1.

github.com/jub0bs/cors

31.01.2026 15:31 ๐Ÿ‘ 17 ๐Ÿ” 3 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 1
Preview
โš ๏ธ OWASP websites/projects/chapters migration. ยท OWASP www-project-secure-headers ยท Discussion #273 Hi, We (@riramar and myself) created this discussion to share/track with the OSHP community, in a open way, an important coming changes in the OSHP. The context ๐Ÿ“ The OWASP foundation has decided t...

๐Ÿ“ก OWASP Secure Headers Project: The OWASP Foundation has decided to migrate its content to a new CMS. As a result, OSHP content is frozen for the duration of the migration. You can find more information and explanations in the discussion below.

github.com/OWASP/www-pr...

#owasp_shp

24.01.2026 16:48 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Love web & AI security research? Want to do it full time on-site with myself, Gareth Heyes & Zak Fedotkin? Join the PortSwigger Research team - we're hiring!

apply.workable.com/portswigger/...

23.01.2026 10:36 ๐Ÿ‘ 8 ๐Ÿ” 8 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
CVE-2026-23993: JWT authentication bypass in HarbourJwt via โ€œunknown algโ€ I didn't know Harbour even existed as a language when I found this bug. The fun part is that I also ...

๐Ÿ”ฅ CVE-2026-23993: HarbourJwt JWT auth bypass via unknown alg.

Not just alg=none: unsupported alg => empty signature, so forged token header.payload. passes.

Write-up + fix: pentesterlab.com/blog/cve-202...

21.01.2026 22:12 ๐Ÿ‘ 6 ๐Ÿ” 6 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1

๐Ÿ“– References used:

- developer.mozilla.org/en-US/docs/W...
- pentesterlab.com/exercises/sv...
- portswigger.net/web-security...
- www.fortinet.com/blog/threat-...

21.01.2026 07:25 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
POC performed.

POC performed.

๐Ÿง‘โ€๐ŸŽ“ Learning of the day for me: I discovered that browsers (at least Chromium) display an SVG image even if the specified content type is set to XML. The contained JS script is also executed.

#appsec #appsecurity

21.01.2026 07:25 ๐Ÿ‘ 6 ๐Ÿ” 2 ๐Ÿ’ฌ 3 ๐Ÿ“Œ 0
Overview of the page.

Overview of the page.

๐Ÿ“ก OWASP Secure Headers Project: We have added information and examples regarding the Trusted Types feature of the Content-Security-Policy header.

๐Ÿ“– owasp.org/www-project-...

#appsec #appsecurity #owasp_shp

12.01.2026 05:59 ๐Ÿ‘ 0 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
GitHub - C4illin/ConvertX: ๐Ÿ’พ Self-hosted online file converter. Supports 1000+ formats โš™๏ธ ๐Ÿ’พ Self-hosted online file converter. Supports 1000+ formats โš™๏ธ - C4illin/ConvertX

๐Ÿ”ฅ Hot Repo๏ผ ๐Ÿ”ฅ (100+ new stars)

๐Ÿ“ฆ C4illin / ConvertX
โญ 13,699 (+159)
๐Ÿ—’ TypeScript

๐Ÿ’พ Self-hosted online file converter. Supports 1000+ formats โš™๏ธ

09.01.2026 12:02 ๐Ÿ‘ 2 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
logo

logo

docker-android : une image Docker minimaliste permettant de faire tourner un รฉmulateur Android avec KVM.

๐Ÿ‘‰ github.com/HQarroum/...

03.01.2026 18:30 ๐Ÿ‘ 26 ๐Ÿ” 4 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
GitHub - BurntSushi/ripgrep: ripgrep recursively searches directories for a regex pattern while respecting your gitignore ripgrep recursively searches directories for a regex pattern while respecting your gitignore - BurntSushi/ripgrep

Best news I've discovered today is that ripgrep is also available for Windows and you can install it with winget (winget install ripgrep). ripgrep is like the grep utility in Linux, but a bit faster, it also accepts grep's params github.com/burntsushi/r...

18.12.2025 18:27 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Video thumbnail

๐Ÿ“š Les guides de lโ€™ANSSI sont sur #MesServicesCyber !

๐Ÿ–ฅ๏ธ Alors que le site de lโ€™ANSSI รฉvolue, MesServicesCyber se transforme pour vous simplifier lโ€™accรจs aux conseils et recommandations de lโ€™ANSSI, et de ses partenaires.

Rendez-vous sur :
๐Ÿ”— messervices.cyber.gouv.fr/catalogue/?m...

17.12.2025 14:11 ๐Ÿ‘ 7 ๐Ÿ” 5 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
GitHub - 0xk1h0/ChatGPT_DAN: ChatGPT DAN, Jailbreaks prompt ChatGPT DAN, Jailbreaks prompt. Contribute to 0xk1h0/ChatGPT_DAN development by creating an account on GitHub.

๐Ÿ“ฆ 0xk1h0 / ChatGPT_DAN
โญ 10,302 (+47)

ChatGPT DAN, Jailbreaks prompt

17.12.2025 16:02 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0