Nicolas Grรฉgoire's Avatar

Nicolas Grรฉgoire

@agarri.fr

Web hacker ๐Ÿ˜ˆ Burp Suite Pro trainer ๐Ÿ‘จโ€๐Ÿซ Maintainer of @mastering-burp.agarri.fr ๐Ÿ› ๏ธ

4,451
Followers
617
Following
1,019
Posts
03.05.2023
Joined
Posts Following

Latest posts by Nicolas Grรฉgoire @agarri.fr

RomHack Training

Come to Roma ๐Ÿ‡ฎ๐Ÿ‡น ๏ฟผin September and attend the only in-person public training session I'll give in 2026! ๐Ÿ‘จโ€๐Ÿซ

And if you like camping with other hackers (as I do), stay over the weekend for the 3-day long RomHack Camp ๏ฟผ๐Ÿ•๏ธ

romhack.io/training/

04.03.2026 14:05 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Last week, I had the opportunity to attend the 4-day Mastering Burp Suite Pro training by ๐Ÿ› ๏ธ Nicolas Gregoire, and it exceeded my expectations by far.

This wasnโ€™t just another slide-driven course. Nicolas took the time to answer every question in depth and provided plenty of hands-on labs, allowing us to immediately apply what had just been explained.

Even though Iโ€™ve been working with Burp for nearly five years, I still picked up a surprising number of new techniques and practical tricks, including ways to streamline otherwise time-consuming workflows such as managing CSRF tokens both with and without session handling rules.

What I especially appreciated were the little side explorations (driven by our requests) into methodologies for leveraging features and extensions to remain stealthy or bypass WAFs. This is something thatโ€™s particularly relevant (and often underestimated) when exploiting external or internal web applications during advanced Red Team engagements.

Iโ€™m genuinely looking forward to applying this newly gained knowledge in upcoming projects, and I can wholeheartedly recommend this training to any (web) pentester who wants to level up their Burp skills.

Big thanks to Nicolas for an excellent and highly practical course!

Last week, I had the opportunity to attend the 4-day Mastering Burp Suite Pro training by ๐Ÿ› ๏ธ Nicolas Gregoire, and it exceeded my expectations by far. This wasnโ€™t just another slide-driven course. Nicolas took the time to answer every question in depth and provided plenty of hands-on labs, allowing us to immediately apply what had just been explained. Even though Iโ€™ve been working with Burp for nearly five years, I still picked up a surprising number of new techniques and practical tricks, including ways to streamline otherwise time-consuming workflows such as managing CSRF tokens both with and without session handling rules. What I especially appreciated were the little side explorations (driven by our requests) into methodologies for leveraging features and extensions to remain stealthy or bypass WAFs. This is something thatโ€™s particularly relevant (and often underestimated) when exploiting external or internal web applications during advanced Red Team engagements. Iโ€™m genuinely looking forward to applying this newly gained knowledge in upcoming projects, and I can wholeheartedly recommend this training to any (web) pentester who wants to level up their Burp skills. Big thanks to Nicolas for an excellent and highly practical course!

Another highly satisfied trainee ๐Ÿ˜Ž ๐Ÿ‘จโ€๐Ÿซ

If you want to take the online version of my Burp Suite course, there are two opportunities really soon (March in French, April in English) hackademy.agarri.fr/sessions

And if you want to indulge your company a private session (like this company did), ping me!

10.02.2026 08:46 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Agarri Training

Spring is just around the corner, and that's when I offer online training courses on Burp Suite Pro ๐Ÿ‘จโ€๐Ÿซ Two sessions are planned (in English and French), and there are still a few spots left in each.

Contact me to get an early-bird discount code! ๐Ÿ’ฐ

31.01.2026 12:31 ๐Ÿ‘ 6 ๐Ÿ” 5 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Agarri Training

Spring is just around the corner, and that's when I offer online training courses on Burp Suite Pro ๐Ÿ‘จโ€๐Ÿซ Two sessions are planned (in English and French), and there are still a few spots left in each.

Contact me to get an early-bird discount code! ๐Ÿ’ฐ

31.01.2026 12:31 ๐Ÿ‘ 6 ๐Ÿ” 5 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Thanks to everyone who nominated & voted in the top ten! The panel of @irsdl.bsky.social , @agarri.fr , @liveoverflow.bsky.social and myself are hard at work reviewing the 15 finalists... we're hoping to announce the winners next week!

29.01.2026 16:04 ๐Ÿ‘ 8 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

In case you didn't vote yet (2 days left!), let me tell you that your participation is critical ๐Ÿ—ณ๏ธ

Indeed, the panel (that I'm part of) will only process the top X results and it may contain some sh*tty entries (because of ballot stuffing ๐Ÿฅด)

So please do your part! ๐Ÿ™

20.01.2026 10:24 ๐Ÿ‘ 4 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Top 10 web hacking techniques of 2025 Welcome to the community vote for the Top 10 Web Hacking Techniques of 2025.

It's time to vote for your favorite Web Hacking Techniques of 2025 ๐Ÿ—ณ๏ธ

portswigger.net/polls/top-10...

16.01.2026 13:01 ๐Ÿ‘ 6 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Preview
Agarri Training

The 2026 online public sessions of my "Mastering Burp Suite Pro" course have been published ๐Ÿ“…

- March 24th to 27th, in French ๐Ÿ‡ซ๐Ÿ‡ท
- April 14th to 17th, in English ๐Ÿ‡ฌ๐Ÿ‡ง

hackademy.agarri.fr/2026

PS: feel free to ping me if you'd like to temporarily block a seat or are looking for a 10% coupon ๐ŸŽ

24.11.2025 10:14 ๐Ÿ‘ 8 ๐Ÿ” 7 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1
Preview
Hacking washing machines Almost everyone has a household appliance at home, whether it's a washing machine, dishwasher, or dryer. Despite their ubiquity, little i...

Hacking washing machines

media.ccc.de/v/39c3-hacki...

13.01.2026 11:36 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
To sign or not to sign: Practical vulnerabilities in GPG & friends Might contain zerodays. https://gpg.fail/ From secure communications to software updates: PGP implementations such as *GnuPG* ubiquitous...

To sign or not to sign: Practical vulnerabilities in GPG & friends

media.ccc.de/v/39c3-to-si...

13.01.2026 11:36 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

I'm slowly going though the talks from the CCC congress. Here's my favorites so far... โคต๏ธ

13.01.2026 11:35 ๐Ÿ‘ 1 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Backing up Spotify We backed up Spotify (metadata and music files). Itโ€™s distributed in bulk torrents (~300TB). Itโ€™s the worldโ€™s first โ€œpreservation archiveโ€ for music which is fully open (meaning it can easily be mirro...

Annaโ€™s Archive is an incredible project aimed at preserving humanityโ€™s knowledge and culture

Their latest exploit is a near-full backup of Spotify. It includes 86 million songs, representing around 99.6% of listens ๐ŸŽถ

annas-archive.org/blog/backing...

31.12.2025 15:06 ๐Ÿ‘ 13 ๐Ÿ” 6 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Backing up Spotify We backed up Spotify (metadata and music files). Itโ€™s distributed in bulk torrents (~300TB). Itโ€™s the worldโ€™s first โ€œpreservation archiveโ€ for music which is fully open (meaning it can easily be mirro...

Annaโ€™s Archive is an incredible project aimed at preserving humanityโ€™s knowledge and culture

Their latest exploit is a near-full backup of Spotify. It includes 86 million songs, representing around 99.6% of listens ๐ŸŽถ

annas-archive.org/blog/backing...

31.12.2025 15:06 ๐Ÿ‘ 13 ๐Ÿ” 6 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
OWASP Top 10:2025 OWASP Top 10:2025

Looks like the final OWASP Top 10 (2025) has been published: owasp.org/Top10/2025/.

Based on commits, looks like this happened 5 days ago.

29.12.2025 12:24 ๐Ÿ‘ 5 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Publishing your work increases your luck In 12 months, @aarondfrancis changed his life by bypassing fear and embracing risk. Now, heโ€™s working his dream job @tuple. Get his full story on The ReadME Project:

Good read github.com/readme/guide...

27.12.2025 14:36 ๐Ÿ‘ 2 ๐Ÿ” 3 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

THC Release ๐Ÿ’ฅ: The worldโ€™s largest IP<>Domain database: ip.thc.org

All forward and reverse IPs, all CNAMES and all subdomains of every domain. For free.

Updated monthly.

Try: curl ip.thc.org/1.1.1.1

Raw data (187GB): ip.thc.org/docs/bulk-da...

(The fine work of messede ๐Ÿ‘Œ)

17.12.2025 13:33 ๐Ÿ‘ 44 ๐Ÿ” 20 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

#Protip Need to go really fast and HEAD is disabled?
Use GET and the Range header...

20.12.2025 10:55 ๐Ÿ‘ 5 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

The wait is over! Phrack 72 40th Anniversary Edition is available now.

Order straight to your doorstep โ€” the perfect gift for your fellow hacker, just in time for the holidays ๐ŸŽ„

No need to go to rely on the warez scene with scans anymore ๐Ÿ˜…

Order here: www.lulu.com/shop/phrack-...

13.12.2025 09:34 ๐Ÿ‘ 28 ๐Ÿ” 17 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

THC Release: ๐ŸŽ„Smallest SSHD backdoor๐ŸŽ„

- Does not add any new file
- Survives apt-update
- Does not use PAM or authorized_keys

Just SSHD trickery....adds one line only.

More at thc.org/tips ๐Ÿ‘Œ

14.12.2025 14:47 ๐Ÿ‘ 17 ๐Ÿ” 4 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Looking for a Christmas gift for yourself? #burp #training #2026

Thereโ€™s 9 seats left for the English-speaking session, and 5 for the French-speaking one

13.12.2025 13:39 ๐Ÿ‘ 4 ๐Ÿ” 3 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Great article ๐Ÿ’Ž

13.12.2025 13:35 ๐Ÿ‘ 6 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Printed version of Paged Out #7, collected during GreHack 2025

Printed version of Paged Out #7, collected during GreHack 2025

Printed version of Paged Out #7, collected during GreHack 2025 ๐Ÿคฉ

06.12.2025 12:13 ๐Ÿ‘ 6 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

This vulnerability was the inspiration for the first step of the Panel challenge we played during last weekโ€™s Grehack CTF

But we found a dumb bypass ๐Ÿ˜Ž

03.12.2025 14:42 ๐Ÿ‘ 4 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Issue 91 โ€“ GDP on the blockchain The regulator set to take on primary crypto oversight is down to a single Commissioner, and new pro-crypto PACs focus on installing more Republicans in the midterms

www.citationneeded.news/issue-91/#tr...

25.11.2025 16:42 ๐Ÿ‘ 48 ๐Ÿ” 3 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Lโ€™4N551 4 un3 m1551on 9our vou5 :

Lโ€™4N551 4 un3 m1551on 9our vou5 :

๐Ÿ“œ Lโ€™4N551 4 un3 m1551on 9our vou5.

S1 vou5 lโ€™4cc3973z, vou5 s3r3z 4m3n3 4 :
*53rv1r lโ€™1nt3r37 g3n3r4l 37 9ro73g3r l4 N471on f4c3 4 l4 m3n4c3 cy83r ;
*1nc4rn3r lโ€™3xc3ll3nc3 fr4nรง4153 3n m4713r3 d3 cy83rd3f3n53.

9our 7rouv3r vo7r3 m1551on :
๐Ÿ”— www.welcometothejungle.com/fr/companies...

03.12.2025 10:56 ๐Ÿ‘ 8 ๐Ÿ” 5 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 2

Stealth (from Team-Teso, Phrack staff and other groups) passed away earlier this year ๐Ÿ˜ข

I didn't know him personally, but his groundbreaking research has been a constant influence on my career

www.thc.org/404/

03.12.2025 12:10 ๐Ÿ‘ 5 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
EP 208 EN | Caido de Noel ? Ft. @Agarri_FR @Rhynorater @TheSytten
EP 208 EN | Caido de Noel ? Ft. @Agarri_FR @Rhynorater @TheSytten YouTube video by Laluka

Here's the recording of the stream we made earlier this week with @laluka.bsky.social, @thesytten.bsky.social and @rhynorater.bsky.social

If you speak French, you may appreciate its title: "Caido de Noรซl" ๐Ÿ˜„ ๐ŸŽ ๐ŸŽ…

www.youtube.com/watch?v=JvUm...

27.11.2025 08:52 ๐Ÿ‘ 4 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I really want to know the full story behind this epic hack, and yet I also hope it is never solved.

22.11.2025 19:50 ๐Ÿ‘ 334 ๐Ÿ” 79 ๐Ÿ’ฌ 14 ๐Ÿ“Œ 2

I've uploaded the slides of my recent talk "JS Engine Security in 2025": saelo.github.io/presentation.... I think there'll also be a recording available at some point (otherwise I can make one as not everything's in the slides).

Fantastic conference as usual, big thanks to the PoC Crew!

24.11.2025 09:58 ๐Ÿ‘ 22 ๐Ÿ” 11 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Agarri Training

The 2026 online public sessions of my "Mastering Burp Suite Pro" course have been published ๐Ÿ“…

- March 24th to 27th, in French ๐Ÿ‡ซ๐Ÿ‡ท
- April 14th to 17th, in English ๐Ÿ‡ฌ๐Ÿ‡ง

hackademy.agarri.fr/2026

PS: feel free to ping me if you'd like to temporarily block a seat or are looking for a 10% coupon ๐ŸŽ

24.11.2025 10:14 ๐Ÿ‘ 8 ๐Ÿ” 7 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 1