RomHack Training
Come to Roma ๐ฎ๐น ๏ฟผin September and attend the only in-person public training session I'll give in 2026! ๐จโ๐ซ
And if you like camping with other hackers (as I do), stay over the weekend for the 3-day long RomHack Camp ๏ฟผ๐๏ธ
romhack.io/training/
04.03.2026 14:05
๐ 3
๐ 2
๐ฌ 0
๐ 0
Last week, I had the opportunity to attend the 4-day Mastering Burp Suite Pro training by ๐ ๏ธ Nicolas Gregoire, and it exceeded my expectations by far.
This wasnโt just another slide-driven course. Nicolas took the time to answer every question in depth and provided plenty of hands-on labs, allowing us to immediately apply what had just been explained.
Even though Iโve been working with Burp for nearly five years, I still picked up a surprising number of new techniques and practical tricks, including ways to streamline otherwise time-consuming workflows such as managing CSRF tokens both with and without session handling rules.
What I especially appreciated were the little side explorations (driven by our requests) into methodologies for leveraging features and extensions to remain stealthy or bypass WAFs. This is something thatโs particularly relevant (and often underestimated) when exploiting external or internal web applications during advanced Red Team engagements.
Iโm genuinely looking forward to applying this newly gained knowledge in upcoming projects, and I can wholeheartedly recommend this training to any (web) pentester who wants to level up their Burp skills.
Big thanks to Nicolas for an excellent and highly practical course!
Another highly satisfied trainee ๐ ๐จโ๐ซ
If you want to take the online version of my Burp Suite course, there are two opportunities really soon (March in French, April in English) hackademy.agarri.fr/sessions
And if you want to indulge your company a private session (like this company did), ping me!
10.02.2026 08:46
๐ 4
๐ 1
๐ฌ 0
๐ 0
Agarri
Training
Spring is just around the corner, and that's when I offer online training courses on Burp Suite Pro ๐จโ๐ซ Two sessions are planned (in English and French), and there are still a few spots left in each.
Contact me to get an early-bird discount code! ๐ฐ
31.01.2026 12:31
๐ 6
๐ 5
๐ฌ 0
๐ 0
Agarri
Training
Spring is just around the corner, and that's when I offer online training courses on Burp Suite Pro ๐จโ๐ซ Two sessions are planned (in English and French), and there are still a few spots left in each.
Contact me to get an early-bird discount code! ๐ฐ
31.01.2026 12:31
๐ 6
๐ 5
๐ฌ 0
๐ 0
Thanks to everyone who nominated & voted in the top ten! The panel of @irsdl.bsky.social , @agarri.fr , @liveoverflow.bsky.social and myself are hard at work reviewing the 15 finalists... we're hoping to announce the winners next week!
29.01.2026 16:04
๐ 8
๐ 1
๐ฌ 0
๐ 0
In case you didn't vote yet (2 days left!), let me tell you that your participation is critical ๐ณ๏ธ
Indeed, the panel (that I'm part of) will only process the top X results and it may contain some sh*tty entries (because of ballot stuffing ๐ฅด)
So please do your part! ๐
20.01.2026 10:24
๐ 4
๐ 0
๐ฌ 0
๐ 0
Agarri
Training
The 2026 online public sessions of my "Mastering Burp Suite Pro" course have been published ๐
- March 24th to 27th, in French ๐ซ๐ท
- April 14th to 17th, in English ๐ฌ๐ง
hackademy.agarri.fr/2026
PS: feel free to ping me if you'd like to temporarily block a seat or are looking for a 10% coupon ๐
24.11.2025 10:14
๐ 8
๐ 7
๐ฌ 0
๐ 1
I'm slowly going though the talks from the CCC congress. Here's my favorites so far... โคต๏ธ
13.01.2026 11:35
๐ 1
๐ 1
๐ฌ 1
๐ 0
Backing up Spotify
We backed up Spotify (metadata and music files). Itโs distributed in bulk torrents (~300TB). Itโs the worldโs first โpreservation archiveโ for music which is fully open (meaning it can easily be mirro...
Annaโs Archive is an incredible project aimed at preserving humanityโs knowledge and culture
Their latest exploit is a near-full backup of Spotify. It includes 86 million songs, representing around 99.6% of listens ๐ถ
annas-archive.org/blog/backing...
31.12.2025 15:06
๐ 13
๐ 6
๐ฌ 0
๐ 0
Backing up Spotify
We backed up Spotify (metadata and music files). Itโs distributed in bulk torrents (~300TB). Itโs the worldโs first โpreservation archiveโ for music which is fully open (meaning it can easily be mirro...
Annaโs Archive is an incredible project aimed at preserving humanityโs knowledge and culture
Their latest exploit is a near-full backup of Spotify. It includes 86 million songs, representing around 99.6% of listens ๐ถ
annas-archive.org/blog/backing...
31.12.2025 15:06
๐ 13
๐ 6
๐ฌ 0
๐ 0
OWASP Top 10:2025
OWASP Top 10:2025
Looks like the final OWASP Top 10 (2025) has been published: owasp.org/Top10/2025/.
Based on commits, looks like this happened 5 days ago.
29.12.2025 12:24
๐ 5
๐ 1
๐ฌ 0
๐ 0
THC Release ๐ฅ: The worldโs largest IP<>Domain database: ip.thc.org
All forward and reverse IPs, all CNAMES and all subdomains of every domain. For free.
Updated monthly.
Try: curl ip.thc.org/1.1.1.1
Raw data (187GB): ip.thc.org/docs/bulk-da...
(The fine work of messede ๐)
17.12.2025 13:33
๐ 44
๐ 20
๐ฌ 0
๐ 0
#Protip Need to go really fast and HEAD is disabled?
Use GET and the Range header...
20.12.2025 10:55
๐ 5
๐ 0
๐ฌ 0
๐ 0
The wait is over! Phrack 72 40th Anniversary Edition is available now.
Order straight to your doorstep โ the perfect gift for your fellow hacker, just in time for the holidays ๐
No need to go to rely on the warez scene with scans anymore ๐
Order here: www.lulu.com/shop/phrack-...
13.12.2025 09:34
๐ 28
๐ 17
๐ฌ 1
๐ 0
THC Release: ๐Smallest SSHD backdoor๐
- Does not add any new file
- Survives apt-update
- Does not use PAM or authorized_keys
Just SSHD trickery....adds one line only.
More at thc.org/tips ๐
14.12.2025 14:47
๐ 17
๐ 4
๐ฌ 1
๐ 0
Looking for a Christmas gift for yourself? #burp #training #2026
Thereโs 9 seats left for the English-speaking session, and 5 for the French-speaking one
13.12.2025 13:39
๐ 4
๐ 3
๐ฌ 0
๐ 0
Great article ๐
13.12.2025 13:35
๐ 6
๐ 0
๐ฌ 0
๐ 0
Printed version of Paged Out #7, collected during GreHack 2025
Printed version of Paged Out #7, collected during GreHack 2025 ๐คฉ
06.12.2025 12:13
๐ 6
๐ 1
๐ฌ 0
๐ 0
This vulnerability was the inspiration for the first step of the Panel challenge we played during last weekโs Grehack CTF
But we found a dumb bypass ๐
03.12.2025 14:42
๐ 4
๐ 1
๐ฌ 0
๐ 0
Lโ4N551 4 un3 m1551on 9our vou5 :
๐ Lโ4N551 4 un3 m1551on 9our vou5.
S1 vou5 lโ4cc3973z, vou5 s3r3z 4m3n3 4 :
*53rv1r lโ1nt3r37 g3n3r4l 37 9ro73g3r l4 N471on f4c3 4 l4 m3n4c3 cy83r ;
*1nc4rn3r lโ3xc3ll3nc3 fr4nรง4153 3n m4713r3 d3 cy83rd3f3n53.
9our 7rouv3r vo7r3 m1551on :
๐ www.welcometothejungle.com/fr/companies...
03.12.2025 10:56
๐ 8
๐ 5
๐ฌ 0
๐ 2
Stealth (from Team-Teso, Phrack staff and other groups) passed away earlier this year ๐ข
I didn't know him personally, but his groundbreaking research has been a constant influence on my career
www.thc.org/404/
03.12.2025 12:10
๐ 5
๐ 0
๐ฌ 0
๐ 0
EP 208 EN | Caido de Noel ? Ft. @Agarri_FR @Rhynorater @TheSytten
YouTube video by Laluka
Here's the recording of the stream we made earlier this week with @laluka.bsky.social, @thesytten.bsky.social and @rhynorater.bsky.social
If you speak French, you may appreciate its title: "Caido de Noรซl" ๐ ๐ ๐
www.youtube.com/watch?v=JvUm...
27.11.2025 08:52
๐ 4
๐ 0
๐ฌ 0
๐ 0
I really want to know the full story behind this epic hack, and yet I also hope it is never solved.
22.11.2025 19:50
๐ 334
๐ 79
๐ฌ 14
๐ 2
I've uploaded the slides of my recent talk "JS Engine Security in 2025": saelo.github.io/presentation.... I think there'll also be a recording available at some point (otherwise I can make one as not everything's in the slides).
Fantastic conference as usual, big thanks to the PoC Crew!
24.11.2025 09:58
๐ 22
๐ 11
๐ฌ 0
๐ 0
Agarri
Training
The 2026 online public sessions of my "Mastering Burp Suite Pro" course have been published ๐
- March 24th to 27th, in French ๐ซ๐ท
- April 14th to 17th, in English ๐ฌ๐ง
hackademy.agarri.fr/2026
PS: feel free to ping me if you'd like to temporarily block a seat or are looking for a 10% coupon ๐
24.11.2025 10:14
๐ 8
๐ 7
๐ฌ 0
๐ 1