Log inSign up
Johan Carlsson
1,415 posts
Image
user avatar
Johan Carlsson
@joaxcar
Father and full-time bug hunter ๐Ÿž
joaxcar.bsky.social
Joined January 2022
195
Following
5,965
Followers
  • Pinned
    user avatar
    Johan Carlsson
    @joaxcar
    Feb 4, 2025
    I did not find an easy way to delete all my tweets, I will leave them for now. I might come back for that later. For now: follow me on joaxcar.bsky.social for updates! I will not engage with content here. ๐Ÿฆ‹
    5K
  • user avatar
    Johan Carlsson
    @joaxcar
    Sep 7, 2022
    Yesterday I made it into top 5 on @gitlab bug bounty program ๐Ÿฅณ, at the same time crossing 100k in bounties from the same. Some people are asking me how to get started or where and what to look for. I thought I could share a practical guide if anyone care for a thread [1/6]
  • user avatar
    Johan Carlsson
    @joaxcar
    Oct 4, 2024
    I did not believe I could check off more bucket list items this year. This bug proved me wrong. Found my first ever proper RCE using command injection (through code review), really happy about this one
    Image
    27K
  • user avatar
    Johan Carlsson
    @joaxcar
    Sep 21, 2022
    Looks like this is the time to learn how to hunt for leaked GitLab tokens ๐Ÿ‘€
    Image
  • user avatar
    Johan Carlsson
    @joaxcar
    Oct 9, 2023
    I have finally done my first proper bug write-up! This one is about a SOP bypass in Chrome (escalated to ATO) using the Navigation API. Hope someone finds it interesting. Feel free to leave me any comments; I want to improve on this!
    Image
    CVE-2022-4908: SOP bypass in Chrome using Navigation API - Johan Carlsson
    From joaxcar.com
    85K
  • user avatar
    Johan Carlsson
    @joaxcar
    Feb 19, 2024
    Did a little writeup of the CSP bypass I reported to PortSwigger. It might be interesting to anyone who saw the disclosed report and wonders if CSP bypasses are the new ripe low-hanging fruit!
    Image
    CSP bypass on PortSwigger.net using Google script resources - Johan Carlsson
    From joaxcar.com
    26K
  • user avatar
    Johan Carlsson
    @joaxcar
    Aug 27, 2024
    Finally ๐Ÿฅณ
    Image
    17K
  • user avatar
    Johan Carlsson
    @joaxcar
    Aug 26, 2024
    Can someone explain this
    Image
    78K
  • user avatar
    Johan Carlsson
    @joaxcar
    Nov 21, 2023
    Small XSS challenge. Real life situation that I solved today. Should be pretty easy, but good practice if you are just getting into XSS or is trying to get away from copy pasting payloads xss-playground.glitch.me/01.html?x=injeโ€ฆ
    85K
  • user avatar
    Johan Carlsson
    @joaxcar
    Jul 6, 2024
    Everyone is raving about CSPT used as CSRF. Wy not celebrate that this was explained already in webapp hacker handbook?! See @PortSwigger blog from 2007: portswigger.net/blog/on-site-rโ€ฆ Also, lets bring back the name โ€œOn-site Request Forgeryโ€
    Image
    On-site request forgery
    From portswigger.net
    20K
  • user avatar
    Johan Carlsson
    @joaxcar
    Feb 29, 2024
    Just dropped off my work computer at the office. From tomorrow I will do bug bounties full time for three months. After that evaluate if my mental health can cope with it.. Wish me good luck!
    16K
  • user avatar
    Johan Carlsson
    @joaxcar
    Jun 7, 2022
    My first disclosure to reach 100 up-votes on @Hacker0x01. Disclosures have been the number one learning resource for me, so to see people finding an interest in my own reports makes me happy! Also thanks @gitlab for allowing full disclosures, contributing to this great resource
    Image
  • user avatar
    Johan Carlsson
    @joaxcar
    Aug 27, 2024
    Thanks for the great explanations for this. Apparently, URL parsing (at least in browsers) is supposed to strip out "newlines" AND tabs. So all of these will land on /b
    Image
    Image
    user avatar
    Johan Carlsson
    @joaxcar
    Aug 26, 2024
    Can someone explain this
    23K
  • user avatar
    Johan Carlsson
    @joaxcar
    Aug 12, 2024
    I just dropped the kids off at school on the first day after summer break. I am officially starting my new career as a full-time bug bounty hunter. Now I just have to find those bugs.
    10K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

TermsยทPrivacyยทCookiesยทAccessibilityยทAds Infoยทยฉ 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement