Log inSign up
SinSinology
watchTowr
3,364 posts
Image
user avatar
SinSinology
watchTowr
@SinSinology
Pwn2Own 20{22,23,24*2,25*3,26*2}, i look for 0-Days but i find N-Days & i chase oranges 🍊
summoning.team
Joined June 2018
740
Following
12.8K
Followers
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Jul 18, 2024
    🙋‍♂️Ayo, I did a thing, check out the latest episode where we chat about approaching Pwn2Own targets, some advice and answer some .NET questions🔥 ctbbodcast thanks for having me (give them a sub people, they do cool shit)
    18K
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Jul 8, 2024
    🔥You see, I've been trying hard to promote my training by dropping blogs, poc, teaching different countries/cons, following that idea this Sat I thought, what if, I dropped 3 exploits & 3 blogs on the same day? so after sleeping only 2 hours in the last 48h, they're ready😏🫳🎤
    Image
    22K
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Feb 21, 2025
    it took me so much time to finish this exploit but I finally did it! my first guest-to-host virtualbox escape is finally ready, using a combination of 2 bugs I can target the latest version :) Eternal thank you to my dear friend Corentin @OnlyTheDuck for constantly encouraging me
    Image
    00:00
    79K
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Nov 4, 2024
    🔥💀After 40 hours of constant reversing of weird looking c++ and no sleep, I Finally cooked the CVE-2024-47575 fortimanager unauthenticated RCE 🩸
    user avatar
    watchTowr
    @watchtowrcyber
    Nov 4, 2024
    we’re back, and despite all the buzz about FortiManager - the saga is about to continue. Please, remove this from the Internet *even if fully patched* speak soon.
    Image
    00:00
    108K
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Jul 8, 2024
    🚨🚨🚨PoC DROP! As part of today's triple exploit drop 🔥, here is the link to 1/3 poc, Progress Whatsup gold Pre-Auth Remote Code Execution 🩸 using the GetFileWithoutZip Primitive 🪲 to achieve a write what where and then popping a she'll 🤷‍♂️ github.com/sinsinology/CV…
    Image
    GIF
    9.8K
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Jun 13, 2023
    🚨 #VMWare Pre-Authenticated Remote Code Execution (CVE-2023-20887) #PoC is ready
    Image
    GIF
    80K
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Jul 8, 2024
    🕵️‍♂️Here is the Exploit for the second 🤞 pre-auth Remote Code Execution 🔥 targeting progress whatsup gold which exploits a dangerous .NET WCF Service over NetTcpBinding UnAuThenTicated 🤷‍♂️ github.com/sinsinology/CV…
    Image
    8.6K
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Jun 25, 2024
    🚨🚨🚨 PoC DROP!!! We at watchTowr have released our latest work 🔥 on exploiting MOVEit Transfer, ability to access all your SECRET files 🩸 only by having your username, this was a .NET Target 😏, So fuckin proud of the exploit chain WE crafted 🔥🤝 🔥
    user avatar
    watchTowr
    @watchtowrcyber
    Jun 25, 2024
    Progress just un-embargoed a very closely guarded auth bypass in MOVEit Transfer's SFTP mechanism - CVE-2024-5806. We were lucky enough to receive a tip-off :-) Enjoy our analysis, we had a lot of fun. labs.watchtowr.com/auth-bypass-in…
    Image
    GitHub - watchtowrlabs/watchTowr-vs-progress-moveit_CVE-2024-5806: Exploit for the CVE-2024-5806
    From github.com
    17K
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Jul 8, 2024
    🔥 I've just published the details of my latest progress pre-auth Remote Code Execution this is CVE-2024-4885
    summoning.team
    WhatsUp Gold Pre-Auth RCE GetFileWithoutZip Primitive
    I discovered an unauthenticated path traversal against the latest version of progress whatsup gold and turned it into a pre-auth RCE, following is how I did it, this is the story of CVE-2024-4885
    19K
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Jan 27, 2025
    My English has never been good, I tried to translate what I had in my mind and I hope this shows how I feel Every step of this journey was a challenge—long hours, sacrifices, and moments when it felt impossible. But it was all worth it. I’m so proud and honored to have won 1st
    Image
    Image
    user avatar
    TrendAI Zero Day Initiative
    @thezdi
    Jan 24, 2025
    And that’s a wrap! #Pwn2Own Automotive 2025 is complete. In total, we awarded $886,250 for 49 0-days over the three day competition. With 30.5 points and $222,250 awarded, Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) is our Master of Pwn. #P2OAuto
    39K
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Oct 24, 2025
    PoV: you wakeup and go run a pwn2own exploit @thezdi
    Image
    00:00
    Image
    user avatar
    SinSinology
    watchTowr
    @SinSinology
    Oct 22, 2025
    exhausted, last entry tomorrow
    48K
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Jun 13, 2024
    🚨🚨DO NOT PANIC! I'm publishing my detailed analysis of CVE-2024-29855 which targets Veeam Recovery Orchestrator Authentication 🩸, this has a score of CVSS 9 🪲, but IMHO its not as severe, however, I like the technical details of it, so here we go 🔥
    summoning.team
    There are no Secrets || Exploiting Veeam CVE-2024-29855
    This vulenrability is due to the fact that JWT secret used to generate authentication tokens was a hardcoded value which means an unauthenticated attacker can generate valid tokens for any user (not...
    15K
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Sep 16, 2024
    🔥💀 Here is the "Real" writeup and exploit for the pre-auth deserialization RCE I reported to Ivanti CVE-2024-29847 Apparently, folks at horizon3 tried to write about my bug before me but they did it wrong
    summoning.team
    The real slim shady || Ivanti Endpoint Manager (EPM) Pre-Auth RCE
    ivanti just pushed a patch for a Critical CVSS 9.8 Remote Code Execution Vulnerability that I reported on May 1st 2024, impacting Ivanti Endpoint Manager (EPM). in the following blog post I will be...
    49K
  • user avatar
    SinSinology
    watchTowr
    @SinSinology
    Nov 14, 2024
    A no bull shit staright up fAcTuAl RCE, choke on this
    user avatar
    watchTowr
    @watchtowrcyber
    Nov 14, 2024
    hop skip jump over to our latest blog post - analysing Fortinet's FortiJump CVE-2024-47575, FortiJump-Higher (we love this name😄) and beyond (PoC included) labs.watchtowr.com/hop-skip-forti…
    11K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement