TGViewer
Channel Public Channel
Casual Blog

Casual Blog

@casualblog

Casual, behold I am. This blog heralds tech and its hacks.

Telegram mirror for -
https://blog.ca.sual.in/

Personal posts - @insideCasual
Subscribers
435
Photos
8
Videos
0
Links
37
Recent Posts 17 shown
Post #117 910
Blog: Domain is Gone


## DNS

Thanks to Namecheap I’m ultimately distrust centrilized DNS solutions (and centrilized solutions overall). Anyway blog now works inside Yggdrasil overlay network.

Currently they are accessable at:

● http://[327:b739:99b6:904::face]/
● http://[327:b739:99b6:904::dead]/

Probably there will be mirror at DuckDNS (with announcement in personal blog).

Later, I’m gonna make post in personal blog about other DNS solutions and thoughts about them.


## Telegram mirror news?

Official Unofficial Telegram mirror gained a plantiful of followers lately due to inclusion to shareable channel folder, but let’s be real here - you are tresspassers here and I’m not sure that you will be here after few posts (poor people, 66% of them have notifications enabled).

----------------------

Anyway, more technical posts are on the way

via Casual Blog
Post #114 846
CVE-2025-55182 is overhyped

CVE-2025-55182 is a 10.0 CRITICAL vulnerability. Thou it’s not as easy to exploit in real bugbounty world due to complexity of finding vulnerable target and endpoint.

Changelog: https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components

Commits (scroll to down to Dec1): https://github.com/facebook/react/compare/v19.2.1...main

POC:
https://github.com/ejpir/CVE-2025-55182-poc
https://github.com/sickwell/CVE-2025-55182

via Casual Blog
  • 🔥 3
  • ☃ 2
  • 🙊 2
Post #113 720
HowTo Bruteforce Owncloud

By default Owncloud doesn’t have any account locking or login rate limit (but can be enabled in settings) - which means you can get easy bug bounty:
(CWE-307 Improper Restriction of Excessive Authentication Attempts)

https://github.com/AbandonwareDev/owncloud_bruteforcer

Also tool may slow down owncloud instance by 3 times at 20 threads (and use 100% CPU) - so there can be potential DoS

via Casual Blog
  • 🔥 1
  • 🤡 1
Post #112 808

Forwarded from Inside Casual

HowIs Standoff Hacks Ahmedabad

Hi! I was at Standoff Hacks Ahmedabad. It’s a priv8 bugbounty event for cool hackers!


# How it worked

Some recognized hackers got direct invite and other could participate in a competition (bugbounty on specific vendors). I was directly invited, but also participated in competition and would win.

Then we had 2 weeks for bugbounty hacking few private programs with great payouts.

After that we flew to B-Sides conference in Ahmedabad to celebrate end of the event (almost every expense was covered)


# Experience

Mostly it was good experience, though due to lack of time among all parties hackers didn’t have enough time to get feedback from vendors to understand if they will accept such reports later on.

Also, I would encourage all vendors to reach hackers directly in messenger/in-person to clarify why/how some decisions happen. Communication online can be quite confusing and draining if you don’t understand emotions of interlocutor.

I’m really glad that I was here, it is one of the most productive hacking weeks in my life, thou I was virtually mentally destroyed at the end (add to that lack of sleep). After hacking we got a trip to Ahmedabad. And oh boy, it was exhausting.

So after mental and physical death I was in Ahmedabad just to catch cold in a first taxi right after landing :)

Despite all odds, I’m glad that I was there. The party was amazing. Other hackers really are sweethearts and so easygoing to talk with. It’s a shame that I wasn’t in the best condintion to socialize.

By the way, I scored top-5!!!
Though I believe I didn’t performe well enough. (special thanks to Masha, Orwa, Alexander, Elizavetta, Nastya)


# Thanks

I want to thank a lot of people who made it possible, it is really one of my most valuable memories, even if I wasn’t feeling like it at that moment. Thanks everyone!!! &LT3

Hopefully I will create more memories like those without feeling that I’m at my limits.

Folks, see you all in the next PHD/Hacks :)

----------------------

P.S. After the trip I was sleeping better and partying hard only to get more ill and prolong recovery time. XD

via Inside Casual

Invalid media: image
  • ❤ 4
  • 🔥 3
Post #107 958

Forwarded from Inside Casual

My "Company" got attacked!

Ladies and gentlemen, this is just amazing!
My “company” is being attacked by some hackers pretending to be Indians.

“Company”? Indians? You might ask

It’s simple, my domain is sual.in (the joke is - c@sual.in (mailto:c@sual.in) email) (.in - Indian TLD).
And here’s what I’m seeing now:

I’m curious how they came up with this email and why are they so dumb to send a bunch of emails at the same time…

So, I expect a Korean-style attack, where they “apply” for a job and either steal money through salaries or hack the infrastructure with subsequent data extraction

Of course, the resumes and PDFs are AI-generated (there are even empty 500KB PDFs, maybe they contain exploits), and the links don’t work (they’re just text).

----------------------

What are your suggestions on what I should do about this? Contact me!

I mean, they have used real Gmail accounts, they’re not just here to drop a payload and leave, they spent money to buy accounts, make it look real. It’s not a lot per account, but still, they’re consumables.

via Inside Casual
  • ❤ 1
  • 🥰 1
Post #86 826
HowWorks CRLF

‘HowWorks’ - new post type, explains how something works, in that case CRLF vulnerability
If we can inject some data in web app that doesn’t get proper validation/filtering and used in HTTP response Headers, then we can inject \r\n (HTTP line break, CRLF).

You can think of it as stored XSS, but instead Javascript, we inject \r\n which will allow to effectivly modify entire HTTP response from server to specific endpoint.

Example - set name to username%0d%0aLocation:http://malicioussite.com/ to redirect anyone who access your username in url.

Impact:

● XSS
● Log Injection
● HTTP Header Injection
● HTTP Response Splitting
● Log Tampering
● Cookie Injection
● Phishing
● Web Cache Poisoning

It’s a rare bug nowadays.
Truth be told, I thought it’s more complex

----------------------
Sources
● https://owasp.org/www-community/vulnerabilities/CRLF_Injection
● https://www.imperva.com/learn/application-security/crlf-injection/

via Casual Blog
  • ❤ 1
Post #82 672
Happy New Year v20.25

The World is full of shit.

Neverthless do what You want and be happy with it.

Happy New Year to You. <3

via Casual Blog
  • ❤ 2
Post #76 478
HowTo wipe HDD - 101


# Secure wipe individual file
shred -v -n 3 ./file

Thou might not be secure if your filesystem use COW (copy-on-write) (like btrfs,zfs), make shadow copies (windows, ntfs), uses RAID.



# Secure wipe entire drive
shred -v -n 3 /dev/HDD
# Or if you are paranoid - slower
shred -v -n 7 /dev/HDD

Long. Expect waiting a day or two.
Or…

via Casual Blog
Older posts →

About this channel

How can I read @casualblog without a Telegram account?
TGViewer shows the public web preview Telegram publishes for Casual Blog: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does Casual Blog have?
Casual Blog (@casualblog) has 435 subscribers on Telegram, refreshed roughly every 30 minutes.
Does Casual Blog know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →