91 Followers
250 Following
49 Posts
IT-Security Researcher, Pentester and Bug Hunter. Passionate about πŸ’», πŸ€½β€β™‚οΈ, ⚜️, 🎸 and ⚽ #meinVfL
#Kaeferjaeger + H1 Ambassadorβ€¨πŸ  https://security.lauritz-holtmann.de
Bloghttps://security.lauritz-holtmann.de/
Twitterhttps://twitter.com/_lauritz_
LinkedInhttps://www.linkedin.com/in/lauritz-holtmann/
Intigritihttps://app.intigriti.com/profile/_lauritz_

Bug Bounty Meetup vol. 5 of the German @Hacker0x01 club will be held Feb 14th to Feb 22nd (remote). πŸ‘¨β€πŸ’»

20 seats, swag, remote space for networking, a bug bounty target and lots of collaboration.

RSVP now: https://h1.community/e/mbcd6v/

Recap of our
@Hacker0x01 Hacking Meetup in September πŸ‘€

Leaderboard (still in progress): leaderboards.hackerone.live/germany-meetup-sept-2025

πŸ‘‰ h1.community/e/mbkdm3/

#BugBounty #Meetup #HackerOne

Hacking Meetup vol. 3 of the German @Hacker0x01 Club - supported by EXNESS - was a blast! πŸ’₯

We x6 the overall bounties of our previous meetup and scored over 94,000$ overall bounties. 🀯

Additionally, H1 swag is on the way to all attendees and will hopefully arrive soon. 🀞

Our @Hacker0x01 meetup (vol.2) last month was a blast! πŸ”₯

Almost 40 signups, ~25 active remote attendees and 12 attendees from all over Germany who travelled to #Bochum and hacked together in person on Grab's assets. 🀯

#BugBounty #Meetup

#38c3 was πŸš€
πŸ”œπŸš€ #38c3

#BurpSuite #Bambda to detect Blind SSRF via OpenID Connect "request_uri" using out-of-bound detection (e.g. Collaborator).

The vulnerable URL is b64-encoded and included within the canary URL.

πŸ‘‰ https://gist.github.com/lauritzh/7b3ebfb5f541b6027152e5cee2f11b0d

πŸ“š https://security.lauritz-holtmann.de/post/sso-security-ssrf/

Simple Burp Suite Bambda to detect Blind SSRF via OIDC request_uri GET parameter

Simple Burp Suite Bambda to detect Blind SSRF via OIDC request_uri GET parameter - request_uri.bambda

Gist

Finally found time to automate the build process of my @[email protected] blog and its deployment using a @[email protected] workflow πŸ’ͺ

The setup was actually easier than expected, tbh πŸ˜…

https://security.lauritz-holtmann.de

(Web-)Insecurity Blog