Skip to content
View X3r0Day's full-sized avatar
💭
Fuck your security
💭
Fuck your security
  • Founder @ Project X3r0Day • Security Researcher • Dev @ SNEK • Backend • OpenDih
  • World Wide Web
  • X @X3r0DaySec

Highlights

  • Pro

Organizations

@OpenDih @The-SNEK-Initiative

Block or report X3r0Day

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
X3r0Day/README.md
x3r0day, professionally suspicious of your software

x3r0day 6.x-hardened · #1 SMP PREEMPT_DYNAMIC · offensive-security/unstable · arch btw


./bughunt.sh  ·  it plays itself, and the bugs still lose

a self-playing space-invaders where x3r0day shoots down CVEs

no, you can't control it. neither can the bugs.


whoami

                  -`
                 .o+`
                `ooo/
               `+oooo:
              `+oooooo:
              -+oooooo+:
            `/:-:++oooo+:
           `/++++/+++++++:
          `/++++++++++++++:
         `/+++ooooooooooooo/`
        ./ooosssso++osssssso+`
       .oossssso-````/ossssss+`
      -osssssso.      :ssssssso.
     :osssssss/        osssso+++.
    /ossssssss/        +ssssooo/-
  `/ossssso+/:-        -:/+osssso+-
 `+sso+:-`                 `.-/+oso:
`++:.                           `-/+/
.`                                 `/
x3r0day@arch
─────────────────────────────
> host      x3r0day · India
> role      bug hunter, security researcher
> uptime    00:00:00
> shell     zsh
> editor    nvim
> distro    arch (btw)
> focus     offensive, RE, malware, social-eng
> building  x3r0day framework (pentest toolkit)
> flex      a 32-bit RISC-V CPU. inside roblox.
> also      a (semi) working bash compiler. semi.
> reach     cr4n@duck.com

cat ~/.loadout

[ offense ]    kali · blackarch · parrot · burp · metasploit · wireshark
[ recon   ]    nmap · ffuf · whatever the target deserves
[ code    ]    python · bash · c · go · lua · java · kotlin · js
[ web     ]    node · express · react · mongo
[ systems ]    arch · debian · ubuntu · docker · git
[ daily   ]    nvim · vscode · obsidian · tmux
[ ml      ]    tensorflow, for when a bug needs a brain

cat ~/.trophies

[ pyweek 41 ]   won the team category · "the keeper" · python
                team MXRV. you're a lighthouse keeper at the end of the
                world, keeping the light on while the code keeps breaking.

[ hackathon  ]  2nd place · manware's discord hackathon · ran as 'meowha'
                a 32-bit RISC-V CPU and IDE. inside roblox. on purpose.
                asm → parser.lua → bytecode → cpu.lua. and yeah, it runs.
                (won a fucking gaming keyboard for it!)
the keeper: repo · pyweek  |  rv32im: repo · manware's take

yes, it runs real RISC-V assembly. no, roblox was not built for this.

i break things to understand them, then write down how, so the next person can't.



connection to x3r0day.sys closed.

no third-party widgets were used (or harmed) in the making of this profile.

Pinned Loading

  1. XeroDay-APISniffer XeroDay-APISniffer Public

    API Sniffer is a modular toolkit for scanning publicly available GitHub repositories and identifying exposed API keys, tokens, and secrets.

    Python 29 5

  2. NCRIF/Specter NCRIF/Specter Public

    Really fast async subdomain enumeration and port scanning.

    Python 2

  3. InformationDisclosure InformationDisclosure Public

    A tool to dig up the past for publicly available data... because why wait for secrets to come to you when you can just search for them?

    Python 8

  4. OpenDih/ManBot OpenDih/ManBot Public

    Discord bot to access ManGPT

    Python 2 4

  5. HashLock HashLock Public

    Python 1