Alex Chapman's Avatar

Alex Chapman

@ajxchapman

Full Time #BugBounty Vulnerability Researcher https://blog.ajxchapman.com

2,810
Followers
461
Following
202
Posts
09.10.2023
Joined
Posts Following

Latest posts by Alex Chapman @ajxchapman

Blind SQL injection optimization In this post I examine techniques and optimizations which can be used to efficiently extract SQL query results from Blind SQL Injection vulnerabilities. With the correct techniques and optimizations t...

*cough* blog.ajxchapman.com/posts/2017/0... *cough*

10.03.2026 18:45 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Every bug hunter / vulnerability researcher / pentester should have to write their own blind or timing based SQL injection tool. It's like a rite of passage, if you've taken the time to understand and produce your own you'll probably make it in this world, if not 😬

x.com/slonser_/sta...

10.03.2026 18:45 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Last BSidesNYC I sat behind a guy doing the CTF with ChatGPT. Ctrl-a paste page source and a screenshot, hit enter, repeat. User totally not reading the output. LLM got the flag (flappybird-style JS challenge) after maybe ten rounds of this.

Last message dude sent in the session was "We did it!".

10.03.2026 11:05 πŸ‘ 3 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

Yeah this is 100% what I'm talking about, it _is_ happening, and a whole lot of people are going to be voluntarily less knowledgeable because of it.

LLMs are a tool of the future, but we don't need to stop learning because of it.

10.03.2026 11:12 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I think it's highly likely we'll end up in a split tier future of those that use LLMs without learning, and those that seek to understand what the LLM is doing and learn from it.

I believe the latter is the much more desirable camp to be in.

10.03.2026 10:53 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Hoshino Lina (ζ˜ŸδΉƒγƒͺγƒŠ) 🩡 3D Yuri Wedding 2026!!! (@lina@vt.social) There's a lot of discourse on Twitter about people using LLMs to solve CTF challenges. I used to write CTF challenges in a past life, so I threw a couple of my hardest ones at it. We're screwed. At ...

This post on LLM use in CTFs sums up my feelings on the subject nicely.

vt.social/@lina/116198...

When simply directing LLMs for development / security research / CTFs it's quick, often accurate, often useful, but I don't inherently learn anything other than how to direct the LLM.

10.03.2026 10:53 πŸ‘ 3 πŸ” 1 πŸ’¬ 3 πŸ“Œ 0

What I'm waiting for: Email updates to 5 separate Bug Bounty reports
What I get: Email notifications of 3 year old reports being closed

😭

04.03.2026 08:49 πŸ‘ 2 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

I wouldn't even attempt to report a bug to a company without at least a VDP / security.txt / security@ these days. The amount of effort for sometimes less than 0 appreciation is just not worth it.

26.02.2026 09:23 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
redstopgringo
Follow
β€’β€’β€’
Are Pinky and the Brain still trying to take over the world? Because at this point, I'm willing to hear the Brain's platform.
the-other-sandy ε°±@
β€’β€’.
At this point, I'm willing to hear Pinky's platform.
56
22,966
25,029

redstopgringo Follow β€’β€’β€’ Are Pinky and the Brain still trying to take over the world? Because at this point, I'm willing to hear the Brain's platform. the-other-sandy ε°±@ β€’β€’. At this point, I'm willing to hear Pinky's platform. 56 22,966 25,029

Same.

12.01.2026 15:18 πŸ‘ 111 πŸ” 33 πŸ’¬ 6 πŸ“Œ 3
Post image
03.01.2026 19:57 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

To be fair, dinosaurs rule.

01.12.2025 11:48 πŸ‘ 4 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

If you are selling a mirror and your ad creative includes images of the product with impossible reflections, I'm going to have to go ahead and assume your product doesn't work very well!

29.11.2025 17:20 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I'm sympathetic to corporate policy "patch gaps", but when it's framed as "acceptable exploitation window" it hits on a different level πŸ€”

05.11.2025 18:07 πŸ‘ 8 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

Dad’s books are full of empathy, common sense, and a healthy suspicion of the powerful. But at its heart his work is also about how systems keep people poor while pretending it’s their own fault. So I hope Kemi’s taking notes as well as reading the jokes.

07.10.2025 12:46 πŸ‘ 7808 πŸ” 1980 πŸ’¬ 140 πŸ“Œ 38

"Despite repeated warnings over X's evolution into what some might describe as a wretched hive of scum and villainy, governments and organizations are still reluctant to leave the social media platform" πŸ”₯

29.09.2025 11:49 πŸ‘ 0 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0
Preview
Incentives and Outcomes in Bug Bounties Bug bounty programs have contributed significantly to security in technology firms in the last decade, but little is known about the role of reward incentives in producing useful outcomes. We analyze ...

An in depth summary of the consequence of Google VRP increasing bounties in 2024.

"We observe statistically significant increases in the reporting
of high-value bugs, especially in the highest impact tiers and high merit submissions." πŸ”₯

arxiv.org/abs/2509.16655

28.09.2025 15:14 πŸ‘ 8 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
Incentives and Outcomes in Bug Bounties Bug bounty programs have contributed significantly to security in technology firms in the last decade, but little is known about the role of reward incentives in producing useful outcomes. We analyze ...

An in depth summary of the consequence of Google VRP increasing bounties in 2024.

"We observe statistically significant increases in the reporting
of high-value bugs, especially in the highest impact tiers and high merit submissions." πŸ”₯

arxiv.org/abs/2509.16655

28.09.2025 15:14 πŸ‘ 8 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0

The new favourite fidget toy on my desk is the Zippo lighter I've had since I was a teenager. There is something about the noise of the cap flipping open and flint sparking. This has replaced the ever popular poker chips.

Needless to say, I am not a great example for my kids 😬

18.09.2025 08:05 πŸ‘ 2 πŸ” 0 πŸ’¬ 2 πŸ“Œ 0

Hackers tops the list of films that have influenced my life. Without seeing this film as a young teen I may not have misspent my youth in front of a computer trying to understand how it all worked. Which, despite what my parents suggested at the time, seems to have worked out well for me πŸ˜†

16.09.2025 09:50 πŸ‘ 9 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Back in the day when I was hopping around flats in London I got all of them though scraping rental and roomshare adverts (mostly Gumtree at the time) so I could be the first person to respond and see a place. It's definitely an underrated technique!

15.09.2025 18:50 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

That feeling when you finally read that blog post you've had open in a browser tab for 3 months, and it's complete garbage πŸ˜‘

12.09.2025 08:54 πŸ‘ 30 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0

It's honestly embarrassing!

02.09.2025 14:26 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Alex Chapman on X: "It's been 6 years (!) since I lost my daughter ChloΓ«. This is an intensely confusing time of year for me, enjoying time with my two (wonderful) subsequent daughters, whilst mourning ChloΓ«'s loss. I am so blessed, but at the same time so incredibly sad and angry." / X It's been 6 years (!) since I lost my daughter ChloΓ«. This is an intensely confusing time of year for me, enjoying time with my two (wonderful) subsequent daughters, whilst mourning ChloΓ«'s loss. I am so blessed, but at the same time so incredibly sad and angry.

My previous yearly posts were on the other site, linked below for anyone who wishes to read them, or read ChloΓ«'s story.

x.com/ajxchapman/s...

24.08.2025 22:04 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I nearly didn't post ChloΓ«'s birthday this year. I feel like after 7 years I should be able to handle the pain better (I can't) or be over it somehow (I'm not). I decided that it's a way I choose to remember her, and I don't want to ever forget.

24.08.2025 22:04 πŸ‘ 2 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

It's been another year since my wife and I lost our first daughter ChloΓ«. She would have been 7 today. With each passing year I can't help but think about what her life would have been like, what our life would have been like, had she been given a chance. I love her so much, but don't even know her.

24.08.2025 22:04 πŸ‘ 22 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
All You Need Is MCP - LLMs Solving a DEF CON CTF Finals Challenge DEF CON CTF Every year world-class teams play difficult CTFs such as Plaid CTF and HITCON CTF in an attempt to qualify for DEF CON CTF by getting first place. There are usually only 3-4 CTFs a year de...

This jaw dropping write-up of an LLM solving a DEF CON CTF challenge(!) with minimal human interaction 🀯 It seems like "vibe-reversing" is becoming a viable option now...

15.08.2025 14:32 πŸ‘ 11 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0

I'll add it to the list
bsky.app/profile/ajxc...

14.08.2025 17:15 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Simpsons meme "Old Man Yells At Cloud"

Simpsons meme "Old Man Yells At Cloud"

There is something quite depressing about many of the advertised agentic AI use cases being posting "viral" content to social media. It stinks of one person assuming their time is inherently worth more than everyone else.

08.08.2025 15:36 πŸ‘ 3 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I've said it before and I'll say it again, Windows 11 is _such_ a hostile user experience, it's like they've actively tried to make it unpleasant to use πŸ˜‘

08.08.2025 10:45 πŸ‘ 8 πŸ” 1 πŸ’¬ 1 πŸ“Œ 1
Video thumbnail

Can Bluesky say every word in the dictionary?
I dunno but I plan to find out!

I made a website that tracks every single word said on bluesky (as of yesterday).

06.08.2025 15:51 πŸ‘ 616 πŸ” 138 πŸ’¬ 66 πŸ“Œ 69