Angehefteter Tweet
XssFan
1.4K posts

XssFan retweetet
XssFan retweetet

For more info on how this class of bugs works check @Neodyme's blog
twitter.com/samczsun/statu…
#solana-account-confusions" target="_blank" rel="nofollow noopener">blog.neodyme.io/posts/solana_c…
samczsun@samczsun
tl;dr - Wormhole didn't properly validate all input accounts, which allowed the attacker to spoof guardian signatures and mint 120,000 ETH on Solana, of which they bridged 93,750 back to Ethereum.
English
XssFan retweetet

THE U UP INTERVIEW SERIES featuring @samczsun as our first and very gracious guest is now LIVE.
We discuss: deep philosophy, like the phenomenology of bug hunting, and the secret behind his identity.
medium.com/immunefi/the-u…
English
XssFan retweetet

Probably the best FREE interactive resource/courses for learning Solidity.
CryptoZombies is an interactive school that teaches you all things technical about blockchains, fundamentals of Solidity, web3.js.
cryptozombies.io
#blockchain #solidity

English
XssFan retweetet

A comprehensive list of known attack vectors and common anti-patterns.
github.com/sigp/solidity-…
#solidity #defi #blockchain #ethereum

English
XssFan retweetet
XssFan retweetet

A curated list of blockchain security Capture the Flag (CTF) competitions
github.com/blockthreat/bl…
#blockchain #ethereum #solidity

English
XssFan retweetet

3 months ago, I wrote my first smart contract
Today, I won the biggest web3 hackathon in Toronto and joined @musicoins as a blockchain developer 🚀
Here is my updated web3 developer roadmap
A mega thread 🧵
English
XssFan retweetet

October was - by far - my best #BugBounty month ever! I made 160k USD from 40 bugs across @Hacker0x01 and @synack with almost zero automation involved.
I usually don't talk about my bounty income, but I'm quite proud of my work TBH 🙂 So here's a little bit of statistics. (1/3)
English
XssFan retweetet
XssFan retweetet
XssFan retweetet

Misconfigured Reset password that leads to Account Takeover
by 'Aditya Sharma'
bounty: $5000
Aug 2021
@noob.assassin/5k-misconfigured-reset-password-that-leads-to-account-takeover-no-user-interaction-ato-e6a36b8ef183" target="_blank" rel="nofollow noopener">medium.com/@noob.assassin…
#AccountTakeover
#BugBounty #BugBountyTip #BugBountyTips
English
XssFan retweetet
XssFan retweetet

This blog post by @detectify is gold mine 🔥🔥
👉 10 Types of Web Vulnerabilities that are Often Missed
Thanks, @hakluke and @Farah_Hawaa
labs.detectify.com/2021/09/30/10-…
English
XssFan retweetet
XssFan retweetet

How to learn anything in computer science or cybersecurity effectively: betterprogramming.pub/5-steps-to-lea…
English
XssFan retweetet

Write-up on how a Facebook bug could have exposed your email/phone number to your friends. Quick and easy.😉
Bounty: $18250
#BugBounty
iamsaugat.medium.com/a-facebook-bug…
English
XssFan retweetet

New Module, Burp Suite! Learn this industry-standard tool for Web App Pentesting
🔴 Setup & Basics
🔴 Realistic hands-on labs
🔴 Repeater, Intruder, Extender, Modules
tryhackme.com/module/learn-b…
The first 2 rooms in this module are FREE!
💼 Part of our Jr Penetration Tester path

English




