Bekziz

118 posts

Bekziz

Bekziz

@bektips321

Ethical hacker / Bug Bounty Hunter

Beigetreten Mayıs 2024
76 Folgt5 Follower
Tomma
Tomma@mimuluslarch·
Hey @grok remove the most powerful villain..👀
Tomma tweet media
English
288
193
11.2K
4.3M
Intigriti
Intigriti@intigriti·
@bektips321 Hi there, if the payment was marked 'Paid', it means it has been sent already. It can take up to 3-5 business days for it to arrive in your account. We hope this helps!
English
3
0
0
21
Bekziz
Bekziz@bektips321·
hey @intigriti I initially used my friend’s Wise account for withdrawal for a bounty, so the payment showed "paid" but was not received due to the name mismatch. Ive now updated my payment preference to my own bank account, but the funds have still not been transferred. need help
English
6
0
2
1.2K
Bekziz
Bekziz@bektips321·
@intigriti but mine did not go through. I then changed my payment preference to my own bank account, but the payment still hasn’t been initiated and the support team asked me for bank statement and i told my friend to send me his wise bank statement and i did send them i am waiting
English
0
0
0
15
Bekziz
Bekziz@bektips321·
@intigriti what I meant was that I initially used my friend’s Wise account for the payout, but later realized the Wise account name must match my Intigriti account name. Because of that, my payment was never actually processed to his Wise account. He received his own payout from our collab
English
0
0
0
10
Bekziz
Bekziz@bektips321·
@intigriti hey @intigriti, i don’t want to nag, but do you have an estimate for how long this process will take for my bounty withdrawal? The status still says “paid” even though I haven’t received the payment yet. I’ve already updated my payment preference to my own bank account.
English
1
0
1
34
Intigriti
Intigriti@intigriti·
@bektips321 Hi there! We're sorry to hear about this. We've looked into your case and can confirm that we're actively working on resolving this matter. In the mean time, we recommend you avoid reaching out and/or sharing any of your personal details with unofficial accounts.
English
2
0
6
1.1K
Bekziz
Bekziz@bektips321·
@666archhwh @intigriti i didn't say my friend was a scammer i said the scammer was the one that commented on my tweet that he is able to help me to resolve the issue on intigriti about the bounty payment issue
English
0
0
0
17
Bekziz
Bekziz@bektips321·
@666archhwh @intigriti i didn't say he is a friend i just trusted him but when he talks nonsense on DM about helping me fix issues on intigriti i know he is not helping and he is a scamemr
English
1
0
0
28
The Android root advocate
@bektips321 @intigriti You call him friend and then scammer. First you should admit he was not your friend in the first place. Then next time report only on official channels or by bounty platforms and never trust self claimed employees.
English
1
1
1
50
Bekziz
Bekziz@bektips321·
@intigriti ok understood. the scammer was asking me for personal details and claiming to work for Intigriti, but I didn’t believe him, especially since he was asking for money for his "help" thanks @intigriti, and I hope my issue can be resolved quickly. Thank you.
English
1
1
2
93
Bekziz
Bekziz@bektips321·
@intigriti what shall i do @intigriti i really need help it has been like 2 , 3 months without receiving my bounty
English
0
0
1
91
Bekziz
Bekziz@bektips321·
@4osp3l this is mostly informative
English
0
0
0
207
Gospel
Gospel@4osp3l·
F**k! I didn't look at the scope... they marked it as *OOS* "Password and account recovery policies, such as reset link expiration," but it does lead to ATO, still. I don't know why they added such in *OOS* You can definitely look out for it on your target ( might get accepted if not listed in *OOS* ) Tip - 1. Create a test account ( test@gmail.com ) 2. Logout, then do a *password reset* on *test@gmail.com* 3. Once you get the reset link, take note of it ( do not use it yet ) 4. Login back to *test@gmail.com* 5. Change email from *test@gmail.com* to *another@gmail.com* ( make sure email change is verified / successful ) 6. Logout from *another@gmail.com* 7. Attempt login to *test@gmail.com* ( results to "Invalid login", due to the email doesn't exist in the system, anymore ) 8. Now, go back to the *reset link* sent to *test@gmail.com* 9. Try to use it to set a new password. If successful, the account with the email *another@gmail.com*, password, will be changed. The old email address, although no longer valid for authentication, still retained account recovery capability. A realistic scenario - 1. An attacker gains temporary access to the victim's old email inbox or obtains a reset link. 2. The attacker requests a password reset and keeps the link. 3. The victim later updates their account email to a new address, believing the account is secured. 4. The attacker uses the old reset link to reset the password and regain full access.
Gospel@4osp3l

This vulnerability is an interesting one ( it leads to ATO )! I sent the report a few days ago. Once the report gets accepted, I'll share some tips. You might probably spot the same misconfiguration on your target! I've no idea of the severity ( could be an easy P2/P3 ).

English
12
9
81
7.3K
Vitaly Ⓥ 火
Vitaly Ⓥ 火@vstarbanks·
$500 to person who predicts correct score
Vitaly Ⓥ 火 tweet media
English
13.2K
632
9.8K
1.6M
Bekziz
Bekziz@bektips321·
Getting this kinds of notifications sucks
Bekziz tweet media
English
0
0
0
44
Bekziz
Bekziz@bektips321·
AI generated submissions are flooding bug bounty platforms, and it’s starting to show Real, well-researched reports are getting buried, triage times are getting worse, and signal to noise is at an all-time low. what are your thoughts @zseano how are they going to fix it
English
0
0
0
62