root@rebcesp

3.2K posts

root@rebcesp banner
root@rebcesp

root@rebcesp

@rebcesp

Bergabung Ekim 2018
927 Mengikuti200 Pengikut
Paul Seekamp
Paul Seekamp@nullenc0de·
I am at the point where my bug bounty findings are 100% agentic. I am just pasting in the scope and letting the agent run. It can do full external tests for all kinds of environments. A few people already have access, but if you want to try it, comment/DM. ​How does it work? 👇
Paul Seekamp tweet media
English
219
20
387
34.8K
root@rebcesp me-retweet
𝕷𝖎𝖓𝖆🌼
𝕷𝖎𝖓𝖆🌼@awamzzz·
¡Antes de que lo borren! Me enviaron esta hoja esta mañana. Según la persona que me la pasó, contiene los resultados de los primeros 24 partidos del Mundial. Pues juzguen ustedes.
𝕷𝖎𝖓𝖆🌼 tweet media
Español
1.4K
477
7K
3.6M
Damian Strobel
Damian Strobel@damian_89_·
@thedawgyg ravenx-cyberagent-v6.2,qwen3.6-27b-neo-code,gemma-4-26b-uncensored - for bug bounty hunting - extremly good, usually better then deepseek.
English
6
3
40
2.5K
dawgyg - WoH
dawgyg - WoH@thedawgyg·
What models are you having the most success with right now? Regardless of what your working on.
English
27
2
59
11.6K
root@rebcesp
root@rebcesp@rebcesp·
@4osp3l Sometimes it can be useful to leverage Google-owned domains, such as Google Cloud Shell, and keep a server running there, ready to receive any requests or data you need.
English
0
0
0
56
rokinot
rokinot@rokinot·
@lonelysloth_sec to run models at home? your best bet is 2x 5090 at this price range I think, but you're just below the b200 price. then a good enough storage for the 1T+ models. keep in mind parameters are up only, sooner or later you'll have to run 5T+, maybe 10T+
English
3
0
2
450
LonelySloth
LonelySloth@lonelysloth_sec·
If I wanted to spend 20K on a local LLM setup what should I do and what I could run? I can't ask Claude to help me do it as it will sabotage me.
English
12
1
34
4.6K
root@rebcesp me-retweet
Frank
Frank@frankdegods·
bro basically said "look for bugs that could exploit zcash" that's the prompt that found an exploit in a 10 billion dollar protocol
Frank tweet media
English
172
211
3.2K
414.3K
ElliotSecOps
ElliotSecOps@ElliotSecOps·
¿Cuántos hispanos hay activos en el bug bounty hunting? Es difícil no darse cuenta que la mayoría de los que participan son de EEUU, Europa o Sudeste asiático. Me gustaría ver más paisanos hispanos en el web3 security research, podemos trabajar en algo sumamente interesante.
Español
11
3
33
1.8K
root@rebcesp me-retweet
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
Claude code’s /security-review is just a Skill, and the whole prompt is in this repo It’s p generic and imo you can tailor it to each repo to language you’re scanning to get better results github.com/anthropics/cla…
English
18
159
1.1K
84.9K
root@rebcesp me-retweet
Geek Lite
Geek Lite@QingQ77·
给 Claude Code 装一套漏洞赏金和红队渗透技能包,51 个技能、574+ 报告模式、24 个漏洞类,一装就变身老练研究员。 github.com/elementalsouls…
Geek Lite tweet media
中文
18
132
826
41.7K
root@rebcesp me-retweet
Nicolas Krassas
Nicolas Krassas@Dinosn·
A Claude Code skill bundle for bug hunting and external red-team work - 51 skills, 15 slash commands, 574+ disclosed-report patterns curated across 24 vulnerability classes, plus enterprise identity + infrastructure attack matrices. github.com/elementalsouls…
English
3
144
654
26.7K
pira;)
pira;)@0xPira·
Criei uma ferramenta que: - Coleta rotas, APIs, JS, DOM, screenshots, requests e responses - Recebe diferentes usuários e compara o comportamento entre eles - usa AI pra navegar pela aplicação interagindo como um usuário real - Entende telas, fluxos, ações disponíveis e contexto real - Guarda todo o contexto obtido em grafos de evidências - Faz múltiplos agentes debaterem por turnos sobre como prosseguir - Obriga cada agente a defender hipóteses com evidências reais. Eles tem 6 turnos pra convencer os outros que a ideia vale a pena. Cada um tem uma ""personalidade"" diferente - Manda as hipóteses aprovadas pra agentes especialistas por classes de vulnerabilidade - Usa skills de +10k linhas cada pra criar payloads, bypasses e validações de acordo com a aplicação - Tenta explorar a vuln - Se conseguir, volta pro debate pra pensar em possíveis chains com outras vulns Até agora tá trazendo resultados legais!! quem sabe nao deixo publico essa brincadeira
Português
18
2
196
9.7K
Fôrtûne
Fôrtûne@Fortune71227524·
@4osp3l Which model is doing the work, Claude Opus?
English
1
0
2
304
pira;)
pira;)@0xPira·
EU PERDI O VERIFICADO DO TWITTER KKKKKKKKKKKKKK TAVA TESTANDO FALHA NELE MAIS CEDO ACHO QUE DEU RUIM </3
Português
11
1
105
8.5K
root@rebcesp
root@rebcesp@rebcesp·
Acepte un proyecto inconcluso en aws react serverless no me guiaron ni nada, nunca había tocado aws para desarollar acepte el proyecto, muy duro al principio pero ahora que ya llevo más de 5 meses he aprendido un montón, sigo aprendiendo me gustó mucho.
Español
0
0
1
39
pira;)
pira;)@0xPira·
preciso estudar mas não consigo tirar o HACKING da minha cabeça o BUG BOUNTY está me CONSUMINDO 😭
Português
3
0
41
1.5K
root@rebcesp
root@rebcesp@rebcesp·
valdrá la pena esforzarse después de ver esto:
root@rebcesp tweet media
Español
0
0
1
47