roughwire

859 posts

roughwire

roughwire

@roughwire

Security Engineer I love guitar more than info security ❤️

参加日 Mart 2015
485 フォロー中1.3K フォロワー
固定されたツイート
roughwire
roughwire@roughwire·
I am not a frequent bugbounty hunter. I am a pentester with some years of experience in infosec. I started bugbounties in March2020 on weekly basis. Today I have bought this baby with my bounties. A big thanks to @Hacker0x01
roughwire tweet media
English
33
23
661
0
Pomme
Pomme@pxmme1337·
« I respectfully asked you to disclosure my report and you moron mother fucker deducted my Reputation Point .... Bloody Mother Fucker..................... TAXI DRIVER..... »
English
14
8
124
6.9K
roughwire がリツイート
Six2dez 🇵🇸
Six2dez 🇵🇸@Six2dez1·
This is the first public release of Burp AI Agent. Expect rough edges. If something isn’t clear after reading the docs or you hit a bug, feel free to open an issue. Feedback and improvements are very welcome. Repo: github.com/six2dez/burp-a… Docs: burp-ai-agent.six2dez.com
English
4
28
160
15.6K
roughwire がリツイート
Behi
Behi@Behi_Sec·
IDOR Trick: If you're dealing with a UUID-based IDOR, try this: 00000000-0000-0000-0000-000000000000 This might expose default objects or unintended access.
English
7
69
684
28.2K
roughwire がリツイート
André Baptista
André Baptista@0xacb·
If you found a package.json file in the wild, you might find some internal packages vulnerable to a dependency confusion attack 👀 Check for it quicker using this cool new tool by JSMon: app.jsmon.sh/tools/npm-vali… 👇
English
7
87
368
22.8K
roughwire がリツイート
binaryboy
binaryboy@b1n4r1b01·
Brief info and POC for this week's Apple 0click iOS 18.6.1 RCE bug CVE-2025-43300 github.com/b1n4r1b01/n-da…
binaryboy tweet media
English
16
220
810
130.4K
roughwire がリツイート
Intigriti
Intigriti@intigriti·
💡 Tip! Injecting Log4Shell payloads is also possible in PDF files! eelyvy has a dedicated GitHub repository showing exactly how to craft your PDF payload file! 😎 🔗 github.com/eelyvy/log4jsh…
Intigriti tweet media
English
2
94
403
20.4K
roughwire がリツイート
André Baptista
André Baptista@0xacb·
Have you checked out @hadriansecurity's subwiz? It's a recon tool that uses ML to predict and resolve subdomains👇
English
3
53
251
15.7K
roughwire がリツイート
André Baptista
André Baptista@0xacb·
Ready to explore how AI is transforming Ethical Hacking? We've put together some introductory hands-on examples including: 🔍 Recon & Discovery Contextual subdomain enum, screenshot analysis, and content discovery ⚡ Exploit Development Automated vulnerability detection 🤖 Hackbots Using and extending open-source AI agents, leveraging Burp AI 🧠 Integrations & Plugins MCP servers for Burp Suite and Ghidra, Caido Shift Plugin and custom tool orchestration 🏆 CTF Challenges 3 simple scenarios to test your skills This repository contains a workshop guide, educational tools and scripts for learning how AI can be applied in offensive security. Check it out: github.com/ethiack/ai4eh
André Baptista tweet media
English
4
12
67
5.1K
roughwire がリツイート
André Baptista
André Baptista@0xacb·
DMARC can reveal more domains associated with a target. dmarc.live/info/<target-domain> allows you to find domains using the same DMARC record. Check it out 👇 There's also a python tool: github.com/Tedixx/dmarc-s…
English
10
203
1.1K
66.1K
roughwire がリツイート
André Baptista
André Baptista@0xacb·
A cool recon trick to find more targets is to check out CSP policies for juicy assets. csprecon can do this for you 👉 github.com/edoardottt/csp…
André Baptista tweet media
English
0
46
209
8.4K
roughwire がリツイート
xEHLE
xEHLE@xEHLE_·
New writeup: Early last month, @samwcyo, @sshell_, and I found a Django ORM injection in an online shooter game that let us steal cryptocurrency from the game's wallet. Read the blog post here: blog.p1.gs/writeup/2025/0…
English
35
78
268
19.7K
roughwire がリツイート
sw33tLie
sw33tLie@sw33tLie·
Many don’t realize they already have a powerful, fully autonomous, free hackbot on their computer. If you’re using Cursor, you’ve got it. Here's Cursor solving a @PortSwigger webacademy SQL injection lab! #bugbounty
English
14
30
256
30.5K
roughwire がリツイート
inzo
inzo@inzo____·
back to work with @zhero___ and a new vulnerability on @nextjs that led to CVE-2025-49826 both routers are impacted: app router: framework's cache is directly impacted on ISR pages, regardless of the presence of a CDN pages router: SSR pages only + requires a misconfigured CDN
inzo tweet media
English
4
20
218
53.3K
roughwire がリツイート
Paul Couvert
Paul Couvert@itsPaulAi·
Gemini CLI can automate your computer using MCP 🔥 Add Windows MCP (or macOS MCP) to Gemini CLI and you can tell it what to do autonomously. Gemini then takes control of your entire system to achieve the goal you've set. Links below
English
36
180
1.2K
131.6K
roughwire がリツイート
Hacksparo 🥷👾
Hacksparo 🥷👾@hack_sparo·
We’re cooked, guys. A new vulnerability has been discovered in sudo and you don’t even need to be in the sudo group to get root. I just tried it 👇
English
83
301
2.2K
243.1K