0xjunwei
241 posts

0xjunwei
@0xjunwei
Always Learning | BSCP, CWES, GCIH, OSCP, OSWE



HackerOne accepted my Critical 9.8 vulnerability on Netlify. That's real work, real impact. Meanwhile Hack The Box won't give me the cert because my final report "doesn't meet their standard." or just didn't wanna to give me the cert while i achived 100pnts passing score. Brother, a real company validated the finding as CRITICAL. But HTB's exam says I'm not good enough? Certs are a scam i highly not recomend buying or passing them now as they are just useless with what ai is capable of doeing right now. The real exam is the field. and also tell me in the comments if you had similar experience . in the past


3/ final thought, folks: we need to become hardware wallet maxis _now_. Stop yolo-installing software. Stop executing random code. Stop handing LLMs (I'm looking at you, Claude) code-execution rights. Use hardware wallets. Keep keys off your daily machines. Triple-check domains. This will help your and my own sanity. also, if you care about not getting rekt (and you should lol), read SEAL Frameworks pls: frameworks.securityalliance.org PS: SEAL is funded _entirely_ by donations (and we're close to running out of donation money soon!), so please consider donating either via #donate" target="_blank" rel="nofollow noopener">securityalliance.org/donate#donate
(for the main SEAL org) or directly to us at SEAL 911: #donations" target="_blank" rel="nofollow noopener">github.com/security-allia…). Thanks, and see you on the other side.


For any base builder building on @baseapp if you are generating dynamic embedded preview. Always use a completely cache cleared incognito so that your newly updated image will render. Wasted half a day finding this bug....






















