CircleNinja
910 posts

CircleNinja
@CircleNinja
Information Security Engineer |Made @TheBugBot
For the community: 가입일 Aralık 2017
284 팔로잉1.9K 팔로워

@_jensec I think this guy wants to throw his opinion just for the sake of throwing one 😅
English

@Olamdeen how would you understand your target without spending time.
English

I disagree with this.
My own view is understanding your target not the time spent.
You might spent months on a target and not get anything unless you understand how the target work
Jenish Sojitra@_jensec
Success in bug bounty is directly proportional to time spent ⏰
English

@analogexits @perplexity_ai @AravSrinivas @henrymodis I disagree , maybe compared to others its good but not very best . Check it's thread ft in android app, there is no button yet to scroll down to bottom automatically once you reopen app and go to past convo
English

I just published How I tricked ChatGPT to act as a ‘person interviewing for CTO position’ and write real malware scripts. link.medium.com/vaQMIOEgANb
#chatgpt #openai #security
English

@CodeFryingPan @not_nang Actually the issue was that the founders got a bit arrogant in their wordings, if they had been a little humble by not quoting their TC etc , they would not have recieved this much public ire.
English

Don't invest a lot of time doing bug bounty or just web pentesting. Invest in learning about new tech, and other security domains .
The ocean is too big.. #bugbountytips
English

@Rafik0x63 @Rhynorater There is enough historical proof for the opposite. Infact, most of the early believers were martyrs. I would strongly doubt if someone would give up their life, until they have seen it. Also, 1 Corinthians 15:3-5.
English

@huzayyfah @Rhynorater In bible everything or for that matter any book has to been read in its context otherwise it would all be interpreted wrong. It clearly means God is just and won't be solely judged for the sins of father.
English

@Rhynorater Hey Justin, educate me please. Is there difference between how christians interprete the old testament and the new testament? Because in the OT, Ezekiel 18:20 says sth which sounds different from some of the things you shared above. My DM is open if you can elaborate
English
CircleNinja 리트윗함
CircleNinja 리트윗함

In this article @rez0__ , @Rhynorater and I managed to hack @GoogleVRP AI for 50,000$
Link 👇
landh.tech/blog/20240304-…
Enjoy 🤟🔥

English
CircleNinja 리트윗함

Stanford just hosted a hackathon. Over 1000 students from around the world came to build for 36 hours straight.
The reward? $100k+ in prizes.
Here are the winners and crowd standouts we saw at TreeHacks ‘24 @hackwithtrees (🧵):


English
CircleNinja 리트윗함

@glitchedgitz Best of luck , try to make it compete with Caido.
English
CircleNinja 리트윗함

Annoucing GRROXY!
2 years back I had a thought that we can have *BURP* alt. by simply using #proxify to capt. traffic, #ffuf as intruder, & so on...
So I created one. grroxy.com [Go+Js]
Inviting you all to join me for beta testing and exploring ideas together. Thx!
English

@jayesh25 How can we sign up again when email is already registered !
English

Bug Bounty Tips: 🐛💰 Here's a simple bug bounty tip for shopping site targets that can earn you some serious $$$$.
I've stumbled upon 10+ similar issues on shopping sites that allow guest checkouts 🛒.
Many overlook these issues because they require placing an order 📦. However, some services support cash on delivery 💸 or allow you to place a cheap order and then cancel it for a refund 🔄, making it worth adding to your checklist if other prerequisites are met.
Here's what to look for:
1️⃣ Target app that permits guest orders without creating an account 🕵️♂️
2️⃣ Target app doesn't require email verification for new account creation, or you've found an email verification bypass on sign-up 📧🔓
If these prerequisites are met, you can often find target apps with a misconfiguration that lets you access a guest user's order history by creating a new account with the same email used for the guest order.
Here's how it usually goes down:
1️⃣ Place an order on the site as a "Guest" and use the victim's email during checkout, e.g., victim@example.com 📩
2️⃣ The victim receives an email with the receipt 📧
3️⃣ As an attacker, sign up using the email victim@example.com assuming there's no email verification 🧑💻
4️⃣ Navigate to the account's order history page, and you might strike gold 🪙 by finding the previously made orders, leading to Order History and PII leaks 🔍📜
Takeaways: Don't ignore workflows involving payments; you might discover workarounds like cheap payments or cash on delivery 💡💳. Test for unusual flows and be ready for pleasant surprises with some lucrative bounties 💰💎 #BugBounty #CyberSecurity #HackerOne #BugBountyTips #SecurityTips #Bounties #infosecurity

English
CircleNinja 리트윗함

I just published Automating Port Knocking with Knockd Shellscript wrapper #security #hacking link.medium.com/Zr8kPeu1iEb
English

@SecureFlag @owasp I took owasp membership but i am unable to log into secureflag since @owasp mail isn't issued from 1 week. Pls help.
English

SecureFlag is proud to exhibit at the @owasp #GlobalAppSecDC in Washington DC on October 30th and 31st!🇺🇸
Join us at booth G-13 to discover the power of our #SecureCoding training platform and a preview of our upcoming releases.
See you there! 👋🏼
#SecureFlag #AppSec

English






