samael0x๐Ÿœ โ˜ 

135 posts

samael0x๐Ÿœ โ˜  banner
samael0x๐Ÿœ โ˜ 

samael0x๐Ÿœ โ˜ 

@nerdByt

0x4 | Bug Hunter Credited by Oracle People are the weakest link.

127.0.0.1 ๊ฐ€์ž…์ผ Temmuz 2022
294 ํŒ”๋กœ์ž‰41 ํŒ”๋กœ์›Œ
DeViL07
DeViL07@GodLDeViL07ยท
My first bounty on @intigriti ๐Ÿฅณ
DeViL07 tweet media
English
19
0
247
8K
samael0x๐Ÿœ โ˜ 
samael0x๐Ÿœ โ˜ @nerdBytยท
๐Ÿšจ URGENCY + VIRAL New Critical CVE ๐Ÿšจ CVE-2026-21643 โ€” Unauthenticated SQL Injection (9.1) Demo + PoC ๐Ÿ‘‡ youtu.be/dpCi0EW3N-s
YouTube video
YouTube
English
0
0
0
72
samael0x๐Ÿœ โ˜ 
samael0x๐Ÿœ โ˜ @nerdBytยท
Quick check: npm list axios If vulnerable โ†’ assume full compromise. Fix: โ€ข Downgrade immediately โ€ข Rotate ALL credentials โ€ข Rebuild system from clean image
English
0
0
0
25
samael0x๐Ÿœ โ˜ 
samael0x๐Ÿœ โ˜ @nerdBytยท
The real weapon = postinstall script Runs automatically when you do: โ†’ npm install No user interaction needed. Payload behavior: โ€ข Downloads cross-platform RAT โ€ข Executes in ~1.1 sec โ€ข Works on Windows / Linux / macOS
English
1
0
0
24
samael0x๐Ÿœ โ˜ 
samael0x๐Ÿœ โ˜ @nerdBytยท
๐Ÿšจ Axios supply chain attack (2026) โ€” this should scare every developer. 100M+ weekly downloads. No exploit. No click. Just npm installโ€ฆ and you're owned. ๐Ÿ’€ Attacker took over the maintainerโ€™s npm account. No code vuln. No zero-day. Just account compromise โ†’ full access.
English
1
0
0
64
samael0x๐Ÿœ โ˜  ๋ฆฌํŠธ์œ—ํ•จ
KNOXSS
KNOXSS@KN0X55ยท
๐Ÿšจ KNOXSS GIVEAWAY March 2026 โœ… Follow us โœ… Like and share this ๐ŸŽ Prize: KNOXSS Pro for 1 Month ๐Ÿ† Results: March 6th (3 winners) Want to find some vulns? Get one of our plans and test for #XSS consistently. Sign up now! ๐Ÿ˜€ knoxss.pro #BugBounty #PenTesting
KNOXSS tweet media
English
13
34
51
5.1K
KNOXSS
KNOXSS@KN0X55ยท
Prepare for the 1st GIVEAWAY of 2026! ๐Ÿคฉ Despite the service issues, the lack of true (or fake) testimonials and unprofitable usage of the majority (which is expected)... KNOXSS remains the most smart and comprehensive tool for #XSS with a loyal user base. Stay tuned! ๐Ÿ˜‰
KNOXSS tweet media
English
3
1
16
1.6K
samael0x๐Ÿœ โ˜ 
samael0x๐Ÿœ โ˜ @nerdBytยท
#ุงู„ุญู…ุฏุงู„ู„ู‡ Successfully worked with a major Enterprise vendor on a Responsible Disclosure. ๐Ÿž๐Ÿ”ฅ Issue resolved. Credit coming in next advisory. Patience is part of the process. ๐Ÿ›ก๏ธ
English
1
0
2
27
samael0x๐Ÿœ โ˜ 
samael0x๐Ÿœ โ˜ @nerdBytยท
Reflected XSS identified via unsanitized error parameter โ€” mapped to CVE-2020-19282. User input is reflected back without proper sanitization, allowing script execution in the browser. Minimal PoC used. Reported responsibly. Now waiting for Response ๐Ÿ•ถ๏ธ #RXSS #BugBounty
samael0x๐Ÿœ โ˜  tweet media
English
0
0
0
208
samael0x๐Ÿœ โ˜  ๋ฆฌํŠธ์œ—ํ•จ
Coffin
Coffin@lostsec_ยท
We have only one life, if we can't achieve what we desire, then what's the point of living it?
English
13
15
173
9.5K
samael0x๐Ÿœ โ˜  ๋ฆฌํŠธ์œ—ํ•จ
Nana Sei Anyemedu
Nana Sei Anyemedu@RedHatPentesterยท
WhatsApp End-to-End Encryption vs. Forensic Extraction Although WhatsApp uses end-to-end encryption to protect messages, calls, and shared media during transmission, this protection only applies while the data is moving between devices. Once the content reaches the device, it is stored unencrypted within WhatsAppโ€™s local databases and media folders. Out of the volumes of content, such as 733,543 WhatsApp messages, along with videos, audios, images, and documents. I was able to get a conversation between my kid sister @ama_Anyemedu in November 11, 2020. The chat preview shows a typical WhatsApp conversation recovered from a mobile forensic extraction. At the top of the chat, WhatsApp displays the standard banner โ€œMessages are now secured with end-to-end encryption.โ€ This banner simply means that when messages are being transmitted between two devices, WhatsAppโ€™s servers cannot read them because they are protected by encryption keys stored only on the usersโ€™ devices. However, end-to-end encryption does NOT protect data stored on the device itself. Mobile forensics work by accessing the phoneโ€™s internal storage, not by intercepting messages from WhatsApp servers. Once a device is unlocked or decrypted by the lawful extraction process, the tool can read the local WhatsApp databases stored on the device (usually the `msgstore.db` and related SQLite databases). This is why, despite the presence of the "end-to-end encryption" banner, the forensic tool is still able to extract: * Full chat history * Timestamps * Participants * Message contents * Attachments * Deleted messages (if still recoverable in the database) End-to-end encryption protects data in transit, not data *at rest* on the device. Forensic tools exploit lawful access to the deviceโ€™s decrypted file system, enabling them to parse and display the stored WhatsApp database, which is why you can see the complete message timeline, content, and timestamps on the right side.
Nana Sei Anyemedu tweet mediaNana Sei Anyemedu tweet media
English
103
612
2.6K
302K