yso

479 posts

yso banner
yso

yso

@0a_yso

My crime is that of curiosity. Bug Bounty, Security Engineering, Dev and more Presented at Area41, DEF CON main stage, DEF CON Car Hacking Village

Zurich, Switzerland Katılım Şubat 2019
161 Takip Edilen649 Takipçiler
Sabitlenmiş Tweet
yso
yso@0a_yso·
💰 Just 10 public bug bounty reports paid researchers $26,075,042 - all in Web3/DeFi. These are some of the biggest public bounty payouts ever. We're collecting them - and hundreds more - at VulnIndex, now live: vulnindex.ys0.dev 1/6 #BugBounty #DeFi #AppSec #hacking
yso tweet media
English
3
15
93
6.2K
yso
yso@0a_yso·
@alisaesage Just go ahead. Give us a series of tweets with your opinion on this situation
English
0
0
9
3.3K
Alisa Esage Шевченко
Actual zero day vulnerability researcher and exploit developer here. Top-of-the-field skills across Browser full-chain, hypervisor VM escape, OS kernel and baseband on record since before AI existed. And a proud solo owner of a zero day intelligence company. Anthropic just dropped the mic on my industry. Where do I begin…………
Anthropic@AnthropicAI

Introducing Project Glasswing: an urgent initiative to help secure the world’s most critical software. It’s powered by our newest frontier model, Claude Mythos Preview, which can find software vulnerabilities better than all but the most skilled humans. anthropic.com/glasswing

English
69
37
761
241.9K
yso
yso@0a_yso·
The most sad thing in #bugbounty is when management changes, bounties decrease and inconsistency in the payouts (if any) are present again. Why, just why would you sacrifice your asset?
English
0
0
0
74
yso
yso@0a_yso·
Or repeat them if you re a bug bounty hunter or pentester (on authorized targets of course)
English
0
0
0
122
yso
yso@0a_yso·
"It's internal, we're fine" is how you get breached. I just used a simple SSRF + OpenAPI hints to elevate privileges and leak a customer DB. Your internal documentation shouldn't be a roadmap for attackers. Don't repeat mistakes of others P.s. bb subm #BugBounty #AppSec #infosec
English
2
1
30
1.7K
Damian Strobel
Damian Strobel@damian_89_·
Is there a public github repo with bug bounty programs that are self hosted (except Salesforce, FB, MS, Apple, ...)?
English
2
2
37
4.7K
Damian Strobel
Damian Strobel@damian_89_·
And let me know what you think via PM (or maybe I missed something you want to add to the article, feel free)
English
1
0
1
915
Damian Strobel
Damian Strobel@damian_89_·
Interested in Spring Boot Actuators in the context of bug bounty hunting? I wrote something - nothing new - just some insights ;) Article: dsecured.com/en/articles/sp… Retweet appreciated! Dont expect 0days or some fancy magic.
English
4
77
258
13.9K
yso
yso@0a_yso·
@AnmolSecSavvy I am away on vacation, and I think there is a bug somewhere in the representation. Will fix it and then let you know
English
1
0
1
31
yso
yso@0a_yso·
💰 Just 10 public bug bounty reports paid researchers $26,075,042 - all in Web3/DeFi. These are some of the biggest public bounty payouts ever. We're collecting them - and hundreds more - at VulnIndex, now live: vulnindex.ys0.dev 1/6 #BugBounty #DeFi #AppSec #hacking
yso tweet media
English
3
15
93
6.2K
yso
yso@0a_yso·
@0x0SojalSec What kind of nonsense did I just read? Please prove me wrong
English
0
0
2
234
Md Ismail Šojal 🕷️
Md Ismail Šojal 🕷️@0x0SojalSec·
(LLM injection) Bypass payment in Chat GPT - @VulnRAM/llm-injection-bypass-payment-in-chat-gpt-34b194d1210a" target="_blank" rel="nofollow noopener">medium.com/@VulnRAM/llm-i…
English
2
20
124
8K
Magn4
Magn4@Magn4_·
@0a_yso Access, and i loooove the initiative. Great work 🙌🙌
English
1
0
0
84
yso
yso@0a_yso·
Parsed 12k+ bug-bounty write-ups & blogs (and counting 24/7) and mapped each to CWE + language. Quick hits: • ~60% of RCEs happen in PHP/JS • >50% of GraphQL bugs are plain access-control issues Free site coming soon - reply "access" for an early invite! #bugbounty #hacking
yso tweet mediayso tweet media
English
139
22
232
24.9K