RV
575 posts


@JatinBanga18 @InfoSecComm @ctbbpodcast @BugBountyHQ @gregxsunday @bountywriteups Security engineers at meta saved their ass from being fired lmao
English

I Found a Bug That Exposed Private Instagram Posts to Anyone.
@jatin.b.rx3/i-found-a-bug-that-exposed-private-instagram-posts-to-anyone-eebb7923f7e3" target="_blank" rel="nofollow noopener">medium.com/@jatin.b.rx3/i…
@InfoSecComm @ctbbpodcast
@BugBountyHQ @gregxsunday
@bountywriteups
#instagram #InfoSec #WebSecurity #CybersecurityNews
English

Introducing my Bug Bounty Masterclass. 100% free.
I've made $2,000,000+ finding security bugs. I spent the last year turning my methodology into a complete blueprint.
4 hours of video - foundations, reconnaissance, web proxies, hands-on challenges, and certification.
Finish it in a weekend and start hacking real-world applications 🐞
English

I made $25,000 from bug bounty programs in 2021 before I started my business.
I owe my career to hacking.
And I thank every single ethical hacker out there for doing what you do.
We'd all be cursed if you didn't help organisations close the holes in their security.
But most organisations still treat security as an afterthought.
Something to deal with "later" or "when we have budget."
I've made it a point to implement bug bounty programs for all my clients.
We put serious time and effort into making sure these programs deliver results.
When I worked at Zomato, we paid $2000 to a hacker who absolutely shattered our overconfidence.
Best investment we never planned to make.
That payment hurt at the time.
But you know what would've hurt more?
A massive data breach because we thought we were untouchable and assumed our security was perfect.
It wasn't and that hacker proved it.
To all the ethical hackers reading this:
I know the value you bring.
You're saving companies from disasters they don't even know are coming.
And long may this continue.
My take on where we're heading:
Organisations that don't invest in ethical hackers and bug bounty programs are playing Russian roulette with their reputation.
Eventually, your luck runs out.
So if you're a CTO who hasn't set up a proper bug bounty program yet, now would be a good time.
English

Account Takeover in Facebook mobile app due to usage of cryptographically unsecure random number generator and XSS in Facebook JS SDK ($66,000)
ysamm.com/uncategorized/…
English

how's he able to do this ? he's definitely persistent.
Youssef Sammouda (sam0)@samm0uda
$312,500 worth of stored/reflected XSS vulnerabilities in Meta’s Conversions API Gateway allowed Javascript code to run on any Facebook domain and millions of third-party websites. The flaw enabled zero-click Facebook account takeover and more: ysamm.com/uncategorized/…
English

Exploitation scenario??
host header = evil,target,com
#BugBounty #hackerone #idor #sqlinjection #bugbountytip #xss #injection

English

@abhinav_one Me with 3 year of BB experience got rejected for a triager role 🥲
English

Hot take: if you don’t have real bug bounty experience, you shouldn’t be doing triage. Not as a “final gatekeeper”, not even as the first filter.
A quick “Duplicate/N/A” from someone who’s never done bug bounty can wipe out weeks of work, money, and motivation.
Triage needs context. Without it, you don’t just miss bugs, you burn researchers out.
English


How to bypass Cloudflare WAF?
@FearsOff #bugbountytips #cloudflare #waf #bypass
1. Found an SQL injection but getting blocked by Cloudflare?
Here's a pro tip 😏

English

I live in India so according to PPP, I make equivalent $1,041,600 in states.
x.com/i/grok?convers…
Doing Bug bounty makes great sense looking at PPP when you are in low PPP countries but not so much when in states.
Rudy@Rudy4FutureTech
@_jensec 240k TC and that too without insurance, 401k, or any safety net. One flu, one triager in bad mood, one company dispute - income gone. No paid leave, no stability, no compounding equity. Damn that’s quite less unless you’re in LCOL.
English

@Phantom_07x_ @TeslaTheGod I guess market crash of cs because of the recent update
English
















