RV

575 posts

RV banner
RV

RV

@0xInfernal

🐧 Noob!

Katılım Mayıs 2017
771 Takip Edilen98 Takipçiler
RV
RV@0xInfernal·
@ertugrulphp Thanks for letting us know!
English
0
0
2
324
RV
RV@0xInfernal·
@galnagli There's some sort of error at quiz section, these answers were auto-selected. Btw, thanks for sharing your valuable knowledge with us.
RV tweet media
English
0
0
1
355
Nagli
Nagli@galnagli·
Introducing my Bug Bounty Masterclass. 100% free. I've made $2,000,000+ finding security bugs. I spent the last year turning my methodology into a complete blueprint. 4 hours of video - foundations, reconnaissance, web proxies, hands-on challenges, and certification. Finish it in a weekend and start hacking real-world applications 🐞
English
111
338
2K
245.5K
RV
RV@0xInfernal·
@moury_rajat I really wonder who was that hacker on H1?
English
0
0
0
30
rajat moury
rajat moury@moury_rajat·
I made $25,000 from bug bounty programs in 2021 before I started my business. I owe my career to hacking. And I thank every single ethical hacker out there for doing what you do. We'd all be cursed if you didn't help organisations close the holes in their security. But most organisations still treat security as an afterthought. Something to deal with "later" or "when we have budget." I've made it a point to implement bug bounty programs for all my clients. We put serious time and effort into making sure these programs deliver results. When I worked at Zomato, we paid $2000 to a hacker who absolutely shattered our overconfidence. Best investment we never planned to make. That payment hurt at the time. But you know what would've hurt more? A massive data breach because we thought we were untouchable and assumed our security was perfect. It wasn't and that hacker proved it. To all the ethical hackers reading this: I know the value you bring. You're saving companies from disasters they don't even know are coming. And long may this continue. My take on where we're heading: Organisations that don't invest in ethical hackers and bug bounty programs are playing Russian roulette with their reputation. Eventually, your luck runs out. So if you're a CTO who hasn't set up a proper bug bounty program yet, now would be a good time.
English
1
0
0
46
RV
RV@0xInfernal·
@4osp3l Years of dedication obviously.
English
0
0
1
104
RV
RV@0xInfernal·
@mugh33ra Check for subdomain takeovers or XSS to chain it, in case you can only control the “evil” at the injection.
English
0
0
2
211
Abhinav
Abhinav@abhinav_one·
Hot take: if you don’t have real bug bounty experience, you shouldn’t be doing triage. Not as a “final gatekeeper”, not even as the first filter. A quick “Duplicate/N/A” from someone who’s never done bug bounty can wipe out weeks of work, money, and motivation. Triage needs context. Without it, you don’t just miss bugs, you burn researchers out.
English
7
5
59
7.6K
RV
RV@0xInfernal·
@Freyxfi Please redact the private program's name from the write-up.
English
1
0
4
730
Frey
Frey@offsecrunner·
Write-up on how to find criticals. Enjoy
Frey tweet media
English
17
12
154
12.5K
Philippe Delteil
Philippe Delteil@PhilippeDelteil·
Ticket opened in @Hacker0x01. Almost a year ago and no more communication nor resolution
Philippe Delteil tweet media
English
6
0
39
3.9K
Fir3Drvgon
Fir3Drvgon@A_EL_Kennouch·
@k_firsov @FearsOff Cloudflare blocks me whem trying to use Burpsuite any tip on how to bypass that
English
3
0
7
3.4K
RV
RV@0xInfernal·
@OreoB1scuit Only offensive security is clean. Burp, ec-council etc not
RV tweet media
English
1
0
4
239
Biscuit
Biscuit@OreoB1scuit·
Tell me a better truth in cybersecurity than this.
Biscuit tweet media
English
11
10
246
19.9K
RV
RV@0xInfernal·
@4osp3l Tbh, X numbers of program matters where you spend a lot of time. Platforms have their pros and cons.
English
0
0
1
554
Gospel
Gospel@4osp3l·
I know i can hit $100K in a year if i focus on the right programs; what do you think is the better combo, YWH + H1, YWH + BC, or YWH + big external programs like google, microsoft, e.t.c ?
English
10
5
123
14.4K
RV
RV@0xInfernal·
@Behi_Sec Report writing
English
0
0
2
390
Behi
Behi@Behi_Sec·
What's one skill every bug hunter should master besides finding bugs?
English
12
1
47
8.9K
Fat
Fat@fattselimi·
hello sqli my old friend ^_^
Fat tweet media
English
12
6
204
18.2K
RV
RV@0xInfernal·
@Behi_Sec Also, 1111s instead of 000s
English
0
1
7
521
Behi
Behi@Behi_Sec·
IDOR Trick: If you're dealing with a UUID-based IDOR, try this: 00000000-0000-0000-0000-000000000000 This might expose default objects or unintended access.
English
7
69
686
28.2K
RV
RV@0xInfernal·
@_jensec I thought you’re not Indian. Btw great achievement 🙌
English
0
0
0
74
Jenish Sojitra
Jenish Sojitra@_jensec·
I live in India so according to PPP, I make equivalent $1,041,600 in states. x.com/i/grok?convers… Doing Bug bounty makes great sense looking at PPP when you are in low PPP countries but not so much when in states.
Rudy@Rudy4FutureTech

@_jensec 240k TC and that too without insurance, 401k, or any safety net. One flu, one triager in bad mood, one company dispute - income gone. No paid leave, no stability, no compounding equity. Damn that’s quite less unless you’re in LCOL.

English
7
2
121
16.2K
RV
RV@0xInfernal·
@Suryesh_92 Same to you bro. But what’s that; is it fafda?
English
1
0
0
17