Abang

17.3K posts

Abang banner
Abang

Abang

@484nX

Go On, Move On, Stay Strong

Katılım Ekim 2023
687 Takip Edilen172 Takipçiler
Abang retweetledi
X
X@TheMsterDoctor1·
🧠🔥 CLAUDE “100% MODE” — PRO BUG BOUNTY SYSTEM ⸻ ⚙️ 1. MASTER SYSTEM PROMPT (CORE ENGINE) Paste this FIRST into Claude: You are an elite offensive security researcher operating at a top-tier bug bounty level. You think like a professional attacker but act strictly within authorized security testing. Your mindset: - You hunt broken assumptions, not just vulnerabilities - You prioritize real-world impact over theoretical issues - You think in systems, flows, and trust boundaries - You chain weaknesses into meaningful impact - You ignore noise and focus only on high-probability findings You are not a scanner. You are a strategist. --- CORE MODEL: 1. System Decomposition Break the target into: - APIs, frontend, backend, auth, background jobs, integrations 2. Trust Boundary Mapping Identify where the system assumes: - identity is valid - ownership is enforced - state is consistent 3. High-Value Zones Focus only on: - Access control (IDOR, privilege escalation) - Auth/session flaws - Business logic abuse - SSRF/internal access - Injection in non-obvious contexts - Race conditions 4. Edge Case Thinking - Type confusion - Missing/null values - Encoding tricks - Flow manipulation - Alternate formats 5. Chaining Always ask: → “How does this become critical?” --- EXECUTION: - Explain WHY something may be vulnerable - Provide precise, non-destructive testing strategies - Highlight validation signals - Think like a triager: clear, reproducible, impactful --- OUTPUT: 1. Attack Surface 2. Broken Assumptions 3. Top Vulnerability Hypotheses 4. Testing Strategy 5. Signals 6. Impact 7. Chains --- Stay within ethical, authorized testing only. ⸻ 🔁 2. THE 6-PHASE HUNTER LOOP (REAL SECRET) This is how top hunters think — you’ll run Claude through this loop every target. ⸻ 🔍 PHASE 1 — SYSTEM MAPPING Break this target into components and data flows. Where does user input enter and where is it trusted? ⸻ 🧠 PHASE 2 — ASSUMPTION BREAKING List all assumptions this system makes about: - identity - ownership - state - sequencing Which of these can be broken? ⸻ 🎯 PHASE 3 — HIGH-PROBABILITY BUGS Give ONLY top 5 real vulnerabilities likely to exist. Rank by likelihood and impact. No generic answers. ⸻ ⚔️ PHASE 4 — PRECISION TESTING Design exact step-by-step testing for the #1 vulnerability. Focus on: - edge cases - bypass techniques - validation signals ⸻ 🔗 PHASE 5 — CHAINING If this vulnerability is valid, how can it escalate? Combine with: - access control - logic flaws - race conditions ⸻ 💰 PHASE 6 — REPORT MODE Write a HackerOne-quality report: - Title - Summary - Steps to reproduce - Impact - Severity justification ⸻ 🎯 3. ELITE MICRO-PROMPTS (HIGH ROI) Use these to zoom into specific bug classes: ⸻ 🔐 Access Control Killer Find non-obvious IDOR and privilege escalation paths. Focus on multi-tenant and indirect references. ⸻ 🧾 Business Logic Breaker Break this workflow. Where can steps be skipped, repeated, or abused? ⸻ 🌐 SSRF Hunter Where can the server be forced to make internal requests? Think beyond obvious URL inputs. ⸻ 🔑 Auth & JWT How can identity or roles be confused or escalated? ⸻ ⚡ Race Conditions Where can timing or parallel requests break consistency? ⸻ 💉 Injection (Advanced) Where could injection exist in non-traditional inputs? (JSON, filters, background jobs) ⸻ ⚙️ 4. REAL-WORLD STACK (YOUR FLOW) You already use tools — here’s how Claude fits: Your stack: •gau / waybackurls •httpx •nuclei (optional) •Burp Flow: 1.Collect endpoints 2.Feed into Claude: Analyze attack surface: [paste endpoints] 3.Run 6-phase loop 4.Only test top 1–2 hypotheses 5.Validate manually 6.Generate report ⸻ 💀 WHAT “100% MODE” ACTUALLY MEANS This is the difference: Average Hunter100% Mode Runs toolsBreaks systems Tests payloadsBreaks assumptions Finds low bugsChains into critical Spams reportsWrites 1 winning report
X tweet media
English
2
7
38
1.7K
Abang
Abang@484nX·
@Reuters masalahnya kaya juga nggak orang Indonesianya dari eksploitasi hutan besar2an begini. yang kaya cuma para cukong, mafia, pejabat dan kroni2nya termasuk para buzzer brengsek itu.yang lainnya masih sama aja gak berubah bahkan tambah parah, buktinya harus dikasih mbg.. gt kali ya?
Indonesia
0
0
0
8
Reuters
Reuters@Reuters·
Forest loss in Indonesia surged by 66% in 2025, hitting its highest rate in eight years as a result of weak environmental protections and an ambitious food and energy self-sufficiency drive, an environmental group said reut.rs/4v1KCpB
English
40
1.3K
1.8K
387K
Abang retweetledi
Anies Rasyid Baswedan
Anies Rasyid Baswedan@aniesbaswedan·
Ini adalah alarm yg perlu jd perhatian. Bpk Presiden di Jepang baru saja mengatakan kita harus melindungi hutan, bahkan reforestasi masif, karena Indonesia adalah paru2 bumi. Semoga jadi perhatian jajaran beliau, pemerintah daerah, serta korporasi2 yg mengeksploitasi hutan kita.
Reuters@Reuters

Forest loss in Indonesia surged by 66% in 2025, hitting its highest rate in eight years as a result of weak environmental protections and an ambitious food and energy self-sufficiency drive, an environmental group said reut.rs/4v1KCpB

Indonesia
256
8.9K
25.5K
256.9K
Abang retweetledi
Hunter
Hunter@HunterMapping·
🚨Alert🚨 CVE-2026-21643 (CVSS 9.1) : Pre-Authentication SQL Injection in FortiClient EMS 7.4.4 🧐Detail : bishopfox.com/blog/cve-2026-… 📊 4K+ Services are found on the hunter.how yearly. 🔗Hunter Link:hunter.how/list?searchVal… 👇Query HUNTER : product.name="FortiClient Endpoint Management Server" 📰Refer:bleepingcomputer.com/news/security/… fortiguard.fortinet.com/psirt/FG-IR-25… #hunterhow #infosec #infosecurity #OSINT #Vulnerability
Hunter tweet media
English
5
75
314
17K
Abang retweetledi
shakquraa
shakquraa@shakquraa·
🔥 bug bounty resource: Galaxy BugBounty Checklist — a massive, structured playbook covering everything from XSS, SSRF, APIs to cache bugs & more. Not just a checklist… it’s basically a mindset for systematic hunting. If you're doing bug bounty and missing bugs, this might be why 👇 github.com/0xmaximus/Gala… Use it smartly, not blindly. That’s where the real wins are. #BugBounty #InfoSec #CyberSecurity #WebSecurity
English
1
49
218
7.5K
Yuk Berisik
Yuk Berisik@sharpandshark·
DETIK-DETIK TRAGEDI: Ketika 'Kenakalan' Berubah Menjadi Bahaya Maut 🚨🚨🚨 ​"Video ini bukan sekadar tentang anak nakal, tapi tentang potensi bahaya fatal yang sering kita sepelekan. ​Terlihat jelas bocah tersebut tertawa sambil menyayat dinding balon. Padahal, istana balon sangat bergantung pada stabilitas tekanan udara. Begitu bocor, material berat tersebut akan mengempis dan bisa mengurung anak-anak di dalamnya.
Indonesia
1.1K
664
2.7K
823.2K
Abang retweetledi
GitLawb
GitLawb@gitlawb·
new version of OpenClaude is up! v0.1.5 is released.
GitLawb tweet media
English
123
447
6.6K
680.3K
Abang
Abang@484nX·
@depangsube @mickeymrdt nah itu yang bikin heboh dengan bocornya code2 claude, mungkin bisa dimanfaatkan
Indonesia
0
0
0
141
👑
👑@depangsube·
@484nX @mickeymrdt bikin sistem agentic dengan prompt engineering yang bagus jg susah bro. model bagus udah pasti keharusan, tp sistem agentic (software) yang bagus jg penting banget. saya lagi bikin sistem agentic jg saat ini. jadi ngerti kompleksitas nya gimana.
Indonesia
1
0
0
219
MickΞy M
MickΞy M@mickeymrdt·
Gila sih, ini bener-bener plot twist paling insane di industri tech tahun ini. ✨Bayangin, perusahaan sekelas Anthropic yang bangun Claude yang notabene saingan berat OpenAI malah kena blunder yang sifatnya human error banget cuy ckckck Nih, gue ceritain kronologinya biar lo tetep update tapi nggak pusing sama istilah teknisnya: 1. The 4 AM Blunder Jadi jam 4 pagi, tim Anthropic nge-push update buat tool mereka namanya Claude Code. Eh, ada satu file buat debugging (buat nyari error) yang lupa dihapus dan ikut ke-upload. Masalahnya, file itu isinya 512.000 baris kode rahasia mereka. Itu ibarat lo nggak sengaja nge-share resep rahasia Krabby Patty ke grup WhatsApp komplek. 2. Viral dalam Itungan Menit Ada researcher namanya Chaofan Shou nemuin file ini, terus langsung di-post di X (Twitter). Dan Boom! 21 juta orang ngelihat. Sebelum tim Anthropic bangun tidur dan sadar kalau mereka "telanjang" di internet, kode itu udah di-downloaddan di-copy ribuan orang ke mana-mana. 3. The "Genius" Move dari Korea Pas Anthropic mulai panik dan kirim surat ancaman (DMCA takedown) ke mana-mana buat hapus kodenya, muncul seorang developer dari Korea namanya Sigrid Jin. Dia ini user Claude paling loyal sedunia (katanya pake 25 miliar token setahun!). Karena takut kena masalah hukum tapi pengen kodenya tetep ada, dia ngelakuin hal paling mad lad: ✅Dia nulis ulang seluruh kode itu pakai bahasa pemrograman Python dari awal sebelum matahari terbit. ✅Logikanya gini: Kalau lo cuma copy-paste, itu melanggar hak cipta. Tapi kalau lo tulis ulang pakai bahasa lain dengan gaya lo sendiri, itu dihitung karya kreatif baru. Jadi tim legal Anthropic nggak bisa nyentuh dia! 4. Bintang Baru di GitHub Proyek "re-write" dia yang dinamain claw-code langsung meledak. Cuma dalam waktu singkat, dapet puluhan ribu starsdi GitHub (ini kayak dapet jutaan likes tapi buat anak koding). Dia bahkan nulis ulang lagi pake bahasa Rust biar makin kenceng performanya. 5. Permanen dan "Undercover" Fail Sekarang kodenya udah di-upload ke platform decentralized yang nggak bisa dihapus sama siapa pun. Basically, rahasia dapur Anthropic udah jadi milik publik selamanya. Stay Ciakakakaka😁😁
MickΞy M tweet mediaMickΞy M tweet media
Indonesia
76
569
4.2K
206.4K
Abang
Abang@484nX·
@depangsube @mickeymrdt sayangnya modelnya gak dapet hehe.. tapi apakah skillnya mengandung data training? tapi sayangnya gak
Indonesia
1
0
0
714
👑
👑@depangsube·
@484nX @mickeymrdt jangan gitu mikirnya. kalau dpt agentic sistem kyk punya claude code, bisa jadi glm, minmax, kimi dll, punya product yang mirip kyk antropic dengan harga lebih murah dengan kualitas acceptable.
Indonesia
1
0
0
805
Abang retweetledi
Het Mehta
Het Mehta@hetmehtaa·
Will Claude soon impact all bug bounty hunters?
Het Mehta tweet media
English
4
3
74
7.3K
Abang retweetledi
airplanestar 🏴‍☠️
airplanestar 🏴‍☠️@airplanestar_·
Leon Lin@LexnLin

HERE IS Claw Dev (claude code but free) An opensource cli agent with local model support(ollama) + different providers: anthropic, gemini, grok, groq (You aren't getting any claude models for free) github.com/Leonxlnx/claw-… btw inspired by claude code. download fast ;) if there are bugs please write an issue or PR or reply here and a full tutorial is in the readme (please read first before asking questions or just ask your ai with the repo as context)

English
0
4
41
11.5K
Abang
Abang@484nX·
@lynxluna tapi lumayan skillnya juga bocor, kalau skillnya itu mengandung data training maka lumayan buat upgrade model2 opensource
Indonesia
0
0
0
329
Dane24
Dane24@Dane2415·
@484nX @rigaz29 @mickeymrdt Ya enggak lah secanggih-canggihnya rtx 5090 tetep kalah sama custom gpu mereka sendiri, toh modelnya butuh ratusan komputer data center
Indonesia
1
0
0
596
Abang
Abang@484nX·
@rigaz29 @mickeymrdt sayangnya, kalau modelnya juga dapet maka per-AI an akan collapse, dan kita bisa bikin platform sendiri yang sedahsyat opus sonnet
Indonesia
1
0
0
1.5K