Thierry

1.4K posts

Thierry

Thierry

@7hierri

Katılım Şubat 2023
62 Takip Edilen1.4K Takipçiler
Sabitlenmiş Tweet
Thierry
Thierry@7hierri·
Wayback machine can help you see internal documents that are restricted. #Bug
English
10
73
756
40.6K
Thierry retweetledi
Coffin
Coffin@lostsec_·
Most people don’t realize how little real competition there is in bug hunting. A huge part of the younger generation is focused on gaming, while others spend most of their time scrolling Instagram, TikTok and similar platforms. Even within tech, a lot of people are tied up in web development, chasing projects, clients or frontend trends. And now with AI in the picture, many beginners get discouraged before they even start, thinking everything is already saturated or automated. But the reality is very different. The field is still wide open. If you stay consistent, actually learn the fundamentals and put in real effort, you’re already ahead of most people. The barrier to entry is much lower than it looks, and very few people are willing to go deep enough to stand out. That’s where the opportunity is. Take advantage of it. Build your skills. Stay focused. This space can genuinely change your life if you take it seriously.
English
69
119
1.2K
42.8K
Thierry
Thierry@7hierri·
@IdontCa31377684 Its bearer token that was accidentaly archieved. The bearer token had expiry date of 2035. You could easily access the user information's and exchanged messages during convasation with other people.
English
0
0
0
55
Thierry
Thierry@7hierri·
Information Disclosure Public Archives (Wayback) on app.reducted.com through /l/share/{conversation-uuid}/{bearer-token} via Path Wayback payload to check archived URL: Replace the place holder with your target in the payload. web.archive.org/cdx/search?url…
Thierry tweet media
English
2
6
92
5.1K
DuckywantDucky
DuckywantDucky@DuckyWantDucky·
Day 137/365 of the Until get 10.0 Critical report 📤 Reports Submitted:- 0 🟠 triaged - 2 🟦 new status - 🟤 Duplicate - 0 🟣 New -0 💰 Paid - $200 💻 Worked- 9 HOUR #BugBounty After 13 duplicate finaly i get my first bounty in hackerone 😅
DuckywantDucky tweet media
English
21
1
203
9.4K
Thierry
Thierry@7hierri·
@K10594Stanley That’s only possible with an adapter that supports monitor mode + packet injection. Linux alone won’t let you capture beacon frames or send deauth packets.
English
1
1
14
5.4K
Dr. bones💀
Dr. bones💀@K10594Stanley·
POV: The University WiFi is too low to submit your final assignment... Me on Linux: launching a deauth payload to kick the entire floor offline and claim the bandwidth💀😂😂💔
Dr. bones💀 tweet media
English
80
443
4.2K
124.8K
Thierry
Thierry@7hierri·
@4osp3l Contribution is acknowledged with a sign of reward. Saying acknowledging with mind, is crazy.
English
0
0
2
214
Gospel
Gospel@4osp3l·
site:com "We're sorry but Directus doesn't" -github -gitlab -google ( PII leak via /users )
Gospel tweet media
English
2
0
51
3.1K
Thierry
Thierry@7hierri·
@ks7X01 They asked me escalation with the data I have. Like why? They are saying email, phone number, names, configurations of devices of their over 2000+ employees not worthy reportable.
English
1
0
1
84
Ks7
Ks7@ks7X01·
@datafuel0 based on this this does not seem to be a company that cares about it's users privacy , i mean when you first use the app i guess they declare that your personal infos will be secured , in this case they are not and these infos can be sold in the dark web easily by an attacker
English
1
0
0
95
Thierry
Thierry@7hierri·
Found endpoint, returned PII containing (full names, emails, phone numbers, system configurations, thier phone type, and location). Submitted it, and they said "it is not that sensitive, show exploitation with those data" Fine. I asked myself what do i do? Unable to escalate.
Thierry tweet media
English
8
0
62
6.3K
Thierry
Thierry@7hierri·
Scan js files. Or do manual checking. The URL I got while reading a js file was just bootstrap URL by design. However, when i tried it it returned thousands or employees information. #bugbounty #informationDisclosure
Thierry tweet media
English
3
7
84
4.5K
Thierry
Thierry@7hierri·
I submitted a report INTENTIONALY out of the Scope. The CVSS score is 9.8+ and the triage instead of rejecting it or closing it, they changed my report title and report details to something even massive which is also still out of scope😎😎 lets see how it goes.
Thierry tweet media
English
4
1
36
3.7K
Thierry retweetledi
DinDinDin
DinDinDin@comores_11·
🔥 XSS Tip: Unicode Normalization Don't give up if <, >, " or ' are filtered ! Many apps normalize Unicode after the WAF/security layer. Some bypass variants (URL-encoded): 🔹 < ➔ %EF%BC%9C 🔹 > ➔ %EF%BC%9E 🔹 " ➔ %EF%BC%A2 🔹 ' ➔ %EF%BC%87 🔹 ` ➔ %EF%BD%80 For example, inject %EF%BC%9Cscript%EF%BC%9E and check if it reflects as