Camberty
9 posts

Camberty
@Camberty1337
Brazilian Bug Hunter & Pentester LinkedIn: https://t.co/lsuI6l0Si0
Brazil Katılım Ocak 2024
64 Takip Edilen23 Takipçiler

easy bounty, se nao soubesse explicar com clareza poderia levar informative, show cambertyyy
KATRINASEC Offensive Security@katrinasecteam
New post blog from @Camberty1337 How a Simple Analysis Revealed an IDOR That Exposed User PII (third-party service) 🇧🇷[PT] katrinasec.com/blog/idor-api-… [EN] katrinasec.com/blog/en/idor-a…
English

March dump:
- 1 pentest (solo) + meetings @katrinasecteam
- Chile trip w/ my wife
- ~10k in bounties (a few collabs)
Findings:
- 2 IDORs (WordPress)
- Symfony Debug Bypass
- DOM XSS via postMessage()
- KYC bypass (iGaming)
- NGINX path traversal
good enough for me 😆




English

@dk4trin @intigriti Cadeee a Intigriti pra criar uma arte do home
Português

after a few months away from the @intigriti
Just scored a reward @intigriti, check my profile: app.intigriti.com/profile/dk4trin #HackWithIntigriti
English

huge thanks to @inspectiv
aos poucos voltando + collab @theWeertic top top top
shortscan > fuzzing > persistence fuzzing (+ theWeertic's tools)

English



Just scored a reward @intigriti, check my profile: app.intigriti.com/profile/dk4trin #HackWithIntigriti
enjoying the calm ....
English

@encrypt3dpoison Could you provide more details of the endpoint and the type of ATO?
English




