Dark

57 posts

Dark banner
Dark

Dark

@DarkLorSy

Katılım Mayıs 2024
131 Takip Edilen7 Takipçiler
Shad0w
Shad0w@Itx_Shad0w·
My 5th duplicate in the last 3 days 🤧 Since I decided to avoid relying too much on automation this year and focus more on improving my manual hunting skills, I think I’ll have to deal with a lot of duplicates until I learn my lessons. Part of the process, I guess.
Shad0w tweet media
English
5
0
34
1.1K
R1s
R1s@R1s666·
Just got a reward for a vulnerability submitted on @yeswehack -- Cross-site Scripting (XSS) - Reflected (CWE-79). Waf bypass: <mctx%2FOnCoNtEnTvIsIbIlItYaUtOsTaTeChAnGe%3Dalert%601%61%09STYLE%3Ddisplay%3Ablock%3Bcontent-visibility%3Aauto>
R1s tweet mediaR1s tweet media
English
7
19
240
5.5K
Ethical Hacker
Ethical Hacker@whithat444·
Update: Now I’m able to trigger an `alert` after bypassing the WAF 😄 This is my first DOM XSS after spending many days learning and practicing. Special thanks to @YShahinzadeh @kobi_hk and all the bug bounty community members who share helpful resources 🙏 #BugBounty #XSS
Ethical Hacker tweet media
Ethical Hacker@whithat444

Found a DOM XSS sink via `location.href`. I can redirect to another domain, but I’m not yet able to achieve JavaScript execution. Need help with a bypass. Whoever helps me get successful JS execution gets a 50% bounty split. DM me I’ll share more details.

English
6
3
87
9.7K
Dark
Dark@DarkLorSy·
@Jos_eph19 I hate this word “Duplicate” if it reported why they did not fixed it and let us send repeted bugs !
English
0
0
3
224
King Josef
King Josef@Jos_eph19·
Hmm tough week
King Josef tweet mediaKing Josef tweet media
English
3
0
71
3.2K
Dark retweetledi
bugcrowd
bugcrowd@Bugcrowd·
Bug bounty hunters are putting AI to work. Researchers told @WSJ they’re using AI to support everything from recon to analysis and exploitation, with a growing focus on fewer, higher-value findings. But as Bugcrowd CEO @davegerryjr shared, human insight still plays a critical role in finding deeper, novel vulnerabilities, including “things that people have never seen before.” Read the full piece: wsj.com/pro/cybersecur…
English
1
4
44
3.1K
Dark
Dark@DarkLorSy·
@fattselimi POC is the controler for everything , if the report conatin a good thing send report otherwise find another thing
English
0
0
0
203
Fat
Fat@fattselimi·
Only Critical/Exceptional bugs seem to be prioritized lately by Bug Bounty Platforms, but what happens when AI-generated low-value reports are also marked as Critical/Exceptional? We end up prioritizing noise while real, impactful security issues are being neglected.
English
6
3
94
4.4K
Dark
Dark@DarkLorSy·
@yousefrol كيف اجربة ؟ انا حاليا استخدم claude الافضل هو ام claude ?
العربية
1
0
0
805
Yousef Rol
Yousef Rol@yousefrol·
جربتوا Codex Security ؟ 🛡️
Yousef Rol tweet media
Català
8
0
45
9.2K
Dark
Dark@DarkLorSy·
@oxflask You mean reached to shell ?
English
0
0
0
152
oxflask
oxflask@oxflask·
/etc/passwd , /etc/shadow
Filipino
12
0
50
4.8K
Dark
Dark@DarkLorSy·
@M7moudx22 Ture , I do not know what wrong with them in these days !
English
0
0
1
199
TraceX0
TraceX0@TraceX0_0·
FIRST BOUNTY UNLOCKED 😭🔥 Started my bug bounty journey with a HIGH severity report… still feels unreal 🫡 Months of NA, duplicates, failures & grinding finally paid off 🙏 God’s plan really different sometimes. @tsxninja200 @defronixacademy @thehacktivator #bugbounty
TraceX0 tweet media
English
22
5
297
10.2K
Dark
Dark@DarkLorSy·
@xau8k How many days normaly they back first response ?
English
0
0
0
14
Frozt Nova
Frozt Nova@FroztNova127·
@DarkLorSy Yes of course, i always verif every bug claude found manually
English
1
0
1
64
Dark retweetledi
bugcrowd
bugcrowd@Bugcrowd·
Friendly reminder: validate the bugs that AI is finding for you *before* submitting them. 😅
English
15
17
208
12.8K
Dark
Dark@DarkLorSy·
@FroztNova127 When you test it manually it is worked ?
English
1
0
2
307
Frozt Nova
Frozt Nova@FroztNova127·
Day 8 - Bug Bounty - Ask claude code to hunt bac and idor on specific feature - Claude found idor bug - Try connecting claude with caido mcp and analyze http request and look for bac and idor while im browsing manually Submitted: 6 Triaged: 0 Accepted: 0 Total bounty: 0$
English
5
2
77
3.1K
Dark
Dark@DarkLorSy·
@yusufthebdev If you do not mind could I dm you ?
English
0
0
0
14
Yousef
Yousef@yusufthebdev·
i’m getting numb to these daily hacks😪
English
1
0
5
203
Dark retweetledi
Amr Elsagaei
Amr Elsagaei@amrelsagaei·
If you found a real bug, and closed as NA/Duplicate/informative and you tried to reach out an got no response, publishing your finding with the users data is not right, remember the goal of working as hunter. We are protecting companies NOT helping blackhats to hack'em. Move on to another target.
English
11
5
66
6.8K