geo457

91 posts

geo457 banner
geo457

geo457

@Geocapri

Katılım Temmuz 2019
465 Takip Edilen26 Takipçiler
geo457
geo457@Geocapri·
@Behi_Sec Congratulations. Is this from Google AI VRP? If so could you make a writeup ?
English
1
0
0
389
Behi
Behi@Behi_Sec·
Google just rewarded me with a $12,000 bounty😃 Now, I'm closer to my $1m goal. Tip: Always validate your assumptions, as there are always exceptions.
Behi tweet mediaBehi tweet media
English
26
8
438
14.7K
geo457
geo457@Geocapri·
@hetmehtaa Yes but you will have to work in EST hours
English
1
0
1
108
Het Mehta
Het Mehta@hetmehtaa·
Is it possible to land a fully remote cybersecurity job in the US without holding a visa?
English
14
0
56
12.1K
YS
YS@YShahinzadeh·
my first bug using AI DIRECTLY to help me analyze JS fles. I've been always doing it by hand, but this case, I was able to find it with AI. Of-course It woudn't find it with "go anayze all JS files and give me bug" FYI: I could have found it purely by hand within few hours
YS tweet media
English
11
10
376
14.4K
geo457 retweetledi
Behi
Behi@Behi_Sec·
When I started bug hunting, I went from $0 to $3K/month in just 6 months. No secrets, no shortcuts, just a refined process. Here is the exact framework I followed: 🧵
English
9
52
366
18.9K
geo457 retweetledi
Bour Abdelhadi
Bour Abdelhadi@BourAbdelhadi·
🚀 Supaleak just launched! Vibe coders: you ship fast, but secrets leak into JS files. Supaleak detects + validates exposed secrets: - API keys, tokens, JWTs, Supabase keys, and many more. - Scheduled scans (daily/weekly/custom). - CSV export + email alerts. See what you discover. supaleak.com Thanks @martindonadieu for the guidance and the idea ♥️ shout out to @marclou 🙌
English
26
48
488
50.9K
Scott Wheeler
Scott Wheeler@sc0ttWheeler·
@shodanhq FYI had to copy the link and open in separate browser (used Firefox) and it worked!
English
1
0
1
2.5K
geo457 retweetledi
Luke Stephens (hakluke)
Luke Stephens (hakluke)@hakluke·
What an awesome bug and write-up by @brutecat. They found a way to leak any YouTube user's email address using only their public YouTube channel ID. The trick? Chaining two unrelated Google services: - YouTube (to get an ID) - Google Recorder (which mapped that ID to an email when sharing a recording) One issue that they faced was that when sharing a recording, it sent an email to the victim. To avoid this, they used extremely long recording names, which broke the email’s subject line and prevented the notification from being sent. This bug is a great example of cross-platform hacking, abusing logic across different services. One key takeaway for new hackers is that hacking is more effective when it’s goal-driven. Instead of just testing for common bugs like XSS or SQLi, focus on achieving a specific outcome (leaking email addresses) and find a way to make it happen. Link to the writeup 👇
English
2
22
161
12.1K
geo457 retweetledi
Somdev Sangwan
Somdev Sangwan@s0md3v·
bruh what were they thinking 😭
Somdev Sangwan tweet media
English
11
11
118
38.6K
hacker.house
hacker.house@hackerfantastic·
Did code signing certificates suddenly increase? Last year I had a code signing certificate renewal that was only $80, this year they are asking us for $400. Is this across the board or do we drop them for a cheaper code signer? Is there a letsencrypt yet for code signing?
English
5
9
39
21.7K
geo457
geo457@Geocapri·
@hackerfantastic As per the new regulation, the code signing cert’s private key should be generated, stored and used in FIBS 2 compatible USB token. So CAs are delivering the cert through a hardware token. That is why the price increased. it is not possible to get software based certs PFX any mor
English
1
1
5
2.1K
geo457 retweetledi
Nagli
Nagli@galnagli·
AI helps greatly translating JavaScript to "Human Readable Language", here's how I found a very straight forward DOM Based XSS in 2 minutes. #BugBounty
Nagli tweet media
English
13
89
575
101.5K
geo457 retweetledi
Youstin
Youstin@iustinBB·
If you want to find domains associated to an organization, you can explore DuckDuckGo's tracker-radar. It's a publicly accesible dataset that stores web tracking information, including domains operated by an organization. #L44" target="_blank" rel="nofollow noopener">github.com/duckduckgo/tra…
Youstin tweet media
English
13
467
1.7K
189K
geo457
geo457@Geocapri·
@LetsDefendIO CAA record : It allows you control which certificate authority can issue SSL/TLS certificate for your domain
English
0
0
0
43
LetsDefend
LetsDefend@LetsDefendIO·
Types of DNS Records
LetsDefend tweet media
English
4
153
652
37.6K