szd

527 posts

szd

szd

@Intrusio

J'aime le bounty.

Katılım Temmuz 2012
522 Takip Edilen350 Takipçiler
Lupin
Lupin@0xLupin·
WE DID IT ! WE RAISED $5.9M PRE-SEED 🥳🎉🎉
English
77
41
407
33.5K
doomerhunter (Victor Poucheret)
doomerhunter (Victor Poucheret)@DoomerOutrun·
Honored to receive the MVH award (Most Valuable Hacker) & the BIGGEST bounty Epic Games ever paid: $130,000! 🏆💰 Leaving the @EpicGames Live Hacking Event with a surreal win with my teammates with @Blaklis_ and Snorlhax. 🤯 My first LHE was with Epic in 2022, so this closes the loop perfectly. Having my parents there to see it meant the world. ❤️ Oh, and I beat Popeye at arm wrestling. 💪 What a month!
doomerhunter (Victor Poucheret) tweet mediadoomerhunter (Victor Poucheret) tweet mediadoomerhunter (Victor Poucheret) tweet mediadoomerhunter (Victor Poucheret) tweet media
English
30
7
328
22.5K
doomerhunter (Victor Poucheret)
doomerhunter (Victor Poucheret)@DoomerOutrun·
I am now officially a @Hacker0x01 ambassador 🚀 French hunters, beginners or veterans : How about an upcoming hacker meetup ? What would you prefer ? (talks, hacking event, exploration/research...)
doomerhunter (Victor Poucheret) tweet media
English
10
7
123
5.6K
szd
szd@Intrusio·
@Icare1337 See you there bro 😉
English
1
0
0
66
Icare
Icare@Icare1337·
Here we go ! #leHack
Icare tweet media
English
3
0
31
1.2K
HackerOne
HackerOne@Hacker0x01·
The security research community in Europe and the Middle East just got even stronger. Say hello to these new HackerOne Brand Ambassadors: 🇦🇿 @AzeriumD34132 (Azerbaijan—new club!) 🇧🇪 @dropn0w & @hgreal1 (Belgium—new club!) 🇩🇰 @mthirup (Denmark—new club!) 🇮🇹 @Al7eX91 & @Ciper_942 (Italy—new club!) 🇱🇧 @hasansheet (Lebanon—new club!) 🇸🇪 @joaxcar (Sweden—new club!) 🇳🇱 @yoerivegt (Netherlands) 🇫🇷 @DoomerOutrun (France) 🇵🇹 @secgus (Portugal) 🇹🇷 @jusxing (Turkey) These ambassadors will fuel research, mentoring, and live events across the region. We’re glad they’re here! Check out the program: bit.ly/3lMs6lO #AppSec #EthicalHacking #H1Club
HackerOne tweet media
English
8
11
81
25.4K
Jobert Abma
Jobert Abma@jobertabma·
Hey hackers! We're running a beta for Hai for Hackers, our AI security agent. If you're interested, please reply with your HackerOne username (we will probably limit to ~100 hackers for now). After it's been enabled, you can start using it by clicking the Hai button in the top right corner of the app. It’s free to use (with a limited daily budget for now). It is like any other AI you’ve interacted with, with the added benefit that it has access to a whole bunch of HackerOne data, like reports and programs. We’re shipping improvements to Hai almost every day. Here are some neat use cases: - “take all the learnings from STÖK, jhaddix, and nahamsec's recon strategy and build one for me!” - “write a python script for a typical recon process” - “i need an XSS payload that doesn’t use single or double quotes” - “my XXE payload doesn't call back to my server, what could go wrong?” - “write a response for report #133337” The beta also comes with Hai Plays for you, which allows you to build your own security agents in HackerOne. You can create them at hackerone.com/settings/hai_p…. Some of the cool use cases we’ve seen so far are: - write reports with minimal input from you (efficiency++!) - convert reports into blogposts with a single prompt - AI mentor to give feedback about your communication and increase the likelihood of a reward In the background we’ve been working on agentic behavior, which we expect will soon come to Hai for Hackers as well. These AI agents can act like your hacking buddy and hack alongside you. We’ll keep you in the loop on our progress.
Jobert Abma tweet media
English
293
36
243
53.6K
Blaklis
Blaklis@Blaklis_·
My french team, for the world cup, and in collaboration with my wife, printed me a hoodie with a redacted payload on it. That bug was super fun, but quite hard to exploit! If encoded words, RFC2047 and so on are strange words to you, @garethheyes presented at the same time their research about emails parsing, which explains much better and much deeper the things I'm talking about in my talk : portswigger.net/research/split… t.co/jB0vOfWEQb Worth a read/look! :) #bugbounty
YouTube video
YouTube
Blaklis tweet mediaBlaklis tweet media
Bug Bounty Village@BugBountyDEFCON

@Blaklis_ squeezed a pre-auth RCE payload into exactly 64 chars using MIME-encoded magic, a short web root, and some RFC sorcery. “It works. Don’t ask me why. I even printed it on a T-shirt.” Full talk → youtu.be/4yJQz2jXV-E #BugBounty #DEFCON #AppSec #BBV

English
9
10
134
13.2K
szd
szd@Intrusio·
@yeswehack Où est ce qu'on signe ? 🎅
Français
0
0
2
94
YesWeHack ⠵
YesWeHack ⠵@yeswehack·
Before tonight's big feast, take a glimpse into our Christmas parties ✨ In London, the team gathered for an exciting urban golf session ⛳, while in Singapore, it was boat time, wandering the Straits of Singapore 🚤 Parisians had to save Gotham City and escape the Joker's lair 🃏, and a medieval role-playing game entertained our team in Rouen! ⚜️ Now, we won't delay your preparations any longer... and wish you a wonderful Christmas Eve! 🥂
YesWeHack ⠵ tweet mediaYesWeHack ⠵ tweet mediaYesWeHack ⠵ tweet mediaYesWeHack ⠵ tweet media
English
1
1
32
2.4K
szd
szd@Intrusio·
@nissanfrance @Gabydebur Bonjour @Gabydebur, On ne se connaît pas mais je m'apprêtais à passer une commande chez @nissanfrance, si vous pouviez me dire s'ils ont réglé la situation concernant votre véhicule ça m'intéresse car de mon côté je ne pourrai pas me permettre un tel retard de livraison.
Français
1
0
0
39
Nissan France
Nissan France@nissanfrance·
@Gabydebur Pour cela, il nous faudrait ces éléments dans un message privé : votre nom complet, votre numéro de téléphone, le nom de la concession et votre numéro de commande. Cordialement, Emilie 2/2
Français
2
0
0
47
Westrelin Gabriel
Westrelin Gabriel@Gabydebur·
Hey @nissanfrance ! Ma #xTrail commandée fin août, devait arriver il y a 2 semaines. Elle a été repoussée sans aucun avertissement à fin février ! Vous trouvez ça normal ? J'ai un dossier ouvert chez vous depuis deux semaines et pas de news depuis ! @UFCquechoisir
Français
3
0
0
51
YesWeHack ⠵
YesWeHack ⠵@yeswehack·
It’s nearly Christmas, so we need your letter to Santa, bug hunters! ✍ Which topic would you like us to focus on to add great features to the @yeswehack platform in 2025? 🎁 Got another wish? Drop it in the comments 👇
English
9
2
10
8.5K
szd
szd@Intrusio·
@DoomerOutrun @gregxsunday We need more infos about the workout to be so fresh as you are on these pics 😁
English
0
0
2
52
Bug Bounty Reports Explained
Bug Bounty Reports Explained@gregxsunday·
Today, @DoomerOutrun made history as the first BBRE podcast guest to visit Kraków exclusively for the recording. We:  ✅ Conducted a great interview ✅ Did a workout ✅ Went to a shooting range ✅ Got some drinks It was a pleasure and fun hosting you Victor!
Bug Bounty Reports Explained tweet mediaBug Bounty Reports Explained tweet mediaBug Bounty Reports Explained tweet media
English
5
1
56
6.3K
szd
szd@Intrusio·
@h4x0r_dz Try with your own known id to validate : /api/users/H4x*
English
0
0
2
670
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
I have an endpoint, /api/users/<id>, which retrieves user data . when I use * as ID, like `/api/users/*`, it takes 60 seconds and returns a Timeout . I think this request is trying to retrieve data for all users, but due to the large volume of data, the response is timing out.
H4x0r.DZ 🇰🇵 tweet media
English
33
36
515
46.7K
szd
szd@Intrusio·
@Blaklis_ Merci pour tous les bons moments et pour les opportunités que tu nous as offert chef ! 🇫🇷
Français
0
0
1
349
Blaklis
Blaklis@Blaklis_·
I'm no longer a HackerOne ambassador - I decided recently to re-focus on myself, and on hacking. I've invested a lot of time in the community last years - and I'll still be there, somehow - but it's time to get back some time for myself, and for hacking a bit more :) #bugbounty
English
20
9
386
20.3K