Jess Gutierrez 🇦🇹🇵🇭

213 posts

Jess Gutierrez 🇦🇹🇵🇭

Jess Gutierrez 🇦🇹🇵🇭

@Jess_Gutier

Katılım Kasım 2019
245 Takip Edilen10 Takipçiler
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
Gareth Heyes \u2028
Gareth Heyes \u2028@garethheyes·
I've built a brand new version of my fuzzing tool Shazzer🚀 shazzer.co.uk - Easy fuzz browser behaviour - Find bugs - Share the results with the world
English
7
88
261
40.6K
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
MrBeast
MrBeast@MrBeast·
I’m gonna give 10 random people that repost this and follow me $25,000 for fun (the $250,000 my X video made) I’ll pick the winners in 72 hours
English
378.3K
2.5M
1.9M
284M
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
Bug Bounty Reports Explained
Bug Bounty Reports Explained@gregxsunday·
Turns out that 5-digit bounties aren't reserved for crazy top hunters! I recently got a $20,000 bounty for an misconfiguration of S3 pre-signed URLs. Here's the explanation: youtu.be/MBQJJ3jfJ8k
YouTube video
YouTube
English
6
32
218
22.2K
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
shubs
shubs@infosec_au·
Really love this WAF bypass technique documented and found by @irsdl in 2017: soroush.me/downloadable/r… - still super effective today!
English
8
118
428
62.8K
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
SwiftOnSecurity
SwiftOnSecurity@SwiftOnSecurity·
Working in InfoSec watching the rest of IT
English
215
4.1K
32.2K
4.5M
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
Jon Bottarini
Jon Bottarini@jon_bottarini·
Here's a #bugbountytip I've used a couple times to find some really interesting functionality - if you're doing recon, check out this endpoint: <targetdomain>/.well-known/apple-app-site-association This endpoint is used for Apple's associated domains feature - you would really
English
7
52
204
18K
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
meg west
meg west@cybersecmeg·
Y’all, PLEASE take advantage of this FREE CERTIFICATION from @ISC2! They are offering FREE entry-level Cybersecurity training AND a FREE exam voucher for a certification attempt! Sign-up below! Learn more about One Million Certified in Cybersecurity at: bit.ly/LearnMore_MegW… *If you pass the exam and choose to become a member, there is a $50 annual membership fee. #ad
English
75
749
2.1K
363.8K
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
Abdelrhman Amin
Abdelrhman Amin@0xUchihamrx·
"Shodan is your best friend with the big scope target" tips org:"target trad name" and use"http.title" you will get result like adminpanel,directory listing ,etc check logs file,maybe get some sensitive data,usernames,passwords,PLL thx @GodfatherOrwa #bugbountytips #bugbountytip
Abdelrhman Amin tweet media
English
9
105
438
22.7K
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
Toni Gidwani
Toni Gidwani@t_gidwani·
The Google Cybersecurity Certificate is here! 🎉 I am excited to be an instructor in this program, and helping ppl looking to get into the field #GrowWithGoogle goo.gle/3AxpCfu
English
12
108
567
61.1K
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
Mehdi
Mehdi@silentgh00st·
Here is how I chained two bugs to exploit a UUID based IDOR and gained access to admin panel. 🧵THREAD🧵 1. How I knew that the target uses the same panel for both (normal users and admins)?! This is because of two things, the first one is through subdomain enumeration
Mehdi tweet mediaMehdi tweet media
English
31
230
878
114.1K
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
Paul Seekamp
Paul Seekamp@nullenc0de·
I just found an unbelievable number of unauthorized API endpoints using this 1 liner. katana -u $url -hl -nos -jc -silent -aff -kf all,robotstxt,sitemapxml -c 150 -fs fqdn |subjs | python3 /opt/JSA/jsa.py |goverview probe -N -c 500 |sort -u -t';' -k2,14 |cut -d ';' -f1
English
16
126
665
61.2K
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
Linux Handbook
Linux Handbook@LinuxHandbook·
Just came across this Bash ebook that can be downloaded legally for🆓 Enjoy it😎 and follow us for regular dose of Linux learning 🤘🐧 #ebook" target="_blank" rel="nofollow noopener">ebook.bobby.sh/#ebook
English
9
92
291
29.4K
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
Joseph Cox
Joseph Cox@josephfcox·
New: we proved it could be done. I used an AI replica of my voice to break into my bank account. The AI tricked the bank into thinking it was talking to me. Could access my balances, transactions, etc. Shatters the idea that voice biometrics are foolproof vice.com/en/article/dy7…
English
125
1.9K
5K
1.4M
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
Youssef Sammouda (sam0)
Youssef Sammouda (sam0)@samm0uda·
ATO of FB/OC accounts after stealing access_tokens ($44,250) ysamm.com/?p=777 DOM-XSS in Instant Games due to improper verifications ($62,500?) ysamm.com/?p=779 ATO in Canvas Games due to weak cross window message Origin validations ($62,500) ysamm.com/?p=783
English
12
160
594
80.2K
Jess Gutierrez 🇦🇹🇵🇭 retweetledi
InfoSec Community
InfoSec Community@InfoSecComm·
📢GIVEAWAY ALERT📢 If you're a student & unable to pay for a ticket to #IWCON2022💔 For the next 2 hours, any student who mails us at contact[at]infosecwriteup[dot]com with a college email ID We'll provide all-access passes to #IWCON2022!🥳 #Retweet & tag fellow students!
InfoSec Community tweet media
English
10
10
52
9.8K