JustinRuth

39 posts

JustinRuth banner
JustinRuth

JustinRuth

@JustinRuth

Independent Security Researcher | Checkmarx Sales Engineer | lover of all (most) Whiskey

Dallas Katılım Eylül 2008
129 Takip Edilen57 Takipçiler
JustinRuth
JustinRuth@JustinRuth·
I never post on here but here's an update on how today was going and went.
JustinRuth tweet media
English
0
0
0
0
JustinRuth retweetledi
STÖK ✌️
STÖK ✌️@stokfredrik·
More than 280 million people suffer from depression worldwide. Over 700 000 people die due to suicide every year. Suicide is the fourth leading cause of death in 15-29-year-olds. (WHO/2021) If you feel depressed, alone, or lost, there is help to get. You are not alone.
English
20
67
303
0
JustinRuth
JustinRuth@JustinRuth·
@MantisSTS If it's e-commerce, check redemption flows especially when a default cc is stored. I had success with POST based Gift cards add to carts and redemptions.
English
1
0
2
0
Mantis
Mantis@MantisSTS·
I found an XSS last night and didn't report it because I want to escalate it. What would you look for to escalate it? #BugBounty #bugbountytips
English
9
5
18
0
JustinRuth retweetledi
Luke Stephens (hakluke)
Luke Stephens (hakluke)@hakluke·
This is @codingo_ 's first video and comprehensive written guide. His guide to ffuf is actually more comprehensive than the ffuf readme! I can see his content becoming the ultimate reference guide for hacking/bb stuff. Follow/sub to him everywhere!
Michael Skelton@codingo_

I just spent over a month crafting the ultimate guide to Fuff. It is such an incredibly powerful tool, and I bet you're not using all of the features to full advantage! Video: youtube.com/watch?v=iLFkxA… Written guide: codingo.io/tools/ffuf/bou… #bugbountytips

English
1
8
64
0
JustinRuth
JustinRuth@JustinRuth·
@zseano Love this! I think 75 or 80% of the bugs I've found are on the main site. Recon is great for learning how the entire Enterprise deploys as well as architectures at play.
English
0
0
0
0
zseano
zseano@zseano·
I love that everyone's hot on the recon game, ya'll leaving the main web app fresh for me to poke at ;) keep scanning for them subdomains please:P
English
18
6
174
0
JustinRuth
JustinRuth@JustinRuth·
Question for #bugbounty #BugBountyTips would you submit exposed source code (.jsx files) via the browser? Only appears on a certain page and seems like the full app. Not seeing any keys but tons of endpoints as well as custom code and full node_modules folder.
English
0
1
2
0
JustinRuth
JustinRuth@JustinRuth·
dang today became such a better day when I realized I could use _ in SED instead of / echo '"google.com"' | sed 's_"__g' is the same thing as echo '"google.com"' | sed 's/"//g' substitute all double quotes with nothing. #linuxnoob
English
0
0
0
0
streaak
streaak@streaak·
@R44MB00 @Bugcrowd Would've been 100 if not for the first few bugs which I submitted back when I started 😂
English
1
0
1
0
JustinRuth
JustinRuth@JustinRuth·
@fin1te Incredible post! I love the part about P0s. It's crazy when you spend some time on the "other side" prioritizing tons of security issues. Bug bounties are important and great, but don't represent all the risk to an org. Really great context to learn.
English
0
0
0
0
JustinRuth
JustinRuth@JustinRuth·
@mubix Really silly one... I suck at regex and I shouldn't. A coworker corrected a really dumb regex mistake I was making on a call and I realized how hard I was making that particular workflow. He was so matter of fact, it was super pleasant, and I learned something awesome.
English
0
0
3
0
Rob Fuller
Rob Fuller@mubix·
I wish more people in this world would feel joy instead of fear when someone confronted with conflicting information to their current knowledge base. I absolutely love learning new things, especially when I'm wrong about how I think it works. My favorite example is:
English
2
6
94
0
JustinRuth
JustinRuth@JustinRuth·
@greenwaybarista Haven't watched Anime in a bit but literally just finished Altered Carbon: Resleeved on NF, was entertaining but not a series!
English
0
0
0
0
David Buehrer He/Him/Y'all
David Buehrer He/Him/Y'all@greenwaybarista·
Hunter x Hunter was amazing. any other 150 episodes or less Anime anyone recommend?
English
10
0
7
0
JustinRuth
JustinRuth@JustinRuth·
Hit 2 personal goals today on @Bugcrowd 1. Top 1000! 2. Pass 2019 earnings in 2020. set personal goals you can celebrate, the more obtainable the better! #BugBounty
JustinRuth tweet media
English
3
0
22
0
JustinRuth
JustinRuth@JustinRuth·
If javascript: is being filtered try some other payloads that might still work in <a href='payload'> java%0Ascript: java%0Dscript: java%20script: anything others? #bugbounty #bugbountytips
English
0
4
11
0
JustinRuth
JustinRuth@JustinRuth·
Over the last couple of weeks I had some down time and got the itch to hit some Bug Bounty programs. Reported a couple of vulnerabilities which ultimately lead to my first payout! Thanks @Bugcrowd ! #bugbounty
English
1
0
2
0