Mochammad Nosa Shandy

6.7K posts

Mochammad Nosa Shandy banner
Mochammad Nosa Shandy

Mochammad Nosa Shandy

@LocalHost31337

another infosec guy | {insert your certification here}

Katılım Nisan 2015
1.6K Takip Edilen2K Takipçiler
Sabitlenmiş Tweet
Mochammad Nosa Shandy
Mochammad Nosa Shandy@LocalHost31337·
So, on August I've found clickjacking on google worth 7,500$ , This is the write up : apapedulimu.click/clickjacking-o… Thanks to all of the community who teach me a lot for finding a bug. Specially for indonesia bug hunter community. 🙏
Mochammad Nosa Shandy tweet media
English
28
156
402
0
Mochammad Nosa Shandy retweetledi
Mushtaq Bilal, PhD
Mushtaq Bilal, PhD@MushtaqBilalPhD·
Sci-Hub is an evil website that pirated 85M+ research papers and made them freely available And now they've added AI to their database to make Sci-Bot. It answers your questions using latest, full-text articles. But DO NOT use it. We should all try to make billion-dollar academic publishers richer. I'm putting the link below so you know how to avoid it.
English
825
8.9K
46.7K
4.6M
Mochammad Nosa Shandy retweetledi
OmerAF
OmerAF@omer_asfu·
I achieved a cross-tenant #RCE in #GoogleCloud simply by abusing predictable bucket names. 🪣 In my latest research for @FocalSecurity, I look into "Bucket Squatting" - a cross-tenant attack that landed me 3 critical vulnerabilities in GCP. Here is how it works:
OmerAF tweet media
English
3
50
212
23.7K
Mochammad Nosa Shandy retweetledi
skull
skull@brutecat·
My 2nd RCE in Google Cloud production (Borg) in less than 3 months... I'm at $600k in total rewards from Google VRP in the past few months. Still can't believe it.
skull tweet media
English
66
70
1.8K
90.9K
skull
skull@brutecat·
Finally had the pleasure of meeting @sirdarckcat IRL at Google Singapore 🇸🇬 Always learn something new talking to him!
skull tweet mediaskull tweet media
English
1
1
102
9.9K
Mochammad Nosa Shandy retweetledi
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
I pointed claude opus at chrome and told it to build a full v8 exploit for discord. A week of back-and-forth pulling it out of dead ends. 2.3B tokens. $2,283 in API costs, and it popped a shell. hacktron.ai/blog/i-let-cla…
English
22
172
1.1K
146.9K
Mochammad Nosa Shandy retweetledi
Synack Red Team
Synack Red Team@SynackRedTeam·
Is your checkout logic costing you? 💸 In our Exploits Explained blog, SRT member Tubagus Fahrudiansyah exposes a critical business logic flaw that turned a standard checkout into a free-for-all. By exploiting a synchronization gap between the payment gateway and the shopping cart, this researcher successfully finalized high-value orders for the price of a single, cheap item. Read the full breakdown & remediation steps: synack.com/exploits-expla…
Synack Red Team tweet media
English
0
7
25
2.4K
Mochammad Nosa Shandy retweetledi
Intigriti
Intigriti@intigriti·
Are you testing for race conditions? 🏁 If not, it can sometimes be as easy as: 1. Grouping your requests in Burp Repeater 2. Sending all groups in parallel 🤠 Example! 👇
Intigriti tweet media
English
8
17
167
8.3K
Mochammad Nosa Shandy retweetledi
YS
YS@YShahinzadeh·
android hunt GOLDEN tip: if you land inside an internal webview via deep link (myapp://web?url=your_site), dump all JS bridges, apps inject native objects on window, they are callable by JS and some leak tokens, fire authed requests, etc. 1-click ato material ;]
YS tweet media
English
2
24
341
9.8K
Mochammad Nosa Shandy retweetledi
Zellic
Zellic@zellic_io·
How to find a $65,000 zero-day in Chrome V8: Meet @eternalsakura13, researcher at Zellic. - Top 3 Chrome VRP 2022–2024 - Top 2 Facebook whitehat in 2023 - Top 10 MSRC MVR in 2025 Here’s a walk through the mind of one of the world’s best Chrome researchers. Can you follow along?
Zellic tweet media
English
4
59
512
50K
Mochammad Nosa Shandy retweetledi
Intigriti
Intigriti@intigriti·
Master broken access control vulnerabilities! 😎 A thread! 🧵👇
Intigriti tweet media
English
4
81
566
25.7K
Mochammad Nosa Shandy retweetledi
RyotaK
RyotaK@ryotkak·
I've published a writeup on a vulnerability I found in Google Cloud Looker: a single directory deletion bug that led to RCE and cross-instance privilege escalation in k8s.
GMO Flatt Security Inc.@flatt_sec_en

We've published a new blog post by RyotaK @ryotkak ! He exploited a directory deletion race condition in Google Cloud's Looker, leading to full RCE and K8s privilege escalation. Read the technical details here: flatt.tech/research/posts…

English
6
36
221
24.1K
sw33tLie
sw33tLie@sw33tLie·
I wanted a screenshot tool for macOS better than anything out there, so I built one with @claudeai Native Swift. No Electron. Annotate, record screen, scroll capture, auto-redact PII, beautify, upload to Drive & more — one flow. Free & open source forever. macshot 🔗👇
English
23
39
170
25K
Mochammad Nosa Shandy retweetledi
YS
YS@YShahinzadeh·
I published one of the techniques that I've been using against OAuth providers, honetly, it's led me to discover many flaws, and recently I used it to find a 1-click ATO on one of the most widely visited websites,I hope you find it useful :-) blog.voorivex.team/story-of-abusi…
YS tweet media
English
19
119
647
28.1K
Mochammad Nosa Shandy retweetledi
✨_geeknik_//✨
✨_geeknik_//✨@geeknik·
Pentesters found a fully-patched WordPress site. All plugins updated. No exposed APIs. Clean. Then AI read 20 plugins' source code and found an unauth deserialization → novel Monolog RCE chain → webshell in hours. "Up to date" is not a security posture. blog.sicuranext.com/exploiting-a-p…
English
0
1
1
225
Mochammad Nosa Shandy retweetledi
Douglas Day
Douglas Day@ArchAngelDDay·
It is wild to think that the bug bounty automation engine I built by myself is leaps & bounds more mature than enterprise level security products that charge 7-figures.
English
5
3
82
18.3K
Mochammad Nosa Shandy retweetledi
8kSec
8kSec@8kSec·
This blog walks through Android deep link and WebView exploitation, bypassing host validation to exfiltrate credentials from shared_prefs via JavaScript: 8ksec.io/android-deepli… Tested on InsecureShop using ADB + Frida.
8kSec tweet media
English
0
39
146
8.9K
Mochammad Nosa Shandy
Mochammad Nosa Shandy@LocalHost31337·
@mindfulln3ss @0xObsidian_X not works tho, I once reported 2 IDOR on different endpoint on some program on @Bugcrowd. 1 report along with video already triaged by the analyst and giving it to the team, once the team step up they cannot reproduce it and was fixed. they ignore the video and close it as N/A
English
0
0
0
86