NullSecurityX

897 posts

NullSecurityX banner
NullSecurityX

NullSecurityX

@NullSecurityX

Infosec researcher • Bug bounties & security analysis. https://t.co/kOIAd973sL Collabs/ads: DM 📥

Katılım Mayıs 2024
178 Takip Edilen11.5K Takipçiler
NullSecurityX
NullSecurityX@NullSecurityX·
Sorry for the delay everyone. The cPanel vulnerability video drops Wednesday full technical breakdown + live exploitation on real targets.Friday/Saturday we’ll publish a live bug bounty PoC showing how we triggered an IDOR via UUID handling issues on UBER
English
1
0
7
309
NullSecurityX
NullSecurityX@NullSecurityX·
@taviso “Localhost-only” is not a security boundary. Too many Electron/Python apps expose loopback HTTP services with weak CORS/WebSocket protections, enabling browser-assisted local pivoting or CSRF-style abuse. PNA enforcement can’t come soon enough.
English
1
0
10
1.6K
Tavis Ormandy
Tavis Ormandy@taviso·
I really wish browsers would hurry up and implement private-network-access, developers often don't understand the implications. This weekend I tried a random flashcard application for language learning... and it started a localhost web service 😔
Tavis Ormandy tweet media
English
18
15
286
42K
Cyber_Racheal
Cyber_Racheal@CyberRacheal·
Interviewer: HTTPS encrypts everything. Then how do CDNs still cache content?
English
12
13
183
37.3K
Elorm Daniel
Elorm Daniel@elormkdaniel·
When a Hacker Finds Your Password...
English
204
1.7K
19.9K
1.3M
NullSecurityX
NullSecurityX@NullSecurityX·
New Videoo: How Hackers Exploit XSS Vulnerabilities | Understanding XSS Attacks Learn how attackers abuse XSS flaws, inject malicious payloads, and compromise browsers in real-world scenarios during live bug bounty style testing. youtu.be/QuSytRm-pz4
YouTube video
YouTube
NullSecurityX tweet media
English
0
2
10
1.4K
NullSecurityX
NullSecurityX@NullSecurityX·
@sorunsalladi @DailyDarkWeb Sen öyle deyince index2.html index.html geldi aklıma :D keşke o yıllara dönebilseydik. Hack'e başladıktan sonra ki 3-4 yıl sonra ki pastebin açıklamamı buldum :D Burdan yeri gelmişken 3 Mayıs Türkçü'ler günü kutlu olsun.:)
NullSecurityX tweet media
Türkçe
1
0
0
124
Ali
Ali@sorunsalladi·
@NullSecurityX @DailyDarkWeb Yıllar önce bir dernek sitesinde zafiyet bulmuştum. Racon gereği hacklemedim, adminin telefonunu bulup bildirdim. Teşekkür edip bana iki kişilik sinema bileti almıştı. O dönem kız arkadaşımla gitmiştim. İlk bug bounty anımdır. Sene 2014 falan.
Türkçe
1
0
0
57
NullSecurityX
NullSecurityX@NullSecurityX·
@sorunsalladi @DailyDarkWeb Önceden giren şerefi ile indexini atar bilgileri public yayınlar geçerdi. Şimdi bir reklamcı lamer grup gibi public .xslx dosyalarından eriştiği verilerle olmayan db mimarisi inşa edip, bilgileri leak ettik diye etkileşim kaşarlığı yapıyorlar
Türkçe
1
0
0
70
Ali
Ali@sorunsalladi·
@NullSecurityX @DailyDarkWeb Eskiden hiç değilse black hatlerden bir şeyler öğrenip defansif tarafı güçlendiriyorduk. Şimdi götten sallama leak yayınlıyorlar.
Türkçe
1
0
1
71
NullSecurityX
NullSecurityX@NullSecurityX·
@sorunsalladi @DailyDarkWeb En son sallamasyon yayınladığı bilgileri yalanlayıp kanıtlarıyla ispatladım. Gönderileri vs hepsini kaldırdılar. Yine yayınlamaya başladılar. Bu darkwebintelligence de etkileşim kaşarlığı yapıyor. Hatırlamışken burdan eski dostlara selam olsun..:)
Türkçe
0
0
1
132
Ali
Ali@sorunsalladi·
@NullSecurityX @DailyDarkWeb Yine ne sallamış bu Doğan SLX götünden acaba... Aylardır sallamasyon veri yayınlıyor. Biri de sesini çıkartmıyor. Çok bozdu bu black hat tarafı. Eskiden daha kaliteliydi. Nerede o eski black hatler...
Türkçe
2
0
1
182
NullSecurityX
NullSecurityX@NullSecurityX·
FBI reportedly leveraged iOS notification preview persistence to recover deleted Signal message artifacts. E2E encryption remained intact the exposure was entirely OS-side. Apple patched it in iOS 26.4.2 by replacing cached content with metadata/length-only storage.
NullSecurityX tweet media
English
1
4
26
3.4K
NullSecurityX
NullSecurityX@NullSecurityX·
@xfeylesof Thanks for becoming a member. The upcoming videos will definitely be worth the wait.. :)
English
0
0
0
35
Outis
Outis@xfeylesof·
@NullSecurityX We became members and turned on notifications. now we’re waiting 🔥
English
1
0
0
48
NullSecurityX
NullSecurityX@NullSecurityX·
Get ready next week, some legendary videos are coming. The high-level ones will be shared exclusively for members only. Everyone who joins, even at the lowest membership tier, will have access to the videos. youtube.com/channel/UCTeWg… Big thanks to everyone who became a member ❤️
English
2
2
7
1.1K
NullSecurityX
NullSecurityX@NullSecurityX·
Copy Fail is a Linux privilege escalation bug that lets any local user get root using a 732-byte Python script, and itworks on basically every major Linux distro shipped. CVE-2026-31431 Write-up: xint.io/blog/copy-fail… YouTube: @NullSecurityX" target="_blank" rel="nofollow noopener">youtube.com/@NullSecurityX
English
1
6
15
1.8K
Vito Botta
Vito Botta@vitobotta·
@NullSecurityX $15K for ATO on Facebook seems low. They can afford more for something this critical.
English
1
0
0
26
NullSecurityX
NullSecurityX@NullSecurityX·
🔐 Facebook Account Takeover | $15000 Bug Bounty PoC This video walks through a critical Account Takeover vulnerability on Facebook, including a step-by-step PoC, 📌 Now members-only Get access by joining at the lowest tier. 👉 youtu.be/Sm_2JJPm2g4
YouTube video
YouTube
English
3
8
37
4.7K
NullSecurityX
NullSecurityX@NullSecurityX·
Bug Bounty Course: Recon, Dorking, XSS/LFI, CORS & Open Redirect on Live Targets | YesWeHack ✅ Subdomain Recon ✅ Google Dorking ✅ XSS & LFI ✅ CORS Misconfiguration ✅ Open Redirect Mass Hunt Perfect for beginners👇 youtu.be/wcZxhXel7jQ
YouTube video
YouTube
English
0
0
16
1.3K