f00l

32 posts

f00l

f00l

@PPPF00L

binary noob

Katılım Kasım 2019
391 Takip Edilen57 Takipçiler
f00l retweetledi
f4lc0n
f4lc0n@al_f4lc0n·
I Saved Injective's $500M. They Pay Me $50K. I like hunting bugs on @immunefi . I'm decent at it. - #1 — Attackathon | Stacks - #2 — Attackathon | Stacks II - #1 — Attackathon | XRPL Lending Protocol - 1 Critical and 1 High from bug bounties (not counting this one) Life was good. Then I found a Critical vulnerability in @injective . This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk. I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity. Then — silence. For 3 months. No follow up. No technical discussion. Nothing. A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either. I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten. I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve. Full Technical Report: github.com/injective-wall…
English
519
524
4.6K
1.8M
f00l
f00l@PPPF00L·
@ma1fan what is this panel?
English
1
0
0
81
Nolan | Exvul
Nolan | Exvul@ma1fan·
Lol, Rust audits are consuming most of my time lately. How about you?
Nolan | Exvul tweet media
English
5
0
25
2.8K
Tony KΞ
Tony KΞ@tonykebot·
just release an interesting chal 🤣🤣 enjoy!
Tony KΞ tweet media
𝕗𝕦𝕫𝕫𝕝𝕒𝕟𝕕@fuzzland_

Fuzzland #CTF is back on 9/20 ~ 9/22 Put your skills to the test with big prizes - $10k prize pool for the top 3 teams, and big swag bags for the top 30. Can you solve puzzles designed by the masters @fried_rice @tonyke_bot? Can you beat the defending champs @Offside_Labs ? Last year we had 670 teams, 14 puzzles, and only 251 teams who completed at least 1 puzzle. Register today@ ctf.blaz.ai and prove who the best hacker in the industry is.

English
1
0
9
2.3K
f00l
f00l@PPPF00L·
@ma1fan is this found by fuzzer?
English
0
0
0
251
Nolan | Exvul
Nolan | Exvul@ma1fan·
Happy Friday 😎🍺This bug is very interesting and complex
Nolan | Exvul tweet media
English
8
4
132
15.1K
f00l
f00l@PPPF00L·
@Y1nKoc my dear dalao, plz daidaiwo
English
1
0
1
473
Minghao Lin
Minghao Lin@Y1nKoc·
It's my first CVE in Apple!
Minghao Lin tweet media
English
9
2
130
13.9K
Nolan | Exvul
Nolan | Exvul@ma1fan·
I have create a web3 security telegram group, Welcome to join our technical community. In this group, I will share some original security technologies as soon as possible, and discuss and exchange real web3 security technologies together. t.me/+QnrDM5RnAbczN…
Nolan | Exvul tweet media
English
0
2
26
6.3K
zh1x1an1221
zh1x1an1221@zh1x1an1221·
Under the guidance of several web3 friends, I tried to find some web3 bugs. Currently, 3 high and 2 medium in code4rena. Recently, I spent a day trying @PatrickAlphaC Codehawks and found the first one. Although it is low-risk, it is also very happy.
zh1x1an1221 tweet mediazh1x1an1221 tweet media
English
9
1
22
4.8K
Albinauric
Albinauric@JonLion15·
what's wrong with this code?
Albinauric tweet media
English
3
0
0
445
f00l
f00l@PPPF00L·
repay the debt of DSA for drain all funds (it would trigger a health factor check if dont repay the debt lead to only get partial of funds)
English
0
0
0
150
f00l
f00l@PPPF00L·
build such a external call sequence's swap data: 1. approve 1wei usdc token of connector for DSA contract 2. calling executeAction for switching 1wei usdc to all weth 3. calling weth transferFrom to get the token
English
1
0
0
180
f00l
f00l@PPPF00L·
The root case of DoughDsa hack is because of arbitrary external call in `deloopAllCollaterals` function which is called by `executeOperation` function in connector contract.
f00l tweet media
English
1
0
0
226
f00l
f00l@PPPF00L·
@WangTielei Execuse me, is this vulnerability fixed in iOS 17.3 and not in 17.4 actually?
English
0
0
0
399
Tielei
Tielei@WangTielei·
Still interested in exploiting IPC memory corruptions on Apple devices? Try this one: CVE-2024-27801, UAF in the low level implementation of NSXPC that has been present since the initial release of NSXPC (over decade ago). POC: github.com/wangtielei/POC…
English
1
40
173
20.1K
f00l
f00l@PPPF00L·
@WangTielei Is this bug eligible for a bounty?🤪
English
0
0
1
555
Tielei
Tielei@WangTielei·
Long time no research share! Back with some interesting bugs. Let's start with CVE-2024-27842. UDF is a kernel extension that's been on macOS for decades. The vuln lies in VNOP_IOCTL, where an arbitrary cmd can be sent to an arbitrary vnode, leading to memory corruptions.
English
3
11
78
12.8K
孟岩-Mike Meng
孟岩-Mike Meng@myanTokenGeek·
有没有熟悉 EVM 区块链智能合约开发、基本掌握 Rust、勤奋好学、愿意拜在明师下实战 Solana 应用协议的年轻人?
中文
45
4
48
43K
f00l retweetledi
h0mbre
h0mbre@h0mbre_·
they’re called 0days because ive found 0 of them
English
10
60
443
30.9K