Ronin

22 posts

Ronin banner
Ronin

Ronin

@Roninxgh

Hi🫪

Katılım Haziran 2026
6 Takip Edilen190 Takipçiler
Ronin
Ronin@Roninxgh·
Sometimes I fucking hate bug bounty.
GIF
English
0
1
5
176
Ronin
Ronin@Roninxgh·
Favorite bug chain of the year: Broken Access Control in Comment Mentions → Stored XSS → CSP bypass → Notification code execution → Domain-wide token → Tenant-wide account takeover. Sometimes the smallest features hide the biggest bugs. Should I write a full write-up?
English
12
3
190
6.1K
Ronin
Ronin@Roninxgh·
@r00t_ak I’ll share it here soon!
English
0
0
0
4
Ayush
Ayush@r00t_ak·
@Roninxgh Yeah waiting for your writup...
English
2
0
2
82
Satar
Satar@satar_nz·
@Roninxgh Damn🔥 It's gonna be a fire writeup
English
1
0
1
60
Ronin
Ronin@Roninxgh·
@mosab_4_u Thanks , working on it. It’ll be out soon
English
0
0
2
84
Ronin
Ronin@Roninxgh·
Two bounties from a WAF bypass that took zero new payloads. Just a different place to put the old one. #xss
Ronin tweet media
English
5
1
113
3.2K
Ronin
Ronin@Roninxgh·
Why it works: signature matching runs per input. Neither half matches a rule on its own, so nothing fires. The browser doesn’t care where the bytes came from, it just parses the finished output. WAF sees input. Browser sees output.
English
0
0
4
87
Ronin
Ronin@Roninxgh·
The WAF blocked every payload I tried. But two user-controlled fields were rendering side by side in the same response, so I split the payload across both. Half in one, half in the other. Each part looked harmless. The browser put it back together.
English
1
0
5
271
Ronin
Ronin@Roninxgh·
Just got paid $2,000 for a single SSRF. 🩸 It started with a simple “fetch this image” endpoint. A few requests later, I had access to internal APIs that were never meant to be exposed. Big thanks to my mentor, @safe_mode01 , for the continuous guidance and support. 🙏
Ronin tweet media
English
8
6
205
10.2K