Satya

728 posts

Satya banner
Satya

Satya

@tines_io

Security Researcher | Bug Hunter | Microsoft HOF

Ramachandrapuram, India Katılım Temmuz 2020
526 Takip Edilen73 Takipçiler
Sabitlenmiş Tweet
Satya
Satya@tines_io·
New year gift in advance 😍
Satya tweet media
English
2
0
3
0
Satya retweetledi
Fun At All X
Fun At All X@Ishita_Sharma42·
Fun At All X tweet media
ZXX
48
418
8.2K
112K
Satya retweetledi
Godfather Orwa 🇯🇴
Godfather Orwa 🇯🇴@GodfatherOrwa·
Big #Bugbountytip / #bugbountytips Google Services Hunting Google services are amazing, and for bug hunters, it's amazing as well. In some cases, you can get some P1-P2-P3 from these services, such as Workspaces / Sheets / Groups / Drives / Etc... In groups: you can access emails / internal data/ credentials In Sheets, you can access PIIs / Edit access In Drive: you can access backups/ PII / Etc... still hard to find and It was an issue how to make good and at the same time fresh dorks for bug bounty programs Then I found out that a lot of links have the same path, and it was like this All Google resources I've found sites.google.com/a/domain.com/x… docs.google.com/a/domain.com/x… groups.google.com/a/domain.com/x… drive.google.com/a/domain.com/x… mail.google.com/a/domain.com/x… spreadsheets.google.com/a/domain.com/x… spreadsheets0.google.com/a/domain.com/x… spreadsheets1.google.com/a/domain.com/x… spreadsheets2.google.com/a/domain.com/x… spreadsheets3.google.com/a/domain.com/x… spreadsheets4.google.com/a/domain.com/x… spreadsheets5.google.com/a/domain.com/x… spreadsheets6.google.com/a/domain.com/x… spreadsheets7.google.com/a/domain.com/x… spreadsheets8.google.com/a/domain.com/x… UrlScan Dorking: page.url:"sites.google.com/a/*" page.url:"docs.google.com/a/*" You can replace * => the program domain Google Dorking: site:sites.google.com/a/* "inurl:/a/" Or for specific domain site:sites.google.com/a/* "inurl:/a/domain.com" GitHub Dorking: "sites.google.com/a/" Or for a specific domain "sites.google.com/a/domain.com" Shodan Dorking: "sites.google.com/a" Web Archive web.archive.org/cdx/search/cdx… Don't forget: It's not just sites.google.com still you have to look for docs/groups/mail/drive/spreadsheetsX still working in Google Research and will add more and more soon ...... Happy Hunting♥ #bugbounty
Godfather Orwa 🇯🇴 tweet media
English
16
206
910
39.9K
Satya retweetledi
fidexCode
fidexCode@fidexcode·
Relatable 😂💔
fidexCode tweet media
English
51
590
12.9K
85.6K
Satya retweetledi
JS0N Haddix
JS0N Haddix@Jhaddix·
This is the clearest graphic I could make on Prompt Injection. 1. Yes it's a vulnerability 2. It is the superset 3. No this does not illustrate ALL risks, just some
JS0N Haddix tweet media
English
17
75
400
30.6K
Satya retweetledi
Crafters Warrior
Crafters Warrior@tech_crafters·
86.65 GB All paid Courses Collection🔥 Full Drive link, Worth: $599 FREE for first 2000 people👇 💀 Data science 💀 Python 💀 AI 💀 Cloud 💀 BIG DATA 💀 Data Analytics 💀 BI 💀 Google Cloud Training 💀 Machine Learning 💀 Deep Learning 💀 Ethical Hacking To get it: ✅ Follow Me [MUST] ✅ Like and RETWEET this content. ✅ COMMENT with "DM"
Crafters Warrior tweet media
English
825
555
1.2K
112.6K
Satya retweetledi
Bipin Jitiya
Bipin Jitiya@win3zz·
Scan Git orgs 4 secrets: /(?i)(password|passwd|pwd|secret|token|apikey|api_key|access_key|secret_key|access_token|api_secret|apiSecret|app_secret|application_key|app_key|appkey|auth_token|authsecret)\s*=\s*["'][^"']{4,}["']/ AND org:adobe AND NOT language:Markdown NOT is:archived
Bipin Jitiya tweet media
English
4
62
307
15.5K
Satya retweetledi
Shraddha Bharuka
Shraddha Bharuka@BharukaShraddha·
Here’s your Complete Beginner to Advanced Guide to Handwritten AWS Notes! All, FREE of cost! To get the guide: 1. Follow me (So I can DM you) 2. Like & Repost this post 3. Comment "AWS" to receive…
Shraddha Bharuka tweet mediaShraddha Bharuka tweet media
English
498
378
1.4K
109K
Satya retweetledi
Godfather Orwa 🇯🇴
Godfather Orwa 🇯🇴@GodfatherOrwa·
🧐🧐🧐🧐🧐🧐
dbugs@ptdbugs

1/4 dbugs LIVE dbugs.ptsecurity.com — vulnerabilities’ home See trends, discover more, read AI summaries, have all references at hand, and your profile with all your CVEs and CVSS score on a leaderboard. ⬇️ See thread: what’s live + what’s next ⬇️

ART
0
1
32
3.7K
Satya retweetledi
Godfather Orwa 🇯🇴
Godfather Orwa 🇯🇴@GodfatherOrwa·
To be honest it’s super amazing place Thanks @PTsecurity_EN for this amazing work
Godfather Orwa 🇯🇴 tweet mediaGodfather Orwa 🇯🇴 tweet mediaGodfather Orwa 🇯🇴 tweet mediaGodfather Orwa 🇯🇴 tweet media
dbugs@ptdbugs

1/4 dbugs LIVE dbugs.ptsecurity.com — vulnerabilities’ home See trends, discover more, read AI summaries, have all references at hand, and your profile with all your CVEs and CVSS score on a leaderboard. ⬇️ See thread: what’s live + what’s next ⬇️

English
2
4
146
8.7K
Satya retweetledi
André Baptista
André Baptista@0xacb·
Have you checked out @hadriansecurity's subwiz? It's a recon tool that uses ML to predict and resolve subdomains👇
English
3
53
251
15.7K
Satya retweetledi
Daher Mohamed
Daher Mohamed@m0m0x01d·
One bug I’ve found during the @StandoffBB event: -> Subdomain redirects to SSO -> Found a Path traversal and accessed the API Swagger -> One of the API call took as input an image, and returned all similar images from the CDN -> Sent a passport sample found on google as input, server returned all passports from the CDN -> PII leak Think smart! #BugBounty #BugBountyTips
Daher Mohamed tweet media
English
9
38
300
20.3K
Satya retweetledi
Rakesh Krishnan Simha
Rakesh Krishnan Simha@ByRakeshSimha·
Now the British owe us $43 trillion + ₹4.7 lakh.
Rakesh Krishnan Simha tweet media
English
452
5.1K
44.2K
782K
Satya retweetledi
Raghvi
Raghvi@Just_Raghvi·
Cameraman won millions of heart 🥹❤️
English
548
2.6K
40.1K
1.8M