unknown
820 posts

unknown
@Unknownuser1806
Your time is limited, so don't waste it living someone else's life ... Stay Hungry. Stay Foolish. (Steve Jobs)
twitter Katılım Haziran 2019
444 Takip Edilen7.2K Takipçiler
unknown retweetledi

Here's the third bug. Multiple bugs were chained to achieve Facebook account takeover.
Facebook account takeover due to unsafe redirects after the OAuth flow ( $30k )
ysamm.com/?p=667
Youssef Sammouda (sam0)@samm0uda
I had a crazy week in February in which i was able to find 3 interesting account takeovers in Facebook and resulted a total of $100k in bounties. I'm sharing details about two of them and soon the third: ysamm.com/?p=646 ysamm.com/?p=654
English

There is always two types of people
- One who get inspired by seeing others and want to be like them
- And other get jealous to see other's success.
Make sure be in 1st type.
STÖK ✌️@stokfredrik
It’s easy to get overwhelmed when you watch others work, may it be art, music, creative, content, hacking, research, write ups, bounties, work life. Just remember, it’s not a competition, there is enough room and abundance for all of us to succeed, if we want to and work for it.
English
unknown retweetledi

Some notes from "How to Crush Bug Bounties in the first 12 Months" by
@hakluke
#bugbountytips
#BugBounty



English

Problem was, I dont know I was burning out, Here are symtoms of burned if you never exprinced it
- No long term vision of life
- No confidence
- No motivation
- No balanced in life
I love how @thehackerish explained in that video, It really helps me a lot
English

Burned out for a long time because of 80 to 100 hour of work week, Here are top best resource that might help you to overcame it
youtu.be/roVg_wgGgxQ -by @stokfredrik
@NathOnSecurity/bug-bounties-and-mental-health-40662b2e497b" target="_blank" rel="nofollow noopener">medium.com/@NathOnSecurit… by @NathOnSecurity
youtu.be/84QD2SjRDic - by @thehackerish
#bugbounty

YouTube

YouTube
English
unknown retweetledi

New writeup:
"We Hacked Apple for 3 Months: Here’s What We Found"
Featuring...
@bbuerhaus, @NahamSec, @erbbysam, and @_StaticFlow_
samcurry.net/hacking-apple
English
unknown retweetledi
unknown retweetledi

I wrote a post on @assetnote's blog about hacking in bug bounties for the last four years. This should give you a good idea on what I've been reporting and how I find bugs and incorporate them back into our platform.
blog.assetnote.io/2020/09/15/hac…
English
unknown retweetledi

I compiled a mind-map of all the tools I use for my day to day Bug Bounty journey :)
Please let me know if you find his helpful 👐
🥰🔐
full resolution of the image here:
blog.it-securityguard.com/patriks-bug-bo…

English
unknown retweetledi

Hey bountyhunters, here is an honest tip:
Don't rely on twitter.
Stop consuming what makes other hunters money, and start hunting and getting experience with methodologies, techniques, tools, and bug-classes that work for you.
#bugbountytips #bugbounty
English
unknown retweetledi

How I Hacked Facebook Again! Unauthenticated RCE on MobileIron MDM (slides inside) blog.orange.tw/2020/09/how-i-…
#HITCON
English
unknown retweetledi

unknown retweetledi

Just fully disclosed ~30 reports encompassing over two years of hacking on New Relic - hackerone.com/jon_bottarini - most of the reports are PrivEsc/IDOR but there are some business logic bugs in here as well. No recon here! Just getting really familiar with the application itself :)
English

Time for some reflection: what is one thing #BugBounty taught you about yourself? 🧘
Let us know in the comments! 💬
English

@intigriti We need 3Ps to get sucess anything in life. Persistence, patient,practice
English

This time I've taken a deeper look into HTTP request smuggling reports by @defparam and I've described his submissions to Slack and Zomato for $6,500 and $5,000 respectively. Enjoy!
youtu.be/gzM4wWA7RFo

YouTube
English
unknown retweetledi

Burp Extensions that I use: (1/n)
1. Autorize - To Test BACs
2. Burp Bounty - Profile-based Scanner
3. Active Scan++ - Add more power to Burp's Active Scanner
4. AuthMatrix - Authorization/PrivEsc Checks
5. Broken Link Hijacking - For BLH
#bugbountytips #bugbounty
English
unknown retweetledi


