Sabitlenmiş Tweet
X3r0Day
67 posts

X3r0Day
@X3r0DaySec
Security Researcher | Pentester | Part time coder Founder of Project X3r0Day! | DM for audit
Katılım Aralık 2024
18 Takip Edilen234 Takipçiler

@love_deepseek @yoursbyte @h4x0r_dz Look into how to prompt, opus 4.8 does not refuse me, and tbh jailbreaking a model wasn't even hard until fable dropped
English

@yoursbyte @h4x0r_dz I don't believe that it's literally equal until DeepSWE drops it's benchmark
Gpt 5.5 > opus 4.8 btw
English

@X3r0DaySec @h4x0r_dz GLM 5.2 IS LITERALLY EQUAL TO OPUS 4.8 they are equal but I get this model for way cheaper then opus this is the difference
English

@yoursbyte @h4x0r_dz Seen you 2nd time, what makes you think it can be a cyber weapon?
Imo opus 4.8 is way better for that job
What do you think
English
X3r0Day retweetledi

Important clarification regarding the Haryana Higher Education data exposure:
I did NOT hack into any system.
The data was publicly accessible without any login or credentials due to a simple misconfiguration (IDOR/Broken Access Control).
Anyone could construct the URL and access student documents (marksheets, photos, signatures etc.).
I reported this responsibly to CERT-In and finally its PATCHED now !!
I did not download bulk data or misuse anything. My only goal was to get it fixed.
Full technical details + proof here:
blogs.hacck3y.me/posts/haryana-…
#ResponsibleDisclosure #CyberSecurity

404@hacck3y
🚨 Haryana Higher Education Data Leaked.. 🚨 10+ Lakh Haryana students' personal data EXPOSED -10th/12th marksheets, photos leaked due to misconfig on official Higher Education site. I emailed them weeks ago. No response. Govt sites leaking student data in 2026?
English

@FirstOnWire @CTI__Updates Well they used AES-256 then used base64 on top of it so they can transfer data through https requests
English

They "fixed" my last Indian Govt data dump by encrypting it (srsly lol?)
Bypassed that too lmao
48,593 contacts. 37,598 users. All decrypted with a PoC. (IP, Pass, Aadhaar..)
CERT-In has been notified. Not dropping full details until it's actually fixed.
x.com/X3r0DaySec/sta…

X3r0Day@X3r0DaySec
I Hacked an Indian Government Website Found Users’ Passwords,Aadhaar Numbers,IP Address, Address,phone no,email This is a serious data privacy failure. Reported to CERT-In. Will release full technical details once its fixed. Got more in my Bag 👀 1 vuln each week series? ;))
English

Day 200/365 of the Until get 10.0 Critical report
📤 Reports Submitted:- 0
🟠 triaged - 3
🟦 program review - 0
🟤 Duplicate - 0
🟣 New - 2
⚪️ Info - 0
💰 Paid - $3487
💻 Worked- 10 HOUR
#BugBounty
Yay, I was awarded a $2700 + Bonus bounty on @Hacker0x01

English

@VivekIntel LLMs are better at finding origin host IP than anything
English

☁️ CloudFail — Discover Infrastructure Hidden Behind Cloudflare
CloudFail is an open-source reconnaissance tool designed to uncover origin server information that may be exposed behind Cloudflare protection through historical records and DNS misconfigurations.
Key Features:
• Searches for leaked origin IP addresses behind Cloudflare
• Checks historical records from CrimeFlare databases
• Performs DNS reconnaissance using DNSDumpster
• Enumerates over 2,500 subdomains to identify exposed assets
• Supports Tor routing for privacy during research
• Useful for infrastructure exposure assessments and attack surface analysis
Reconnaissance Techniques:
✔ Misconfigured DNS record discovery
✔ Historical infrastructure correlation
✔ Subdomain enumeration and analysis
✔ Cloudflare origin exposure detection
Note: CloudFail is intended for authorized security testing, research, and defensive assessments. Properly configured Cloudflare deployments may not expose origin infrastructure.
🔗 github.com/m0rtem/CloudFa…
#CyberSecurity #OSINT #Recon #Cloudflare #Pentesting

English















