Dalus

103 posts

Dalus

Dalus

@_d4ly_

Tired, old and grumpy. Can do a bit on a computer.

UK Katılım Eylül 2021
73 Takip Edilen487 Takipçiler
Dalus retweetledi
No Context Brits
No Context Brits@NoContextBrits·
How did it end up like this?
No Context Brits tweet media
English
319
4K
71.6K
2.1M
TryHackMe
TryHackMe@tryhackme·
____ is the best TryHackMe room? 👀
English
11
2
48
8.1K
Dalus
Dalus@_d4ly_·
I wonder what the intersection is between those crying about AI and bug bounty being dead, and those that bought courses on how to do bug bounty. #bugbounty #thoughtfortheday
English
0
0
0
94
Dalus
Dalus@_d4ly_·
@0xConda Showing the desperation is the key.
English
0
0
0
238
Brandon Rossi
Brandon Rossi@0xConda·
If you beg hard enough the bounties will come
English
3
4
64
5.1K
Dave
Dave@GamewithDave·
For anyone who used a computer between 1990 & 2005… what’s the one game you still think about?
English
40.6K
723
14.3K
10.5M
Dalus
Dalus@_d4ly_·
@irsdl They are becoming more sentient, you need to say please.
English
0
0
1
278
Soroush Dalili
Soroush Dalili@irsdl·
Are you AI? Then prove it! 😂
Soroush Dalili tweet media
English
2
0
14
3.3K
Dalus
Dalus@_d4ly_·
@hakluke It'd be fair for the platform on request. Researchers get a bit emotional. It'd help build trust in the platform and the program - trust isn't just about the researcher. If many bugs are dup, does program see value? Seems smart to follow up for platform on this point too.
English
0
0
0
67
Luke Stephens (hakluke)
Luke Stephens (hakluke)@hakluke·
Bug bounty question: If you submit a bug, and it gets marked as an internal dupe because "the team already knew about it", is it fair to ask for proof?
English
57
5
262
37.9K
Dalus
Dalus@_d4ly_·
@monkehack I think the ultimate end goal is trying to go near-full AI - less researcher spend and more money in the bank. Synack has a similar idea.
English
0
0
1
372
Ciarán Cotter
Ciarán Cotter@monkehack·
HackerOne and Bugcrowd are pentest shops these days, and bug bounty is increasingly becoming a smaller focus for them. Ultimately, though, they both still rely on the community of hackers to give their offerings any value - it’ll be interesting to see where this is all going.
English
3
1
101
5.8K
Dalus
Dalus@_d4ly_·
@_RastaMouse Just like the olden days when people used to use SBS.
English
0
0
2
882
Dalus
Dalus@_d4ly_·
It also didn’t help seeing how few of the “trusted few” pushed back, even with early access to feedback. If Synack is a main income source, it’s probably time to look elsewhere. If you’re just gaming missions, you might be fine. Here are my YoY results.
Dalus tweet media
English
0
0
6
321
Dalus
Dalus@_d4ly_·
Alongside this was a shift to a mission-based pentest model that feels increasingly exploitative, especially when you factor in the time investment versus what you’re actually paid.... (2/3)
English
1
0
4
297
Dalus
Dalus@_d4ly_·
This year I spent most of my spare time hacking with #SynackRedTeam, but eased off later in the year after some awful changes to "short" tests resulting in less clarity on payouts and reduced pay for more effort... (1/3)
English
1
1
19
2.4K
Dalus retweetledi
SinSinology
SinSinology@SinSinology·
NEED YOUR HELP! My Friend/Teacher Soroush (@irsdl) Is looking for a new company to join, you know him as the .NET-God, the guy who has popped exchange, sharepoint, has maintained ysoserial_.net for years, contributed to the exploitation scene numerous times, taught all of you about what .net ghost webshells are, taught you about what viewstate exploitation is, how .net remoting exploitation issues can be solved, iis cookieless, web_config exploitation, countless of blogs, talks, techniques,... but companies keep saying: "we aren't hiring right now!" if i was in position of hiring, woudln't wanna miss out on having one of THE BEST in my team you're retweet is Extremely appreciated ❤️‍🔥 soroush, if you see this, don't hate me, had to do it without telling you
English
12
120
249
82.7K
Dalus
Dalus@_d4ly_·
As someone who has to to muck in with IR, thrunting and the like... it amazes me how many times it starts with with the most clearly dodgy looking phishing email. 😭
English
1
0
1
204
Dalus
Dalus@_d4ly_·
Couple of weeks without finding a bug and I feel like I've forgotten everything I once knew. I need some #bugbountytips and some bug bounty courses ASAP.
English
1
0
5
444
Adam Langley
Adam Langley@BuildHackSecure·
LinkedIn profile: penetration tester, security researcher, bug bounty hunter. LinkedIn DMs: Will you be my mentor…
English
11
0
39
4.8K
Dalus
Dalus@_d4ly_·
@irsdl That's why I use the word 'void', because it's a big black box if you're using someone else's service. You can only hope they do the right things 😂
English
0
0
1
53
Dalus
Dalus@_d4ly_·
@irsdl And to that end, say do plug in to your own "thing", how can a business be sure your controls are sufficient to safeguard whatever was kept. And what's to say how another company uses it. Needs a lot of thought for enterprise use.
English
1
0
1
90
Soroush Dalili
Soroush Dalili@irsdl·
Among web app security tools like #BurpSuite and #Caido, it seems that whoever nails AI integration fastest will win the race this year. I like the idea of Burp AI, but only if I can choose which AI model to use. Will Caido be the first to get it right? The goal is to have a simple agent or button -similar to those in coding IDEs- with access to request/response data, capable of performing tasks such as researching, sending requests, opening a new tab with a fresh request, updating the current request, or answering relevant questions. What do you think?
English
8
2
64
7.7K
Dalus
Dalus@_d4ly_·
@irsdl It's not something you can necessarily control, either.
English
1
0
0
62