Roronoa

1.8K posts

Roronoa

Roronoa

@_jayesh_7

Ancora imparo 🛌

Katılım Mayıs 2020
729 Takip Edilen243 Takipçiler
Sabitlenmiş Tweet
Roronoa
Roronoa@_jayesh_7·
Reached level 4 🫣.
Roronoa tweet media
English
4
2
28
3.5K
zseano
zseano@zseano·
i'm taking a pause from hacking to resume building bugbountyhunter.com. i regret closing it down and I shouldn't of done it. everything will be back online EXACTLY as it was very soon and i've got some big plans for the future. and yes, that includes zseano methodology v2 ;)
English
43
53
639
24.1K
Roronoa retweetledi
Roronoa retweetledi
Douglas Day
Douglas Day@ArchAngelDDay·
The best career move I ever made was abandoning traditional employment and doing my own thing! The "safe" path is not that safe in the long run!
HackerOne@Hacker0x01

What if your biggest career risk was actually the safest move you could make? @ArchAngelDDay spent years in application security, climbing the ladder, running bug bounty programs, doing everything right. Then he walked away from all of it. Today he's a full-time independent security researcher, a HackerOne champion, and home every Tuesday afternoon with his kids. And he built an AI bot that finds vulnerabilities while he sleeps. This is the story of how he engineered that life and what it really took to get there 👇 bit.ly/3Ofzp44

English
5
7
116
12.7K
Roronoa retweetledi
Bour Abdelhadi
Bour Abdelhadi@BourAbdelhadi·
AI is changing bug bounty, but without fundamentals even the best prompts won’t save you. Think first, prompt second. bour.ch/ai-bug-bounty/
English
5
14
125
6.2K
Roronoa retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
No way 😂 A Redditor installed malware without realising it, it kept changing his browser's search engine to Yahoo. Instead of removing the malware, he vibecoded a browser extension that also acts like malware to redirect Yahoo back to Google and published it in Google Web Store.
International Cyber Digest tweet media
English
44
86
1.2K
80.6K
Roronoa retweetledi
James Kettle
James Kettle@albinowax·
I'm thrilled to announce "Can AI Do Novel Security Research? Meet the HTTP Terminator" will premiere at @BlackHatEvents #BHUSA! Check out the abstract:
James Kettle tweet media
English
21
101
645
54.1K
Roronoa retweetledi
Shad0w
Shad0w@Itx_Shad0w·
A couple of months ago, I told a friend about bug bounty and encouraged him to give it a try. I kept checking in on him here and there, sharing whatever I knew even though I was still a beginner myself. A few days ago, he landed his first bounty Seeing your friends win hits different. It’s a whole other kind of happiness.
English
3
3
122
4.5K
Roronoa retweetledi
bugcrowd
bugcrowd@Bugcrowd·
$1,000,000 in bug bounties came down to one decision: pick a program and stick with it 👨‍💻😮‍💨 HX007, a hacker in the Bugcrowd community, made over $750K on a single program. Not by knowing more than everyone else. By knowing one target better than anyone else. 🔖 The longer you work a program, the more you understand the dev team behind it. Their patterns, their blind spots, the bugs they keep missing. It stops feeling like hunting and starts feeling like collaboration. When nothing's clicking, HX007 switches to a VDP, racks up some P1s, and comes back with his confidence rebuilt. 💡 More advice from HX007 and why he hunts on Bugcrowd: bugcrowd.com/blog/how-i-hac…
bugcrowd tweet media
English
8
21
210
12.4K
Roronoa retweetledi
the_IDORminator
the_IDORminator@the_IDORminator·
I maintain that adding a trailing slash to random pages and APIs remains the stupidest albeit perhaps most effective and prevalent authorization and/or WAF bypass there is. Go slay #bugbounty, the world depends on your proper insertion of the slash. When you get your first bounty doing this, go on a vacation and when your wife says "No no, it's too expensive." You say: "Its OK, the slash is paying for it." Because in what other field can you add a backslash somewhere and make enough money to take the family on a vacation 🤣 /place/thing/page.aspx --> /place/thing/page.aspx/ some/v1/api/users --> some/v1/api/users/ Other common wins are: /, //, %2f, %3f, #, and so forth. Just tack stuff lack that on the end. Maybe combine it with method changes. OK BYE
English
8
43
322
11.9K
Roronoa retweetledi
the_IDORminator
the_IDORminator@the_IDORminator·
🚨My #bugbounty course with @arcanuminfosec is 50% off for the entire month of April! This course teaches you how to go from "Zero to Hero" #hacking the web. Based on feedback, great for beginners or experienced hackers... may the 12345 be with you!😉 tinyurl.com/idorminator
English
12
8
144
29.6K
Roronoa retweetledi
YS
YS@YShahinzadeh·
I published one of the techniques that I've been using against OAuth providers, honetly, it's led me to discover many flaws, and recently I used it to find a 1-click ATO on one of the most widely visited websites,I hope you find it useful :-) blog.voorivex.team/story-of-abusi…
YS tweet media
English
19
119
658
29.3K
Roronoa retweetledi
Griffin
Griffin@aussinfosec·
I have been doing bug bounty since 2011 and ran a program for a multinational bank. Put everything I've learned into bugbounty.info. Target selection, recon pipelines, chain patterns, report templates, the business side. Free, no paywall, no course upsell.
English
27
163
979
50.1K
Roronoa retweetledi
Behi
Behi@Behi_Sec·
Nothing is more energy-consuming than starting on a new bug bounty program. AI is fixing that. Simply ask Claude in Chrome to browse the entire application and provide you with a review of its attack surface.
English
5
5
124
6.8K
Roronoa retweetledi
Behi
Behi@Behi_Sec·
Meet BugSkills. I built a tool to convert the knowledge and methodology used in your HackerOne reports into AI skills you can use to automate vulnerability discovery. Thank you @rez0__ for the idea. github.com/BehiSecc/bugSk…
English
5
58
320
15.9K
Roronoa retweetledi
Damian Strobel
Damian Strobel@damian_89_·
Hey guys, I just launched argosdns.io - if you are into IT security, bug bounty hunting, red teaming, ... this is interesting for you! argosdns.io
English
8
39
235
32.7K
Roronoa retweetledi
Piyush Shukla 🇮🇳
Piyush Shukla 🇮🇳@PiyushShukla__·
Ek din bug reh jaygi or me hunt ho jaunga 🤷‍♂️
Indonesia
2
3
13
634