ars4c

566 posts

ars4c banner
ars4c

ars4c

@ars4c_

bug Hunter / developer / htb

terminal Katılım Mart 2025
127 Takip Edilen11 Takipçiler
ars4c retweetledi
0xSabir
0xSabir@0xSabir·
IDOR via JSON Arrays: If {"id": 123} is protected, try {"id": [123, 456]}. Some backends will process the second ID in the array without checking the authorization of the first.
English
1
13
120
3.2K
ars4c retweetledi
Godfather Orwa 🇯🇴
Godfather Orwa 🇯🇴@GodfatherOrwa·
lof web apps that are built by AI, it have .md and mostly 🔥 so any app you test, JSP / PHP / ASP Add for fuzzing the extensions ffuf -w /wordlist -u .com/FUZZ -e .md,.db,.txt,.xml,.sql,.7z,.zip,.tar.gz,.env it will take some time, but it will be back with very good results♥
English
9
72
512
13.5K
ars4c retweetledi
André Baptista
André Baptista@0xacb·
Found an IDOR vulnerability but the IDs are UUIDs? Don't drop the report yet. 1️⃣ Find leaked UUIDs - Use a tool like gau/waybackurl to dump URLs from that target, see if any valid UUIDs are leaked in the URLs and try them (be careful with write/delete operations ⚠️) - Search more sources, like GitHub, Postman public workspaces, GitLab snippets, Pastebin etc for leaked UUIDs 2️⃣ Find an UUID oracle - Search for your UUID in proxy responses, look around the app functionality to see if the UUIDs might be leaked in some other way, things like search, autocomplete, user lookup, mentions... - Investigate collaboration features like "share" or "invite". These features may reveal the other user's UUID. - Check old API versions (/api/v1/*, /api/1.1/*) If these don't work, keep digging, think weird.
English
3
32
209
8.5K
Surendar
Surendar@Surendar__05·
As a developer, which one do you prefer? Windows or Macbook
Surendar tweet mediaSurendar tweet media
English
85
2
180
8.8K
IT Guy
IT Guy@T3chFalcon·
IT people listening to Non-IT people talk about computers.
IT Guy tweet media
English
91
945
9.9K
218K
ars4c retweetledi
TANSTACK
TANSTACK@tan_stack·
SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.
English
136
981
3.9K
3.9M
ars4c
ars4c@ars4c_·
@brandon_shi and after doing hard part, you get "duplicated":)
English
0
0
0
75
BRDNS
BRDNS@brandon_shi·
bruh doing bug bounty is hard
English
25
14
318
16.4K
ars4c retweetledi
Nicolas Krassas
Nicolas Krassas@Dinosn·
Claude Code skill for AI-assisted bug bounty hunting - recon, IDOR, XSS, SSRF, OAuth, GraphQL, LLM injection, and report generation github.com/shuvonsec/clau…
English
8
168
716
43.1K
Edison
Edison@CodeEdison·
As a dev, what do you prefer for frontend?
Edison tweet mediaEdison tweet mediaEdison tweet mediaEdison tweet media
English
58
9
154
16.3K
Ray🫧
Ray🫧@ravikiran_dev7·
Be honest , As a developer, which code editor is worth in 2026?
Ray🫧 tweet mediaRay🫧 tweet mediaRay🫧 tweet mediaRay🫧 tweet media
English
206
5
254
61.1K
ars4c retweetledi
Dmitrii Kovanikov
Dmitrii Kovanikov@ChShersh·
I'm 32. I've been programming for 16 years. AMA
English
265
17
706
84.8K
TheStandupPod
TheStandupPod@thestanduppod·
Divorcing Windows
English
71
197
2K
37.7K
ars4c retweetledi
ThePrimeagen
ThePrimeagen@ThePrimeagen·
This
ThePrimeagen tweet media
English
234
947
12.8K
423.4K